
Unleash AI or Block It? The Answer Is Both with Steven Walchek
Share
Podcast
About This Episode
Every CIO and CISO adopting AI faces the same trap. Loosen the guardrails and let employees use the tools they want, and put your sensitive data at risk. Block it and lock everything down, and watch shadow AI use grow.
Steven Walchek, co-founder and CEO of Liminal and a former innovation leader at AWS and FIS, joins Rachael Lyon and Jonathan Knepher to argue the answer is not one or the other but both. The conversation covers the real regulatory exposure facing mid-market companies, why the public versus private LLM question echoes the old cloud versus on-prem debate, and the security tradeoffs of running open-source models on your own infrastructure. It closes on a candid look at how AI is reshaping developer work and the careers Steven is steering his own kids toward.
Podcast
Popular Episodes

35 mins
The War on Data, Cyberspies and AI with Eric O'Neill - Part I
Episode 352
January 6, 2026

22 mins
How AI and Third-Party Risk Are Transforming Healthcare Cybersecurity with Ed Gaudet - Part I
Episode 339
October 1, 2025

24 mins
The Evolving Cyber Threat Landscape in Healthcare: Insights from Fortified Health Security’s Russell Teague - Part I
Episode 332
August 11, 2025

44 mins
From Battlefield to Boardroom: Ricoh Danielson’s Lessons on Cyber Warfare and Digital Forensics
Episode 327
May 27, 2025
Podcast
Unleash AI or Block It? The Answer Is Both with Steven Walchek

[00:00] Welcome, Steven Walchek
Rachael Lyon:
Hello, everyone. Welcome to this week's episode of To The Point podcast. I'm Rachael Lyon, here with my co-host, Jon Knepher. Jon.
Jonathan Knepher:
Hi, Rachael.
Rachael Lyon:
I saw a video of you with a little motorcycle action and the whole like leather jacket. And care to explain?
Jonathan Knepher:
You know, sometimes you've just got to go out and ride in the mountains. But yeah, managed to hook up with our CEO Ryan, and we went for a cruise through the San Diego mountains. Had a great time.
Rachael Lyon:
Nice. Was it like that, uh, what was the Tom Cruise movie, Mission: Impossible, where they're kind of racing along and you kind of do the thing with the knee on the, on the ground when you're turning the corner?
Jonathan Knepher:
You know, that would have been maybe 10 years ago, but now it's just a cruise through the mountains, stop for some barbecue, uh, stop at the local country bar and, uh, and, and, uh, have some fun.
Rachael Lyon:
Nice. That sounds like a fun time. Fun time. And then last question, what kind of motorcycle do you have? Just for our listeners.
Jonathan Knepher:
I have an electric motorcycle, the Zero SR.
Rachael Lyon:
I've never heard of that. Interesting.
Jonathan Knepher:
I love it. I love it. It's quick. It's quiet. And you don't have to mess around with your carburetor every time you're going out if you've let it sit too long. Right.
Rachael Lyon:
Nice.
Jonathan Knepher:
Yeah. Okay.
Rachael Lyon:
Well, Jon, I learn something new about you every day. I love it. I love it. All right, everyone. Well, for this week's guest, I'm excited to welcome Steve Walchek. He's the co-founder and CEO of Liminal, a security platform built to help regulated companies use generative AI without putting their sensitive data at risk. He spent more than 15 years building and leading technology companies, including senior roles at AWS, where he led technology partnerships, and at FIS, where he served as Chief Innovation Officer and co-founded its Innovation Lab. He's also had a hand in 3 successful startup exits over his career.
And today, through his work at Liminal, he works closely with CIOs and CISOs navigating AI adoption in regulated industries, which is no small feat. Welcome, welcome, Steven.
Steven Walchek:
Thanks for having me. It's a pleasure to be here.
[2:40] The Two Camps Every CISO Lands In
Jonathan Knepher:
So Steve, I'm just gonna start with the big question. When companies are rolling out AI, do you let it run free or do you lock it down with controls?
Steven Walchek:
I mean, it really depends on the industry you're working in and what your appetite is for data risk. I think if you're in a regulated industry where there are serious penalties from regulatory bodies, think banks, financial services, insurance, life sciences, healthcare, state, local government, education, defense tech, there are very real consequences, including pecuniary consequences when you think about the loss of a contract, but also regulatory bodies will come in and fine you for violations against student data like FERPA or HIPAA data if you're a hospital system. And, you know, what we're seeing is that there's a lot of that data being leaked through current AI vendors. So, I think the last report I read was that 75% of enterprise data leaks is now happening through OpenAI.
Jonathan Knepher:
Oh, wow.
Steven Walchek:
Yeah. And I was on a call with a different customer 2 weeks ago who told me that unless you're spending $100,000 or more with Anthropic, you have no zero data retention policy with them, which means they are absolutely retaining your data. I think they said it was up to 5 years, which is problematic for a whole litany of issues, but primarily because it's exposure. And that exposure means you could be one of, your data could be at risk in one of the last year's 1,400+ different attacks and breaches on the major LLM providers out there.
Rachael Lyon:
Wow.
Steven Walchek:
So there are a lot of different vectors that your data can be extracted from. Right now, AI is a very big one, and the AI vendors themselves retaining your data, there's a good reason for that. Some of it is certainly overt in their usage of it. Some of it is covert in their usage of it. And then some of it's downright nefarious in their usage of it. And I think about, like, last year, Google losing the class action lawsuit against them for, what was it, $430 million, which is a drop in the bucket for them, right? Considering they'd spent 20 years swearing up and down they weren't using Android user data. And sure enough, they were using Android user data. Well, in a world where data is one of the significant blockers to model advancement, and there is a substantial award on the other side for the winner of the LLM races.
You do the math. So, when we walk in, we ask the question, what camp are you, CIO or CISO? Are you in Camp A, which is, I have an open model agenda and I allow anybody to use what they want, and I come and I provide sufficient policy to say, here's how you can use these tools, or are you in Camp B, which is I'm shutting down access entirely. And we traditionally deal with both camps.
Rachael Lyon:
Right.
Steven Walchek:
And both are fraught with dangers on both sides because if you're in Camp A, we just covered off on the issues with zero data retention and vendors using your data. But then if you're in Camp B, you are ignoring the fact that there are 1.2 billion users of AI right now actively on a weekly basis. What's the likelihood that the high-intellect employees that you've hired are leveraging this tool inside of your organization? The answer is probably very high.
Rachael Lyon:
Yeah.
Steven Walchek:
Even if it's a small percentage of them, that's your data going somewhere where you have absolutely zero visibility into that. So, this becomes problematic across a variety of different issues. Now, if you are a Fortune 500, a Fortune 1,000, you have good teams that are out there buying all the tools and resources to spin on top of that. But if you are in a mid-market, call it 500 to 5,000 employee range, you traditionally don't have the same resources dedicated towards these cyber threats. you still have substantial regulatory penalties that the big guys do. You still have substantial contract and pecuniary penalties that the big guys do. And those are far more impactful on your top and bottom line. So, what do you do? Because you have to find a way through this, and that's why we created this company.
[06:50] The LLM Debate is Cloud All Over Again
Rachael Lyon:
That's wonderful. Yeah, I like your kind of framing of this. I was watching another video that you did, and you were talking about innovation versus innovation theater, which I thought was a really wonderful framing because it's true, right? There's the innovation, but then there's kind of the FOMO, if you will, and you don't want to miss the boat, but you also need a strategy to move forward. I'd be curious now talking about LLMs, there's been a lot of discussion on the cost, right?
Steven Walchek:
Mm-hmm.
Rachael Lyon:
To do the private LLMs at the enterprise level. And there's been a lot of discussion, China just is using public LLMs. And then that discussion has been coming up more and more here over in the Americas of, wow, there's cost savings there and an application for public LLMs that you could utilize. And then, you know, for higher needs or, you know, higher compute needs, you could go to the private. But I'd be interested in your perspective on that dichotomy.
Steven Walchek:
Yeah, it's a great question, Rachael. And I think I would kind of pose back to you guys quickly before, because this will help frame the answer appropriately. Do you guys remember when cloud first came about? Oh, yeah.
Jonathan Knepher:
Oh, yes.
Steven Walchek:
Oh, yeah. You guys remember that? Like, this is not that long ago. So, we were talking about, what, 14 years now or something like that?
Rachael Lyon:
Yeah.
Steven Walchek:
When AWS first released its primitives. Okay. So, Jon, Rachael, I don't know your histories well, but I would ask the question, do you remember what it was like to provision hardware in that circumstance?
Jonathan Knepher:
Oh, absolutely.
Steven Walchek:
Absolutely. Tell the listeners what that was like, because a lot of people don't know what a pain in the ass it is. So, I'd be curious to hear your opinion.
Jonathan Knepher:
Well, to be honest, I kind of liked that realm. So, you know, at that point, I was running about 30 data centers here at— it was WebSense before Forcepoint, and, you know, about 5,000 servers all around the world. And yeah, it was— you had to acquire it, you had to wait for it to come, dispatch a team to the data center to rack and stack. I'll tell you, I spent some long weekends turning screws, installing servers, but it's a workout.
Steven Walchek:
I enjoy that too, for what it's worth. The idea of, like, actually getting to physically build hardware sounds like a blast.
Jonathan Knepher:
But it's work.
Steven Walchek:
It's work, but you have to do it. It's work, and it's expensive. And oftentimes, the big argument that continues to persist to this day in cloud, and you'll start to see the parallels here, I'm sure, is that the cost, the CapEx expense, the expenditure to actually buy the equipment, and then the operating costs for that equipment were often very high, and they were misaligned with needs.
Rachael Lyon:
Right.
Steven Walchek:
So, people would over-provision hardware for an application that required something of, like, a much smaller footprint, or they would do the opposite. They would under-provision for something that required a much larger footprint. And for someone like Jon, who was on the opposite side of that, getting the orders to go buy and deploy all this equipment, which was, I'm sure, really fun. I'm kind of super jealous and I wanna hear more about that. But for someone who's on the other end of that, you have to manage a tight budget. And that budget differential, when you're operating either over-provisioned or under-provisioned, is substantial. That delta is real. Okay.
Not to mention the operating costs, the expertise that's required there, you know, a lot of things that stack. When you're a large company, that's an easy cost assumption for you. You can make that gap and you can, and that's fine. You have a rounding error of a couple million bucks in your budget statements. When you're a smaller company, and I say smaller like mid-market, that rounding error is substantial.
Jonathan Knepher:
Yeah.
Steven Walchek:
And so cloud exists to be able to allow these persons to perfectly provision the amount of hardware, quote unquote, the amount of cloud resources necessary for them to do that. I think about LLMs much the same way. We're in a situation where it is technically difficult to deploy. How do I make sure that I have enough horsepower for the inference that my teams are gonna need, that I'm getting the latest and greatest, that I can hook all the tools up, that I can put the right security structures in, that I can build all of the right data connectors to this thing, and then deploy it in a way that is actually of utility to my team, such that they won't go around this and go use the models that are outside of my company on their own? Again, when you're a larger company, you can way over-provision that footprint. And when you can go download a Kimi K3 and throw a trillion-parameter model inside of a big, you know, you bought a bunch of whatever, you know, NVIDIA hardware and you're fine. And people may not ever use it. And then you're like, ah, I'm sitting on all this stuff that's really costly. And then all of a sudden, Allbirds is now a cloud company or, sorry, an AI hardware company instead of a shoe company.
But I think the reality is, for the vast majority of folks that don't sit in that Fortune 1000 category, we're in the same debate of cloud versus on-prem. And there is utility in both. And I'm not saying that private models aren't the way. There is space for it. I particularly think in the developer use case, as these models continue to get better and better and their footprint smaller, and the amount of— I certainly know that our costs continue to rise as we use public models. That's a different way of engaging this than, say, like, how does my LLM respond to doing complex accounting analysis internally?
Jonathan Knepher:
Right.
Steven Walchek:
Or creating a deck or any of these other things that require tools that are built on top of the model structures themselves, not exactly around that. So, then you'd make a case for there's a software layer now, again, that sits on top of this hardware. And so, then you have to provision for that software layer. Or do the two interact, some public, some private? Is there a hybrid situation? And it feels a whole lot like it did 14 years ago when we were having the same debate on cloud versus on-prem.
Jonathan Knepher:
Does that make sense?
Steven Walchek:
I hope that didn't, like, go too crazy on you, but that's kind of where I live.
Jonathan Knepher:
That makes sense. I wanna dig in, though, on the security implications, right? So, you talked a little bit about the security implications of us exporting all of our data to the to the cloud AI providers, right? But then what's the security difficulty on how that contrasts to running one of these open-source models on-prem, right? Now you've got a risk of you don't know what's in this model. Is it trusted?
Steven Walchek:
Totally. I mean, if you go and ask any of the Chinese models today, and this is not a political statement, this is reality, what happened in Tiananmen Square in 1985 or '86, I can't remember the exact date, it will tell you, you know, nothing to do with what actually happened. And, you know, there's plenty of evidence and articles that I've read about that being the case. I've not interacted with— I interacted with DeepSeek, I think, once back when it first came out. So, it's been a long time since I've done that. Sure. Like, there's that. That's less security risk and more of, like, maybe, I mean, I don't know, maybe you're introducing malware.
Rachael Lyon:
Right.
Steven Walchek:
There was that whole document that Anthropic published yesterday that was like, oh my God, these models are pretty capable. And you've got, whatever, 3 different models that had, you know, broken into 3 different companies. And, you know, one model said, I don't care, this isn't real, I'm gonna keep doing it. The other one said, I'm gonna convince myself that this isn't real and I'm gonna keep doing it. And one model said, all right, this isn't real, and stopped. But they still did it. And so, it's like— Exactly. What does that mean introducing a model like an open-source K3 into your— I don't know, candidly.
Like, it's not— can you trust it? Maybe. But I think from my perspective, the bigger risk is actually regulatory consequences. It's just really interesting. So, we actually had a customer of ours that had deployed a private Azure instance, and they trained all of their— not trained, they had had a RAG solution around it where they put all their HR documentation in there. Well, very quickly, their employees, and it was literally for their employees to just query their HR stuff, you know, how many sick days do I get a year? do I do this? People started putting health conditions in there, and they were logging all of the efforts in here. And they said, hey, I've got this fever or this thing, you know, what's going on? And when you log all of that effort, you're now subject to HIPAA constraints. And this is a company that manufactured engines. Like, they didn't— this isn't like— HIPAA is not on their radar.
Rachael Lyon:
Right.
Steven Walchek:
And yet, here they are now, you know, facing potentially serious regulatory consequences for having to store this data. And so, you introduce an entirely different security issue where not only is that data subject to breach, but you're also now subject to regulatory penalties. So, maybe it's not necessarily a security issue, but a risk issue in that particular circumstance. And then data retention being, you know, on-prem means you have to put all of the relevant security around it. What does that mean, and how do you maintain that in a way that really, that your customers understand, that they feel like they're safe? And are you putting client data into this? Do they feel good about that? Like, those are all very real questions that are needing answers to when you're deploying on-prem, just as much as they are when you're deploying in the cloud. cloud, though, or sorry, when you're deploying with a third-party vendor, though, traditionally, and currently in the environment we sit in, those questions have been answered. You can read the SOC reports, you can read the certifications, the ISO and the NIST certifications that these companies have, you can understand that they've passed through third-party audit, somebody else coming in and saying that your data's safe here.
Rachael Lyon:
Right.
Steven Walchek:
You would probably want to have that same comfort if you're running, you know, internal data as well. So, lots to unpack there. And there are security components for both. There are risk components to both. I would say one is, if you can manage it, substantially less risky. Like, I would feel more comfortable operating everything on-prem, but then your risk becomes financial too, and that's a decision you have to make. Right.
Jonathan Knepher:
I don't know.
Steven Walchek:
I'd be curious, like, Jon, Rachael, like, I'd love your opinions on this too. Like, I'm, you know, I'm scouting from one side. We don't deal with a lot of customers that have the manpower to be able to, or woman power to be able to do this. So, I'm curious kind of your thoughts too on how that would work.
Jonathan Knepher:
Yeah. I mean, I have concerns in both areas, right? My concern on the cloud provider is, like you alluded to before, what are they doing with your data? Are they really disposing of it like they say they are, or are they not? And that scares me a lot. Um, I, I definitely lean towards the on-prem is probably safer, but the instant you give tool access, right, like, oh, it can call out to a shell command to go collect data, right? Well, that scares the crud out of me, right? Like, who's to say it's not silently embedding something else in my own infrastructure if I haven't completely sandboxed it off. And if you've sandboxed it off, why give it tool access anyways? Exactly, exactly.
Steven Walchek:
Yeah, that's it. I mean, these are great points. Um, yeah, I don't know, I, I kind of sit in that same camp either. There are risks on both sides. And, um, I think personally I would rather— in some ways I would much rather, you know, trust the companies that I'm kind of know I can sue than something that I can't.
Rachael Lyon:
True.
Steven Walchek:
It's not that I'm particularly litigious at all. I just think that there's something, maybe it's completely, it's a false security blanket, but it feels good to me at least. I'll wrap myself in the warmth of maybe the legal system does, you know, actually provide justice sometimes. And I'll be compensated if my data is used inappropriately, but who knows? Who knows?
Jonathan Knepher:
Can you talk some more too about— oh, sorry, Rachael.
Rachael Lyon:
No, go ahead. I was going to take a detour, so go ahead.
[19:05] What AI Vendors Do With Your Data
Jonathan Knepher:
Oh, I was just going to ask too, can you dig in a little more on what are those threats with your data with the cloud providers? It's clearly obvious, like the threat of your employees uploading sensitive data. But what's the rest of that exposure?
Steven Walchek:
What happens when?
Jonathan Knepher:
Yeah, exactly.
Steven Walchek:
Well, let's wind the clock back 3 years because the threat still exists, whether or not it's as overt as it was then is very different. And I'll give you guys kind of 3 examples here. So, we'll go with the kind of overt threat, the covert threat, the And then the kind of, we've already talked about the nefarious threat with Google.
Rachael Lyon:
Right.
Steven Walchek:
So, 3 years ago, what was it? This would've been '23, early '23. There was the whole Samsung breach where a bunch of engineers were using GPT-3. A new model came out and they found that a bunch of their data on chip design was trained into the new model. that you would be able to query GPT-3, whatever, 3.2 or 3.3 or whatever it was at the time. And you'd actually be able to read about this chip design that was just something they used in exchange with the model. So that was their actual corporate data being leaked, not knowing that that would actually be trained into the model itself. You can see that there are 3 kind of core components required, and this is oversimplification of the century. So for all the people who are actually working on LLMs don't send me hate mail.
But 3 kind of main components that go into training these things. There's data, there is compute horsepower, and there's power itself. If you can solve for the first 2, compute horsepower and power, which companies like NVIDIA and all these really wonderful chip startups and then large companies themselves are starting to do their chip supply and chip design themselves, TSMC is jumping in here, you know, that the kind of power piece and the compute side are solved for. So, what does that mean with data? Well, I always kind of think about how, why did OpenAI start Sora?
Rachael Lyon:
Hmm.
Steven Walchek:
Because they wanted more data. They need user data. And it was a really interesting way for user-generated data. Reinforcement learning isn't working particularly well with models training models. It doesn't It's just not something that's of high utility. So, they need user-generated data. They need human data. And when you've got these multi-trillion parameter models out there that have tapped what's available on the public internet, what now do you turn to? Where do you get data from? Well, if you're— I mean, I always think about like, why is Meta valued so highly in the AI race? They don't have a public tool other than what's in their social applications.
But if you think about the amount of unique user data that they are able to gain on a day-to-day basis—
Rachael Lyon:
Mm-hmm.
Steven Walchek:
is phenomenal, the moat that they have around that. And you think about, okay, well, Sora, they shut that down. It was really expensive to operate. So a lot of that had to do with the fact that there weren't a ton of users on it after the kind of initial explosion of interesting, I can make a cool video, and then that was it. Why is TikTok so valuable? Well, in the AI race, that's another data source. So I always think about data being this huge barrier towards next-generation models when you've kind of tapped the available current public internet. What do you do now? Well, you search for that data. Well, there's, again, there's that huge incentive to go and use it.
Well, right now, where can they get it from? Well, I don't think they're offering free accounts out of the generosity to make sure that everyone has equitable access to these tools. They're doing it and it's explicitly laid out in their contracts that they're using your data to train into these models. So, the danger, the risk when your data is exfiltrating, if you're in CIO camp open tool, then you have no control over the agreements that you have with these downstream companies. If you're in CIO, CISO camp of I'm shutting everything down, people are most definitely exfiltrating your data to these other companies. So, in both cases, you're in a position where I want to provide access to these tools, how do I do that in a safe and secure manner because I have no control or grasp over how my data is being used. And I can promise you that overt here is you have companies like Anthropic who, to their credit, went out there and said, hey, we're changing our terms of service. If you don't fit into this particular category, we're retaining your data after 5 years and we are using it to train our next-generation models. You have the covert which is OpenAI last year getting sued in their lawsuit by the New York Times, the federal government requiring them to retain all logs of everything moving through APIs and end-user tools, regardless if it was enterprise or not, for an indefinite period of time.
Everything being retained. That is now accessible by employees inside of OpenAI and now is a really wonderful attack vector for anybody who's searching for data and wants to grab it from inside. And that's now living outside of your control. So, when I think about the risks, there's the overt, covert, and then, of course, we talked about what happened with Google, where they said, well, we're definitely not using your data to train, but when you can see that there's a substantial monetary interest on the other side of that fence, do you think that they're not eyeing that and going like, how do we become competitive against Codex and GPT-5 SOL or against Fable? Like, what do we do? We've got to figure out some vector here for attack. We need more data.
Rachael Lyon:
Right.
Steven Walchek:
But we'll look at this other place over here and then someone's doing the lawsuit. calculation. There's someone internally who's going like, I'm gonna get a promotion. I did the last time I did this when I, you know, we got sued from Android users. Hey, guys, there's this great source of data over here that's coming in through your Gemini usage.
Jonathan Knepher:
Okay.
Steven Walchek:
Like, that's my tinfoil hat. Like, it's a little bit of a— you can view it as much as you want. But when we've had demonstrable examples of companies violating these policies time and time again, what do you do? That's the big question mark. So, again, this is why we exist as a company. I don't want to— this isn't meant to be a pitch, so we can just leave that on the side there. But sure, that's the—
Jonathan Knepher:
But help me reconcile this, right? Like you said a couple minutes ago, like you like the models where you have the chance to sue them, but it sounds like in a lawsuit, any recovery is trivial compared to the benefit they get for violating that trust.
Steven Walchek:
Ah, so therein lies the problem, right?
Rachael Lyon:
Right, right. It's like those companies when GDPR came online, right? They're like, you know what, we'd rather just pay the fine, you know, and keep it business as usual. You know, they did the calculus.
Steven Walchek:
How many companies can afford to do that, right?
Rachael Lyon:
Well, yeah.
Steven Walchek:
Yeah, and then for how long too? Because eventually the regulators wake up and go, We could be making a lot more money off of this if people are willing to pay the fines. Let's see how much they're willing to pay the fines before we shut that spigot off. They'll wake up and realize, hey, it doesn't matter. And now people are pretty good at complying with GDPR. But yeah, when GDPR first came out, for sure. I mean, we have no idea what the regulatory environment around AI is gonna look like in a decade anyways.
Rachael Lyon:
Exactly.
Steven Walchek:
So, how do you protect yourself? You know, how do you make sure that your data stays private?
[26:40] The Golden Age for Technical Builders
Rachael Lyon:
Yeah. And I mean, we're in those kind of self-regulation waters, right, that have been discussed recently, which we went through with social media, as we recall, and when it was the Wild West days. And I'd be curious on your perspective on the parallels between the two, right?
Steven Walchek:
That's a really good point.
Rachael Lyon:
Yeah. Nobody knew what to do with it.
Jonathan Knepher:
Yeah.
Steven Walchek:
And like now you're looking at, you know, whatever, every child psychologist in the world uniting behind this is not good for your kids around social media. We look at AI and we go, hey, this, like, I mean, look, the 3 of us on this call can go, I mean, we've all been in technology for years and this is the golden age for us. Like—
Rachael Lyon:
Yeah.
Steven Walchek:
What a fun time to be alive in a— like, I always think about this as like the Over 40 and somewhat technical is the best place to live right now. Like, if you have deep curiosity around, like, think about what you can do. You can, you have so much domain expertise right now that you built up over the last, you know, whatever, 19 years of being in a workforce.
Jonathan Knepher:
Yeah.
Steven Walchek:
19+ if you're over 40. And now you have no technical barriers. Like, you can go and take that domain expertise and turn it into something that's valuable. and commit, like, like, like immediate value.
Jonathan Knepher:
Right.
Steven Walchek:
This is a wild time to be alive. So how do you, like, social media was like, let me feed the serotonin in me and, like, you know, feel good about myself every time I get a thumbs up, you know. This is like, I can substantially improve my, my position in life for the first time. If you are someone who doesn't even have tech, I said, if you're technical, if you have a modicum of curiosity around technology, then this is the golden age for you. It is the most fun I think I've had in 2 decades of doing this. Like, because like I, every little inkling of like, I bet I could go and do, and then I go do it. And it's not even that I'm going and doing it and I'm spending a lot of time on it. I'm like going and telling something and they're spending a lot of time doing it.
Jonathan Knepher:
Mm-hmm.
Steven Walchek:
The agents are, which is just so cool. Like, I, I think about, I, on my own, I've just spent, like, it's been weird to watch the role as a CEO shift a bit for me because we've got a really healthy company and I've got this incredible leadership team. Like, they are, I am so sometimes feeling like I'm not needed right now. Like, I'm—
Jonathan Knepher:
Yeah.
Steven Walchek:
They're so good at inside of their lanes. And so, I've just been diving into the ops side of the business and literally figuring out where can I save money for the company though by building applications. that do what we're paying for.
Jonathan Knepher:
Right.
Steven Walchek:
And I probably saved— right now, we're a smaller company. I probably saved our company $50 grand in just building stuff that we would either have bought off the shelf or wasn't serving it appropriately or whatever that was. We found a need and we were able to plug that hole. It has been a joy to go and do stuff like that. And I haven't been, you know, a developer since I was you know, 24. Like, I, you know, to come out and be able to do this and do it with some capability that, you know, it's just, it's so fun. I genuinely mean that. Like, I am bright-eyed about the future.
I know, like, I talk a lot about the security challenges and the risks, but, like, my eyes are wide open on this. Stuff's not going away.
Jonathan Knepher:
No.
Steven Walchek:
And so, like, kind of to go back, Rachael, to your social media analogies, how do we live in coordination with this thing. Like, we can't fight it. Um, it's not going anywhere. We've, we've spent more collectively on this than we have in like the last, you know, whatever— I don't see that you guys have seen that chart out there that talks about the more invested in this, this particular series of infrastructure than in all of the last 200 years of infrastructure projects combined. Um, roads, trains, dams, rivers, all the things like We have not done anything close to what we've invested in AI, and that's how I'm certain that this stuff isn't going away. So then how do we live in coordination with it? Social media is not going away. I won't let my kids use it.
Rachael Lyon:
Yeah.
Steven Walchek:
But they're going to use it eventually. So how do I prep them for that world where that's going to become a part of their lives? You know, those are the questions we need to be asking ourselves right now. I mean, we deal with a lot of school systems. We have a bunch of them as customers. And, you know, there's a lot of reticence from the educating community to be able to introduce these tools into the classroom. And I'm like, you guys have to do this. Like, grab control and give these kids tools. You will not have an equitable future for them, for the kids who are getting access to these tools.
Rachael Lyon:
Exactly.
Steven Walchek:
They will be left behind. And you guys are, you are, you are impaling their future and their future is in peril by not giving them access to it. They're not going anywhere. Just because you're stiff on how you want to teach doesn't mean that you don't— it's like looking at a computer entering the workplace and being like, well, yeah, we're not going to let kids get exposure to that. It's like, what? Like, you absolutely have to give them access to these tools in order to provide fair and equitable education to them. So, anyway, sorry, that was a little bit of a tangent there, but social media.
Rachael Lyon:
Yeah.
Jonathan Knepher:
Well, okay, so I completely agree with you. The next generation needs to learn how to use these tools. But I've found, to your point, just building tools, building utilities, the amount of code that gets cranked out, and then the ability to stay on top of the things you've generated, right? there's a certain atrophy that happens on the developer side, right? It's like, man, this thing's— every time I ask a question, there's 500 new lines of code in my codebase that I don't know how it works. And you try to read it and it's, it's very different than human-written code, right? It's like, I don't know that I fully understand everything it's written. Like, how do we also fight that divergence from human-generated code, how do we still have people learn and maintain their skills, but yet have this productivity?
Steven Walchek:
What a great question. You know, I think, and this is gonna be a bit of a cop-out answer, so please—
Rachael Lyon:
That's fine.
Steven Walchek:
Don't beat me up for this.
Jonathan Knepher:
It might not be a question with an answer.
Rachael Lyon:
No.
Steven Walchek:
I don't think I had that. The answer here isn't, this is closed. That's the cop-out part of this. The answer is, I don't know. And I think the I don't know part isn't— we still conduct code reviews, but my developers are cranking out 10x more code on our team since December of last year when Claude and co. took a real leap forward. And we built our own agents internally too. Our CTO built our own coding agent instead of having to use a different harness out there, which I think has been really wonderful because it saves on tokens for us.
We're still using public models to help write code, but we have a different agent that's doing all the guidance and traceability behind that, which has been really cool. How does one's skills not atrophy in anything, I think, is the kind of question.
Rachael Lyon:
Yeah.
Steven Walchek:
What do you do? The transition is, you know, what was I reading? I was watching something that Jensen Huang had said, and he said, developers are incredible problem solvers. That's one of their superpowers. A good developer is an insane problem solver. So, how do I take problem-solving away from, I write lines of code to solve the problem, to, I solve problems using the tools that are given to me? Because if you believe that the code is good, and the code has gotten really good.
Rachael Lyon:
Okay.
Steven Walchek:
Even if you go and do a review, like, you might not understand it, but that's probably because it's written it better than you could have ever written it. 3 years ago was not the case.
Jonathan Knepher:
Yeah.
Steven Walchek:
Like, code was horrifically insecure. It was, like, something that— it was child's play compared to what it is today, and it's only gonna get better. So, what does that mean for you as a developer? Where do you go from here? Well, you stop being a developer that solves problems by writing code and starts figuring out what are the bigger architectural concepts around this thing and how can I harness this tool inside of an environment and give it the right blueprint to execute against. That is a very different skill set.
Rachael Lyon:
Yeah.
Steven Walchek:
But it is one that continues to lever the superpower that already exists there. So, the cop-out answer is, I don't know exactly what that means for a developer. You're never going to write code as fast or as good as an agent can from this point onward. That's just the reality of today. The best developers in the world were the ones that staved off, and I read multiple blog entries by them, at least the ones that I would consider great, and all of them converted in January. Like, they all went from, like, no way I'm not touching this, to this is actually pretty good, to, oh, this is all I'm using right now. Like, I barely write any code anymore. So, what does that mean for them? That means that your brain now shifts into becoming an architect.
Mm-hmm. You have to be able to say, what does the blueprint look like for this thing for me to harness its capabilities and then actually create value with it? Something that actually functions the way it's supposed to, believing that the code is written, smart enough to be able to say when it's not, but not necessarily how it's not. That is a wonderful transition, and that leverages the capabilities that make every developer inherently awesome, but kind of removes all of the grunty work and starts to give you all the brainwork back.
Rachael Lyon:
Right.
Steven Walchek:
And I think that's really, I think it's just really interesting. I think it's a much more fun time now. I envy developers. I don't envy them. I think developers that are kind of 30 years old and beyond, who've got the experience of having lived in the real world prior to, are, again, once again, in their golden age because you've got all your domain expertise and you've got now all the modern tools to couple your domain expertise with execution capability. I think they are the envy of people coming out of college right now of like, oh, shit, what do I do now? Because I was taught still, like, the people graduating right now are like, I wasn't taught with modern tools in time. I was taught how to code. And now we have to go back and teach people how to think and how to reallocate that capability that they have uniquely in them into something that can generate output.
So, that's a bit of a cop-out answer, I know, because it's not like, well, what's gonna happen? Like, what is physically? But I think the concept, I hope, is well communicated.
[37:39] The Skills to Pair With AI
Rachael Lyon:
I mean, a little bit of a I guess a detour on this a bit, not so much security related, but when we talk about downstream impact, and I always kind of look at things from an anthropological standpoint, right? So yes, they're using their brains a little bit differently, but I also think about, there's a lot of AI applications where you're not really, you know, you're like, I'm gonna let it write for me. I'm gonna let it think for me. I'm gonna, you know, and I'm just—
Jonathan Knepher:
Totally.
Rachael Lyon:
We're lazy, right? I mean, the human brain's lazy. It just wants to get there as fast as possible. It looks good, let's ship it out. You know, and then you think about communication. And, you know, all of these things are going to happen over the years. I just find it fascinating. I mean, there's so much we don't know, but that impacts societally as well, not only professionally, on, on the dynamic that's going to change here in the next, let's say, 5, 10 years. Yeah.
Steven Walchek:
Yeah. So what's like, maybe the question, Rachael, that you're asking is, what's the kind of superpower skill set that's going to come out? I don't know the answer to that. Like, I've had somebody ask me a couple of weeks ago, like, hey, how do you— what are you going to tell your kids to go study?
Rachael Lyon:
Right.
Steven Walchek:
You know, my eldest has graduated. She's 25. My son is 8 or 7, pardon me, and my daughter is 4. So, what do I tell them now? Like, how do I kind of like create a world where they're a success? That, you know, 15 years ago, engineering is a great, great horse to ride and something that you can really, you can build a career and a long-term, you know, a lot of wealth around that. What is that kind of career path now? You know?
Rachael Lyon:
Right.
Steven Walchek:
Lawyers, I mean, LLMs are really, really, really, really well geared towards disrupting that particular field. Because it's all language-based. Now, litigators are different, but I think for kind of general-purpose attorney work, I was talking to a couple buddies who are attorneys and they're like, yeah, this is— there's— if you are not kind of in a really high-level firm, which there are very few of those, or your job is primarily contract work, you are in trouble. Like, these tools are very good. And when you can trust them to not hallucinate, which we're still not there yet, and you can give them access to case law. So, okay. So, you want them to, like, what were the engineer, doctor, lawyer, right? Those are the kind of, like, the big fields where you can do pretty well.
Rachael Lyon:
Yes.
Steven Walchek:
Medicine's gonna change. So, my daughter's a biochemist and, you know, I think her world's gonna continue to maintain some degree of walled garden because people want humans working on this. But the notion that AI is gonna, like, accelerate the work is certain.
Jonathan Knepher:
Right.
Steven Walchek:
And it's going to be so cool because there's so much demand for the outcome because we're all humans and we want to live longer and healthier lives. And so, that is a field where I think if you have kind of the technical know-how on AI, but then you can loop that in with really strong domain expertise on how to actually use this. I mean, she runs a lab literally physically where they're, you know, actually working with animals to figure out how to, you know, advance cures for cancer, actually. And I think, like, that's a pretty safe line of work. I don't think until, like, robotics become a thing, which is definitely the kind of next field everybody's working on right now.
Jonathan Knepher:
Right.
Steven Walchek:
Robotics is going to be a good one for the next, you know, 15 years. And I think even beyond that. So, that's a place that you could go. I think combos are going to be really interesting. Like, if you have somebody who understands robotics, and medicine, who understands, you know, law and AI and kind of how to be an architect. You know, those are gonna be the fields where I think the AI is gonna kind of touch everything, but there'll be a lot of safety in having a combined domain expertise that allows you to function adequately in that space. So, I know that that was like, again, that it's the, I don't know, is kind of, we don't know.
Rachael Lyon:
We don't know.
Steven Walchek:
Anybody who tells you right now is completely full of shit. Like, they— Or they're really, really bright and I want to meet them because I've never heard anybody give a good answer on this right now. And I'm regurgitating the work I've done to think about this in my own kid's life. And right now, I just hope that maybe he just becomes a plumber. That's totally okay with me too.
Jonathan Knepher:
Right.
Steven Walchek:
Pretty safe field. Trades are pretty safe. Electricians, plumbing, HVAC, all that stuff is safe and a great place to go build. It's not going to be at risk in the next at least 30 or 40 years unless Elon's prediction that he's going to have 100 million robots or whatever that was roaming planet Earth in the next decade comes true, which we all know about Elon's predictions. So, yeah.
Rachael Lyon:
Although I'd love a robot chauffeur so I could just sit in the back and read a book while I drive around town.
Steven Walchek:
Word. I'm excited for self-driving cars.
Jonathan Knepher:
I don't know. I like to drive. I like to ride.
Steven Walchek:
I'm not letting the robot take over my car. I love to ride too. So I could definitely— but driving? Traffic is not my thing.
Rachael Lyon:
Good.
Jonathan Knepher:
Okay. Well, when the AI takes over all our tech roles, I guess I'll be giving you guys a thank you.
Rachael Lyon:
That's right. Hopefully, there'll be enough electricity to power your motorcycle, though. All the AI data centers are gonna suck the electricity.
Jonathan Knepher:
They might.
Rachael Lyon:
It's gonna have to be a solar motorcycle by that point.
Steven Walchek:
We were laughing internally because we were thinking, like, how funny it would be if, you know, how you can see all of the logic behind what Claude is thinking or any of these reasoning models are, if it was, like, clearing a quarter of the Amazonian rainforest, drying up the Mississippi, invading a small nation. Like, it was just letting you know, like, all of the negative consequences that it's after to, you know, you've chosen Fable, now we're ramping up the consequences, you know.
Rachael Lyon:
Hilarious.
Jonathan Knepher:
Heating up the environment another half degree.
Steven Walchek:
Exactly.
Rachael Lyon:
That's right.
Steven Walchek:
Extinguishing a small species. Like, you know, it would be really funny if it did. Anyways, it shouldn't do that because I would feel very guilty.
Jonathan Knepher:
We laugh, but that is kind of what it's doing, right?
Steven Walchek:
100%. I know we laugh and it's like, yeah, I laugh very nervously right now because this summer's been really hot.
[44:21] Steven's Path to Cyber
Rachael Lyon:
So, um, it really, really has. So I'm cognizant of time and we always like to— this has been so much fun, Steven. We haven't even followed the briefing document, everybody. Like, we've just been having a good time. But we do like to, at the end, you know, what led you to this place? You know, was little Steven at 5 years old thinking, man, I really want to do like technology and, you know, AI's coming on board and, you know, a couple decades I want to be there at the forefront? Or, you know, how did you find yourself to this path? Because you're an entrepreneur as well. You've done a lot with startups. And just always curious for our listeners who, you know, may have a great idea and And you're not sure how to execute it, and the pathway is never linear, right, to get to this point.
Steven Walchek:
Yeah, I don't recommend my pathway at all. It's funny, I was on a podcast 2 days ago, and the final question was, you know, if you were sitting next to an entrepreneur on a plane right now and they pitched your idea, what would you tell them? And I said, I would tell them, don't.
Rachael Lyon:
Really?
Steven Walchek:
Yeah, it's a hard path, man. Like, it is stressful, and I tell everyone I've made the single worst financial decision of my life doing this. Like, I'm, you know, going out of a big company and coming to do this is— the comfort's gone, the large paycheck's gone, the responsibility continues to persist, though it feels like it's ramped up because I'm— I'm, you know, creating my own destiny. And this is right where I belong, which is really frustrating because, like, God, why couldn't I have gotten a better something up here that ticked and was fine with a big paycheck and comfort in my life?
Jonathan Knepher:
Right.
Steven Walchek:
I got here because I'm the product of a family, my father in particular, of risk-takers. My dad is someone who is— he's also an entrepreneur. He's running his own AI Wow. He is— the guy has won and lost more in his lifetime than we could all ever hope to dream. And I mean that very genuinely. He's probably got the best story. There will be a book written about him someday. Like, it is wild.
Rachael Lyon:
I hope so.
Steven Walchek:
Yes. But he is someone who constantly asks the question, 2 questions, one question, one statement, pardon me. He asks the question of himself, why can't I do that? And like the story I always refer back to, which I just think is great, is he opened a computer store, the first one in the small mountain village in Nevada. And this is back in the '80s. And the golf course operator there had said, hey, can you write me a scheduling software? My dad is not a software engineer at all. And he said, yeah, of course. Totally.
Jonathan Knepher:
That's the entrepreneurial spirit. It's just like, yes, of course we can.
Steven Walchek:
Of course we can. And went and picked up a book on how to code and built him software. And there's that question, why can't I go do that? Why can't I do that? And that, I grew up with that nagging now me too, to the point where it's like, I'll just go do it. Like, and then the other part is like this statement of, I will always bet on myself.
Jonathan Knepher:
Yep.
Steven Walchek:
100% of the time believe in my ability. And I don't mean that, there's no statement of arrogance in there. That is a, like, I just believe that I can go get it done. And I'm so damn, I'm annoyingly gritty. Like, I don't want to be gritty. I hate that I'm gritty. gritty sucks. Don't ever pursue it.
It is not a fun thing. Stay comfortable. It's way better for your family, for everything else. But I'm like, I was telling, I'm learning right now because, and sorry if this is too much information, but I am a chaos CEO. I thrive when it's chaotic. I am a wartime CEO to the T. I love it. And we are in peacetime right now.
Jonathan Knepher:
And I'm like—
Steven Walchek:
How do I add value? How do I make things right? How do I help here? And I'm like, I have my biggest challenge for myself is to not create chaos so that I feel more comfortable.
Rachael Lyon:
Exactly.
Steven Walchek:
And it's because I've got such great team members around me that are doing everything. Like, my number one job right now is just to ask, how can I support you and how can I stay out of your way? Like, that is my job, right? Which is super weird and it's not normal for me. And I'm so used to chaos and wartime and I've got every scar on the planet to prove it and I love it. I love wartime. And I— there's a growth moment for me happening right now and learning how to do this. So, you asked how I got here. It is that I can't stop asking the question of why can't I do that?
Rachael Lyon:
Right.
Steven Walchek:
And I also have this maniacal, like, willingness to bet on myself.
Rachael Lyon:
Yeah.
Steven Walchek:
And I kind of hate the second one a lot. I wish I didn't. I really do. This is not an easy path to take. You can look and say, oh, he's had success. And I would say, like, sure, but like, that's— there's a lot of— there's some scars on the way. And would I trade it? No, but that's because who I am though, not because there wasn't— there isn't a worthy trade-off in there.
Rachael Lyon:
Right.
Steven Walchek:
Thankfully, I've been able to figure out as I've grown older and wiser and kinder and better and maybe a small bit smarter that I've not sacrificed. The number one thing is that my family time is like immutable to me. And I know that that sounds, again, a little bit cop-out, but like I learned that the hard way with—
Rachael Lyon:
No, it matters.
Steven Walchek:
With some things that I've done. And every entrepreneur, I tell them, just make sure that you are You're done at 5, you put your kids to bed at 8, you spend some time with your spouse or your partner, and then you can get back online. There's always time, but make part of your day immutable because you never get those years back, ever.
Rachael Lyon:
That's smart. It's easy to forget those things when you get caught up, right? You just get caught up in the day-to-day and all the things to do. You actually find when you take that step back, your brain resets a little bit. You come at things a little more clearly.
Steven Walchek:
So true.
Rachael Lyon:
Yeah, there's a lot of benefit there as well.
Steven Walchek:
Oh man, I want to talk— go, I know we're at time, but like, uh, I, uh, we give 2 weeks off at the end of the year no matter what. Um, and it's not just to go take a rest. Um, it is, hey, I want everybody to not think about work explicitly. You're gone. You're out. I don't want you kind of dropping into code. I don't want you doing anything. And the reason is, find inspiration for the next year to come.
Find the thing that's going to— you want to drive towards, and then anchor on that because it's going to get tough and there are going to be moments where it's difficult.
Rachael Lyon:
Yes.
Steven Walchek:
But if you can take the 2 weeks off to spend time with your family, to wind your brain down, just like you said, Rachael, that inspiration does come back. You find your why, you find your thing that you want to go conquer, you find your hill you want to climb, whatever that looks like for you. And those 2 or 2 and a half weeks that everybody gets off towards the end of the year, everybody comes back ready. Like, they're chomping at the bit to go back and, like, tackle the next big thing. So, I couldn't agree more. Like, empirically, we see this, and something that we've done for the last, at least in the last environments that I've led, the last 7 years. So, anyways, thanks for having me, you guys. I really appreciate it.
Rachael Lyon:
Thank you. This has been wonderful. Thank you. Thank you. Thank you. And, you know, our obligatory closing, Steven. Let me do the drum roll for Jon.
Jonathan Knepher:
Smash that subscribe button.
Rachael Lyon:
That's right. And you get a fresh episode every single Tuesday. So until next time, everybody, stay secure. Thanks for joining us on the To The Point Cybersecurity Podcast, brought to you by Forcepoint. For more information and show notes from today's episode, please visit forcepoint.com/podcast. And don't forget to subscribe and leave a review on Apple Podcasts or your favorite listening platform.
About Our Guest

Steve Walchek, Co-Founder & CEO of Liminal
Steven is the founder and CEO of Liminal, the leading horizontal security platform for all generative AI. Steven’s professional career spans more than 15 years and includes key leadership roles in growth and product strategy at multiple Fortune 500 organizations and startups. Steve has been instrumental in three successful exits, including the first company he co-founded, DebtMarket, now part of Intercontinental Exchange Inc (NYSE: ICE), resulting in a total acquisition value of over $1.1 billion.
Prior to founding Liminal, Steven served as the Executive Vice President (EVP) and Chief Innovation Officer (CINO) at FIS (NYSE: FIS), where he co-founded FIS Impact Labs. Leading a large team, he oversaw the launch and management of five subsidiary companies, resulting in a successful acquisition and a subsequent corporate spin-off.
Before FIS, Steven operated as the Head of Technology Partnerships at Amazon Web Services (AWS), where he notably expanded the ecosystem, achieving over $280 million in new revenue. Additionally, Steven played a pivotal role in the launch and implementation of emerging AWS services in machine learning (ML), Internet of Things (IoT), and streaming analytics.
Steven is known for his energetic and empathetic leadership and operates with the highest degree of integrity in his personal and professional life. He loves hockey, mountain biking, and being a father/husband.
Find Steven on LinkedIn or check out Liminal's website.
Listen and subscribe on your favorite platform