
Kelly Shortridge
Chief Product Officer at Fastly and author of "Security Chaos Engineering"; expert on resilience, behavioral economics in cybersecurity, and DevOps security
2
APPEARANCES
2
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
OCT 5
Jun 30, 2026
Kelly Shortridge - Episode 87
5:19
5:40
5:46
5:56
11:51
Scott HanselmanHOST
But how badly do you want your site to be up? all the time? Do you want it badly enough that you're going to put it in both Azure and AWS? How much, do you want a copy of, like, how do you make a plane that doesn't crash? Do you fly two planes next to each other? And then when one fails, like, you jump to the other plane? Like, it is ultimately on us, is it not? And we just need to decide how hard to squeeze.

Kelly ShortridgeGUEST
I think there is usually a trade-off, if you want to really simplify it, between cost and resilience.

Kelly ShortridgeGUEST
To your point, you know, ultimately redundancy is multiple paths to get to the same goal.

Kelly ShortridgeGUEST
I do think, though, that software has the beautiful luxury we sometimes don't leverage.
6 MINS LATER
Scott HanselmanHOST
How do you feel about that? Is there a place for LLMs to live in security and in resilience and in chaos, or do they just increase chaos and entropy?
The Joy of Unplugging Cables: Kelly Shortridge on Security Resilience
17:13
17:24
17:35
17:45
17:55
18:04
19:05
Scott HanselmanHOST
I'm curious, does, is there an example where traditional compliance actively makes systems less secure, where they think that they're checking boxes, but they're actually hurting themselves?

Kelly ShortridgeGUEST
Actually, a frequent, uh, co-conspirator of mine, Josiah, um, Dykstra, wrote a paper, not with me, um, it's an excellent paper, um, about that exact topic.

Kelly ShortridgeGUEST
I think specifically, uh, covers HIPAA and maybe one of the others that shows that it doesn't, being more compliant doesn't actually result in better security outcomes.

Kelly ShortridgeGUEST
I'm very much of the view, and I've tried to caution regulators as well is, like, well-intentioned regulation in this space very quickly calcifies and ossifies.

Kelly ShortridgeGUEST
Like, it's what helped in year zero through maybe even year three may end up actually eroding resilience long term.

Kelly ShortridgeGUEST
Great example, I'll keep the person anonymous, very innovative CISO, um, had to explain, I think over a few years to his auditors, like, "Actually, it's a great thing that we don't allow SSH access anymore," 'cause that's what attackers love.
Scott HanselmanHOST
And then investors see it, and compliance people see it, and that checkbox is the thing that stands between you and some certificate or some badge, and that's a problem.