Skip to main content
Kelly Shortridge

Kelly Shortridge

Chief Product Officer at Fastly and author of "Security Chaos Engineering"; expert on resilience, behavioral economics in cybersecurity, and DevOps security

Jun 30, 2026

5:19
But how badly do you want your site to be up? all the time? Do you want it badly enough that you're going to put it in both Azure and AWS? How much, do you want a copy of, like, how do you make a plane that doesn't crash? Do you fly two planes next to each other? And then when one fails, like, you jump to the other plane? Like, it is ultimately on us, is it not? And we just need to decide how hard to squeeze.
5:40
I think there is usually a trade-off, if you want to really simplify it, between cost and resilience.
5:46
To your point, you know, ultimately redundancy is multiple paths to get to the same goal.
5:51
In practice, you need polyglot applications and systems.
5:54
That's pretty expensive to pull off.
5:56
I do think, though, that software has the beautiful luxury we sometimes don't leverage.
6:02
To your point about planes...

6 MINS LATER

11:51
How do you feel about that? Is there a place for LLMs to live in security and in resilience and in chaos, or do they just increase chaos and entropy?
17:13
I'm curious, does, is there an example where traditional compliance actively makes systems less secure, where they think that they're checking boxes, but they're actually hurting themselves?
17:23
Yes.
17:24
Actually, a frequent, uh, co-conspirator of mine, Josiah, um, Dykstra, wrote a paper, not with me, um, it's an excellent paper, um, about that exact topic.
17:35
I think specifically, uh, covers HIPAA and maybe one of the others that shows that it doesn't, being more compliant doesn't actually result in better security outcomes.
17:45
I'm very much of the view, and I've tried to caution regulators as well is, like, well-intentioned regulation in this space very quickly calcifies and ossifies.
17:55
Like, it's what helped in year zero through maybe even year three may end up actually eroding resilience long term.
18:04
Great example, I'll keep the person anonymous, very innovative CISO, um, had to explain, I think over a few years to his auditors, like, "Actually, it's a great thing that we don't allow SSH access anymore," 'cause that's what attackers love.
19:05
And then investors see it, and compliance people see it, and that checkbox is the thing that stands between you and some certificate or some badge, and that's a problem.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.