Cybersecurity Best Practices – A Conversation with Doug Shepherd at Tanium Converge – Futurum Tech Webcast

Cybersecurity Best Practices - A Conversation with Doug Shepherd at Tanium Converge

On this episode of the Futurum Tech Webcast, host Shira Rubinoff is joined by JLL‘s Doug Shepherd, Senior Director, Offensive Security, for a conversation on the key insights and takeaways from Tanium’s Converge Conference.

Their discussion covers:

  • The evolving landscape of cybersecurity challenges faced by organizations today
  • Strategic insights into offensive security measures
  • Best practices for organizations to enhance their cybersecurity posture
  • The role of collaboration and knowledge sharing in advancing cybersecurity defenses
  • Future trends and predictions in cybersecurity

Learn more at JLL.

Watch the video below, and be sure to subscribe to our YouTube channel, so you never miss an episode.

Or listen to the audio here:

Or grab the audio on your streaming platform of choice here:

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Transcript:

Shira Rubinoff: Hi, this is Shira Rubinoff, president of Cybersphere, a Futurum Group. I’m here with Doug Shepherd, at Tanium’s Inverge Conference and the first stop of the world tour. Doug, it’s such a pleasure to be with you here today. Please introduce yourself to our audience?

Doug Shepherd: Pleasures mine. Yeah, so I’m Doug Shep Shepherd. Most people call me Shep. And I run offensive security and insider threat at JLL. I’m a senior director there. JLL is a very large commercial real estate company, and we have a lot of endpoints, and we are in about 80 countries.

Shira Rubinoff: Let’s get right to it here at the Tanium Conference, and typically in the past, organizations would buy technology based on who else was buying that technology? But as advancement of technology happens and our advancement in terms of our security world, we now know all the organizations are looking for the best fit and the right product for the organizations because there’s no one size fits all. So I’m curious, what led you to Tanium?

Doug Shepherd: So coming into COVID, we had a lot of tech debt. And we realized that tech debt almost immediately, that we just didn’t have enough telemetry and visibility into our endpoints to know what was happening when they weren’t in one of our buildings and instead were in our employees’ homes. And so we immediately realized we needed some sort of solution to address that, and Tanium really is the only player in that market that would allow us to get that kind of visibility, that kind of inspection, that kind of instrumentation on our endpoints.

Shira Rubinoff: So let’s talk about visibility for a moment. What level and what depth of visibility is provided, and what is needed? Maybe the plus industries.

Doug Shepherd: I would always say you need a little more visibility than you have. So for us, we didn’t have enough visibility into patching, even enough visibility into what employees were doing day in and day out and how that would impact sort the security of the endpoint, so without that level of visibility, we were just hoping that our security really would fix that visibility issue, and it really wasn’t because we were only getting visibility if somebody had malware on their endpoint, and there’s a lot between good and definitively evil.

Shira Rubinoff: Certainly, and now we’re positioned in the industry, it’s if we’re going to be attacked, it’s when, and every organization’s sitting there, “When is it going to happen? Are they going to pull the trigger? Is it going to happen here?” So sitting there in your organization and understanding the needs, the visibility, the types of security you have to have with organizations, how important it is to find the right fit and not just a solution that would just cover what is needed.

Doug Shepherd: That’s right, and frankly, our security stack before coming in had been a threat we thought that we were responding to, and that ended up needing to evolve quite a bit, right? So we’d gone with best in breed solutions just because we felt like it was the right thing to do, but whenever it really came push to shove, we found that the solutions were not delivering the performance and the security we’d expected them to. So Tanium allowed us to see that, to get insight into, there was a lot more happening on the endpoint than just malware, and there was even malware that was happening on the endpoint that we weren’t really being notified about with our solution before moving to Tanium and now MDE.

Shira Rubinoff: Oh, that’s really important now, thank you for sharing that. And let’s just make it a little broader across the cybersecurity atmosphere itself. Where would you say our world is going in the cybersecurity atmosphere? What do we have to pay attention to, and what are the biggest threats that you perceive to be in the cybersecurity world?

Doug Shepherd: Absolutely. I could talk about this for days and I rant on.

Shira Rubinoff: Go ahead, time’s yours.

Doug Shepherd: So a lot of people are concerned about Chinese intrusions or Russian intrusion nation state intrigue in their networks, and it doesn’t make sense. At the end of the day, what you should really be concerned about is ransomware. You should be worried about your users clicking on things, and you shouldn’t be worried about some nation state trying to steal your secret cookie recipe or something like that. You should be more worried about threats to your revenue, to your reputation. Data loss events, like we saw last year with MOVEit. Those are the big events people should be concerned about unless about the nation state intrigue.

Shira Rubinoff: Certainly. And I always ask people who I interview, what is one pointer you give our audience about being cyber secure? What would you say is, “This is something you should think about.”

Doug Shepherd: You need to have a slightly longer password. Whatever your password is today needs to be slightly longer.

Shira Rubinoff: Well, Doug, it’s such a pleasure speaking with you, and thank you for all your insight and I hope you enjoy yourself here at Converge.

Doug Shepherd: Pleasure’s mine. Thank you very much.

Shira Rubinoff: Thank you.

Author Information

Shira Rubinoff

Shira is a global keynote speaker and presenter, and expert media commentator.

Related Insights
Exprivia Bets on Deepfake Detection to Win AI-Security Deals
September 16, 2026

Exprivia Bets on Deepfake Detection to Win AI-Security Deals

Exprivia's alliance with identifAI brings specialized deepfake detection capabilities to high-stakes verticals including banking, healthcare, and public administration, capitalizing on explosive growth in AI software and cybersecurity channels....
Rubrik's MCP Launch Bets on Agentic AI as Cyber Resilience's Next Layer
September 16, 2026

Rubrik's MCP Launch Bets on Agentic AI as Cyber Resilience's Next Layer

Rubrik announced MCP support powered by Claude, enabling enterprise AI agents secure access to Rubrik Security Cloud for machine-speed incident response....
Scalian Completes Skills & Affinity Integration to Build Sovereign-Engineering Scale
September 16, 2026

Scalian Completes Skills & Affinity Integration to Build Sovereign-Engineering Scale

Scalian has completed the brand integration of Skills & Affinity, finalizing a 2025 acquisition sequence that positions the company as a reference actor in sovereign engineering with €550M revenue and...
Thales Embeds Cyber Defense Into Vietnam's Aviation Growth Story
September 15, 2026

Thales Embeds Cyber Defense Into Vietnam's Aviation Growth Story

Thales elevates its role from component supplier to strategic digital transformation partner in Vietnam's aviation sector through dual agreements with Vietjet covering MRO services, cybersecurity, and AI capabilities....
CISA and G7 Make PQC Transition an Immediate Imperative
September 11, 2026

CISA and G7 Make PQC Transition an Immediate Imperative

CISA and the G7 prioritize post-quantum cryptography now, not later. Red River's Quantum Cryptography Accelerator directly addresses their five key areas and counters the "harvest now, decrypt later" threat....
Exprivia Bets on Risk Management as Cybersecurity's Next Frontier
September 10, 2026

Exprivia Bets on Risk Management as Cybersecurity’s Next Frontier

Exprivia pivots from reactive cyberattack response to proactive risk management, positioning itself to capture significant market share as 62.4% of channel partners cite cybersecurity as a top 2026 growth driver....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.