The Lock & Key Lounge - RIFF Edition 7
Communicate or Perish — Five Cyber Voices Speak To One Idea
“Secure communications” was never just about the tool. In this solo narration episode, Matt Calligan trades the usual interview format for something closer to an essay, building an argument out of five presentations recorded at ArmorText’s first annual Field Notes user conference: that securing how you communicate is really three problems, not one — the channel you talk over, the data you hold, and the identity you trust on the other end. Anchored by Jon Schlegel’s keynote and the phrase introduced that day — “communicare aut perire,” communicate or perish — the episode makes the case that most organizations think hard about the technology while quietly presuming the other two, and rarely test any of them until the day they break.
- Secure Communications Is Three Problems, Not One: How You Talk, What You Know, Who You Trust
Field Notes 2026 — framing by Matt Calligan (ArmorText) - Communicare Aut Perire: You Live and Die by Comms or So Your Adversary Hopes
Field Notes 2026 — Jon Schlegel (CSO, CLEAR), keynote - Two Months of Remediation, and the Adversary Was Reading Every Step
Field Notes 2026 — Jon Schlegel (CSO, CLEAR), keynote - Pilot Flying J: Critical Alerts Consolidated Into ArmorText — Gateway Stood Up From the Back of a Rental Car
Field Notes 2026 — Zach Randall (Pilot Flying J) - Hoosier Energy: A Native Splunk Add-On, Vibe Coded and Open-Sourced
Field Notes 2026 — Dan LaCour (Hoosier Energy) - LS Power: Secure, Out-of-Band OT Incident Response Without Exposing Sensitive Information
Field Notes 2026 — JD Barosh (LS Power) - Assume the Breach: From Prevention to Staying Operational — and the “Classified-Tier” Question
Field Notes 2026 — Matt Calligan (ArmorText) - The Military Solved This 20 Years Ago: Invest in Resilience, Not Just Defense
Field Notes 2026 — Jon Schlegel (CSO, CLEAR), keynote - When Your Identity Infrastructure Is the Attack Surface, Verification Has to Happen Outside of It
Field Notes 2026 — Navroop Mitter (ArmorText) and Jon Schlegel (CLEAR) - Project Grimace: Making the CTI Flood Usable — Because a Feed Tailored to You Is Also a Blueprint of You
Field Notes 2026 — Gonzaga University senior capstone team
Matt:
[00.00.05–00.00.28]
Hey, folks! Welcome to the show. I am Matt, and today we’re going to be doing a slightly different version of The Lock & Key Lounge. No guest is with me today, but I’m in good company. I actually have five voices from our first-ever Field Notes user conference, and I’m going to walk you through them. Here’s the thing, the reason I got to thinking about doing it this way.
Matt:
[00.00.28–00.00.59]
Too many people hear us, and, in general, people talking about secure communications, and they picture a tool. It’s a text thing, it’s a privacy app, it’s a redundant deployment or a tenant somewhere else. And that’s true. But that’s just the how. The how matters, but it’s only about a third of the story. At Field Notes, we introduced a phrase: communicare aut perire or, communicate or perish.
Matt:
[00.00.59–00.01.28]
For the non-Latin speakers, Jon Schlegel from CLEAR put it more bluntly during his keynote: “we live, and we die by comms.” It’s a lesson he learned over 25 years in the military. But outside that world, most of us never really stop to think about what a resilient communication plan actually requires, or how much of it rests, beyond just the technology, on an underlying, invisible substrate of trust. Right?
Matt:
[00.01.28–00.01.51]
We don’t even notice it’s there until it’s gone. So, here’s the framework for today. When we say secure communications, there really are three core things in play: how you talk, the actual technical tool, but also what you know needs securing, as well as who you trust. How you talk is the channel itself. Can it be intercepted?
Matt:
[00.01.51–00.02.15]
Can it be surveilled or altered? What you know is the data, it’s your intelligence, it’s telemetry, it’s alerts, it’s reporting. And who you trust is identity: the assumption, which is mostly unspoken, that the person on the other end of the line is who they say they are. And most organizations, I can’t say all of them, think hard about the first part of this.
Matt:
[00.02.15–00.02.45]
Some of them do. The other two? Almost always presumed, rarely tested. And we do know what happens when that trust layer breaks. Think about that time you got a text from a friend who just changed their number. Pig-butchering scams run on exactly that instinct. This forced familiarity. It’s designed to push you quickly past that sort of high-level mental scrutiny, and straight into the part of your brain that just wants to trust people.
Matt:
[00.02.45–00.02.58]
And that’s the lens for the day: how you talk, what you know, and who you trust. These five presentations from Field Notes, each one living in one of these buckets. Let’s start where the day started itself.
Jon:
[00.02.58–00.03.17]
So, Jon Schlegel, the Chief Security Officer, CLEAR. Prior to that, I served 25 years in the military, and in my time in the military, I worked defensive cyber operations, which is not so fun. That is, every day you show up and it’s like you get kicked in the teeth. And then I ended up going on the offensive cyber side, and I can tell you, offensive cyber is a lot funner,
Jon:
[00.03.17–00.03.29]
If that’s a word, because I feel like you win every single day. I learned very early on in my military career that communications is key. Like, you live and die by comms.
Matt:
[00.03.29–00.03.53]
So that line that Jon says, “you live and die by comms,” is the one that sticks with me, because it clicked something into place I’d never really made the connection with before. We always say here at ArmorText, “if you can’t communicate, you can’t remediate.” But flip that around. That’s exactly true for the person attacking you.
Matt:
[00.03.53–00.04.11]
In war, one of the first things you do is go after the enemy’s communications. That’s not a cyber idea. That’s as old as war itself. Unfortunately, private industry is still catching up to that concept, for the most part. Which is exactly where Jon takes us next.
Jon:
[00.04.11–00.04.35]
Bottom line is, after two months, we started remediating this network, we realized that every time we remediated, the APT was still there, and they were still present. And we started scratching our heads. And that’s when we realized that they were basically admin on every system in that network. And they were also admin on the domain controller.
Jon:
[00.04.35–00.05.01]
So, as we were backing up the domain controller, we were basically giving them re-positions to be able to authenticate back into the network. This took us probably about two months to realize this. And then what we realized is that we were communicating in a channel that obviously had been compromised by the adversary. They could anticipate basically every cyber-defense thing that we were doing.
Jon:
[00.05.01–00.05.14]
They… I mean, they were on the comms channel, in our Teams chat. They were monitoring everything that we were doing. So, this universal lesson learned early in my career is what we still see today.
Matt:
[00.05.14–00.05.41]
So, sit with that for a second. Two months of remediation, and the same, not just more of the progress, the rinse-repeat of going through the same steps over and over, the whole time, the adversary’s just reading along. That’s the core question this raises for me, and for others: what could an attacker learn about your defensive response just by watching your communications channels?
Matt:
[00.05.41–00.06.07]
Because securing what you know, your alerts, your reports, telemetry, everything you’re learning during an incident, that’s just as much a part of the trust layer as the channel itself. Two of our clients at Field Notes took that seriously enough to actually do something about it. Zach Randall at Pilot Flying J and Dan LaCour at Hoosier Energy both made the same call, but with different tools.
Matt:
[00.06.07–00.06.21]
One was routing documentation coming out of Splunk, and the other was routing their automated SOAR alerts, both into ArmorText’s environment instead of leaving it on the regular network. Here’s Zach.
Zach:
[00.06.21–00.06.43]
So, I mean, net outcomes are just, you know, improved quality of life for our entire team, especially when you’re on a smaller team. We’re going to send the critical alerts to an ArmorText thread. When we’re talking about critical alerts that could be telling you, “Hey, you’ve got an incident going on,”you want to see those. So, your EDR, your NDR, your cloud security, email security, whatever other tools you have
Zach:
[00.06.43–00.07.15]
Feed it into your pipeline that goes to your case management. Feed it over to your SOAR, have the SOAR enrich it. And then anything critical, we want to bubble up through the gateway. The gateway is pretty easy to deploy. For reference, I configured it and set it up in the back of a rental car while we were driving to Atlanta, to one of our satellite offices, mostly because my CISO was sitting in the front seat, the deputy CISO was driving the car, and my boss was sitting next to me. And the CISO goes, “Hey, so I know that we have this, when can we have that deployed?”
Zach:
[00.07.15–00.07.24]
And my boss looked at me and said, “Do that now.” So it was really easy. Within an hour, I was able to get it deployed, which was great.
Matt:
[00.07.24–00.07.42]
According to Zach, that setup was a lot easier than you’d think, with our Secure Gateway. My favorite line actually didn’t even make it into this clip, it wasn’t even a line, it was actually the title of one of the last slides he had, and it said, “Ruin date night with an ArmorText alert.”
Matt:
[00.07.42–00.08.07]
And it was tongue-in-cheek, but the point was: now that he was able to consolidate those signals coming out of his environment into just the most critical alerts, when those alerts went off, which, fortunately, was less often than usual, it meant you stop what you were doing if you’re on call. Which is, yeah, that’s the job.
Matt:
[00.08.07–00.08.12]
Dan’s story starts in a similar place, but it gets somewhere different.
Dan:
[00.08.12–00.08.35]
Cybersecurity services that we offer our members, and ArmorText is our main line of communication to them. Our gateway’s been in place for about a year now, and despite that, the process for preparing reports from Splunk and getting them over to the gateway was still kind of manual. My solution to this is what I’m here to talk to you today about: the Splunk technology add-on for ArmorText’s gateway.
Dan:
[00.08.35–00.09.04]
It gives you automated Splunk alerting, access control per conversation, and a containerized gateway built on a Node.js and Ubuntu base, with SSL out of the box and support for internal certificate authorities, if you so choose. One prompt, and then a little bit of tweaking after that, to actually go through and do the debugging side of things. But I had a pretty good time getting AI to do exactly what I wanted, to build the Splunk app, provided you give it all the documentation up front.
Matt:
[00.09.04–00.09.31]
So Dan basically vibe-coded his way into a native Splunk app integration for Hoosier. Now he’s got an automated way to push custom reporting out as part of the cybersecurity services they offer their member utilities. And the coolest part about is its actually open source. So, if you have Splunk and you’re looking for ways to drive some of those alerts into a different environment, if it’s useful, come find us.
Matt:
[00.09.31–00.09.42]
Jon’s keynote also gets this from another side: what it looks like when the adversary is the one going after what you know.
Jon:
[00.09.42–00.10.06]
How many people have their incident response to playbook handy, right? And have that printed off? Because when you have a compromise, can you go and actually find it? Will it actually be on the server? If I was a really good hacker, my job would be to go and remove all of that and cause additional chaos, right? Can we reach out to all of our counterparts across the business?
Jon:
[00.10.06–00.10.09]
Do we have all their phone numbers?
Matt:
[00.10.09–00.10.34]
So maybe it’s not too much of a stretch to think about securing alerts coming out of a SIEM or your SOAR. But here’s the harder question: what about alerts coming off of your SCADA, your DCS, or PLCs? Should those config and access alerts really be landing in a web browser, or an inbox that you have to wake up and check every couple hours if you’re on call?
Matt:
[00.10.34–00.10.38]
Well, JD at LS Power actually already answered that question.
JD:
[00.10.38–00.11.13]
We integrated ArmorText into our OT monitoring and alerting environment to solve a very specific operational problem: securely communicating critical OT incidents without exposing sensitive BCSI information, while still maintaining the speed and coordination required during real-world outages. What we really needed was a secure, resilient, out-of-band operational communication designed specifically for OT incident response. The final architecture leveraged two independent monitoring systems, each with primary and backup alerting paths for resiliency.
JD:
[00.11.13–00.11.28]
We reduced alert engagement time by 40 percent. RFO identification improved by 25 percent. Vendor engagement efficiency improved by 25 percent, contributing directly to reduced MTTR. And, most importantly, unsecured BCSI exposure through operational communication was eliminated.
Matt:
[00.11.28–00.11.58]
So, LS Power is one of the first, actually, to make that jump into OT, routing OT feeds the same way. Once it was validated with the numbers that JD just walked through there, they were actually able to add more and more sensitive context to those alerts, site information and stuff like that. This actually sped up how fast their on-call teams could investigate and triage, even eliminating extra steps at times that just added friction.
Matt:
[00.11.58–00.12.31]
And we’re seeing more and more control-systems teams and SOC teams pick up OT on-call alerting and route it straight into their ArmorText tenant. And it’s genuinely changing how our clients think about OT alerting response. So, this is what it looks like when you actually adopt an assumed-breach mindset: you stop trying to force everything through a “prevent the breach” lens, and you start actually planning for how to stay operational inside this contested environment.
Matt:
[00.12.32–00.12.59]
That’s the conversation that leads our clients to what we’ve started calling the “classified tier” question or classified-tier discussion. Which conversations, which people, which data, or even processes are actually on this critical path to keeping certain business units running? And how much of that belongs inside our out-of-band operational layer, a virtual SCIF, if you want that analogy.
Matt:
[00.12.59–00.13.06]
Well, Jon actually picks up that same thread, but from the military side, which adds even more credibility to it.
Jon:
[00.13.06–00.13.31]
One thing too, as an industry: we invest heavily on the defensive side, but never on the resiliency. A lot of my leadership at any organization I’ve been at, they want to stop the breach. But breaches are going to happen. They’re inevitable. Mythos and all the frontier models, and the advancement of them, are really accelerating the way that threat actors are going to be able to get access.
Jon:
[00.13.31–00.13.48]
Let’s not just try to protect against a breach. Let’s assume a breach. And then how do we then remediate through that breach? And then it all comes back to communication again. Like, you need to have secure comms.
Matt:
[00.13.48–00.13.59]
And here’s the comparison that got me, how the military thinks about communications resilience versus how the private sector still does.
Jon:
[00.13.59–00.14.18]
For us, we had a multibillion-dollar network that we could leverage, and we looked at some of the security controls and we’re like, maybe there’s an assumption that it might even be compromised. On the government side, we had the ability, we had the resiliency, to be able to use other out-of-band communications in order to continue to be secure.
Jon:
[00.14.19–00.14.35]
I’m still shocked, and I’m actually flabbergasted, that in the commercial world, that, you know, we’re talking about this now, like almost 20 years later, that we need to have an out-of-band communication for when incidents occur.
Matt:
[00.14.35–00.15.04]
Okay. So, we’ve covered how you talk, what you know. That third piece, who you trust, this is actually brought up by one of the final presentations at Field Notes, which was a joint one by Jon Schlegel and our CEO, Navroop Mitter. They were walking through the out-of-band identity validation process that ArmorText built with CLEAR for T-Mobile, which has actually been used in nation-state attacks, including Salt Typhoon.
Navroop:
[00.15.05–00.15.28]
In one of the talks that Jon and I gave at GRF last year, we were talking about a study that was done out of Australia. Right? Just to highlight why this problem is so bad, the Australians actually tested 16 of the top deepfake detection technologies in the wild. Any guesses as to how many of them could actually reliably detect a deepfake? Any guesses? One, two, three, four? Zero.
Navroop:
[00.15.29–00.15.46]
One of the other things that came up, there’s a study in Nature around the same time period, and they’re talking about the ability to detect a deepfake voice. And I think it was less than 40% of the time could you reliably detect it. Now, if you think about operating under stress or duress, we’ve all seen the articles now where there are mothers who can’t even identify if it’s their own kid’s voice or not.
Navroop:
[00.15.46–00.16.13]
Right. There’s a company who I won’t name right now, on stage here, but when they were breached, the processes to go back and revalidate everyone that had to be a part of the response effort itself actually took a week, alongside their incident response retainer firm. And so, as a result, all response and remediation efforts were actually pushed back for quite some time because they had realized that they had actually been dialing their own adversaries in, to kind of the point that was being made.
Navroop:
[00.16.13–00.16.28]
In one of the earlier presentations, their adversary compromised the SharePoint, plugged in their own contact details. They were dialing their own adversary into every single remediation call. That’s when they shut everything off and said, “We need to validate who’s who. Can’t trust anything. This might be synthetic.” It took them a week.
Jon:
[00.16.28–00.16.46]
So, to Navroop’s point, if you think about how painful this is, to be able to do this on a manual, one-off basis, without having automation or having a solution, it just ain’t tenable.
Matt:
[00.16.46–00.17.09]
A week. That’s how long it took to revalidate identities across the organization after that SharePoint compromise. And it wasn’t because someone was careless, it was because once an attacker dialed back in through a trusted channel, you can’t just take their word for who people are anymore. And that’s the ball game now with identity. That’s what AI’s impact is on this and deepfaking.
Matt:
[00.17.09–00.17.33]
It’s the layer nobody budgets time for until they’re stuck rebuilding it under pressure because most people are still trying to get their heads around having to use something other than Microsoft for official communications, or, alternatively, not using Signal because their lawyer told them not to. So, last stop today. It’s actually not a clip, it’s a shout-out.
Matt:
[00.17.33–00.18.12]
One of the last presentations at Field Notes didn’t actually come from a customer or a partner. It came from a team of Gonzaga University grads presenting their senior capstone project, something I’ve affectionately taken to calling our skunkworks project. It’s actually called Project Grimace. The problem they set out to solve is: security analysts today are literally drowning. Thousands of reports, blogs, alerts, articles, public CTI, and every other variation are getting published daily.
Matt:
[00.18.12–00.18.40]
I remember one of our clients saying he had 100 different login credentials for various sources of intelligence. And most existing tools just dump that raw volume on your screen without really telling you what matters to your environment, outside of maybe some enrichment. More importantly, it doesn’t say anything about what you do with it, or next steps. What these university students actually built
Matt:
[00.18.40–00.19.08]
It takes that raw flood, and it turns it into something usable. It’s pulling out the relevant threat actors, it’s pulling out the techniques, countermeasures, it’s scoring it for reliability, so you’re not chasing hallucinated context, and then mapping it against your own risk profile. And the part that I like best is this: the sensitive stuff, your network configuration, environment specifics, things that make the intelligence useful.
Matt:
[00.19.08–00.19.34]
It does not leave your premises, right? It stays behind your firewall. The heavy lifting, the aggregated intelligence outside, happens in the cloud, but not inclusive of your environment and configuration specifics. So, it decouples that process from anything that would let someone be able to use that to draw a map of your environment just by watching the tool work.
Matt:
[00.19.34–00.20.00]
Because here’s the paradox with this curated intelligence: the more specific and useful it gets, the more signal there is and the less noise, the more attractive it becomes to exactly the kind of adversary you’re trying to stay ahead of with this stuff. And a feed that’s tailored to you is potentially a blueprint. That’s not something you want sitting in an inbox, or stored in Google or AWS, or reachable through a browser tab.
Matt:
[00.20.00–00.20.30]
This is still an early project. The roadmap for what this becomes isn’t entirely baked in, and honestly, we’d rather it be shaped by the people who actually use it than us just sort of guessing in a vacuum or trying to mimic the wrong way of doing it that’s already out there. So, if you’re a threat hunter or CTI analyst and you have opinions on what this could do for you, and maybe some capabilities or features you’d like to see in a tool like this, definitely reach out to us.
Matt:
[00.20.30–00.21.00]
We’re looking for folks to help us figure out this final list, and how to make it a good offering for everybody. And that’s just us trying to do our part, we’re not just building this channel, this operational layer, but we’re helping make the people who are using this, the ones doing the threat hunting, feel a little less overwhelmed. So, that’s Field Notes for today, in five stories. How you talk, Jon’s lesson, 25 years of learning it the hard way.
Matt:
[00.21.00–00.21.30]
What you know, Zach, Dan, and JD, each finding a different reason the data itself, what you know, needed a more secure home. And who you trust, the identity work Jon and Navroop built with CLEAR and T-Mobile, and a team of Gonzaga grads trying to make sure that the people defending all of it aren’t just drowning while they do it. If there’s one thing I’d like you to take from this, if you’re listening still, it’s that secure communications was never just about a tool or a cool technology.
Matt:
[00.21.30–00.21.46]
It’s the channel, it’s the data, and it’s the identity behind it. And most organizations are really just starting to think hard about that first one. So, thanks for sticking with me today. And until next time. Be well, stay curious, and do good work.