Devin Lukomski: Cyber Isn't an IT Problem, It's an Everyone Problem
About this episode
Devin Lukomski, president of OTM Cyber, makes the case that cybersecurity is not an IT problem but an everyone problem. His firm protects 911 call centers and public safety infrastructure, where seconds of downtime can change whether someone survives a cardiac arrest. Lukomski spent his whole career in the military, moving from infantryman to field artillery officer to cyber and electronic warfare before leaving service in 2022. He joined OTM Cyber as an intern and helped grow it from four employees to nearly twenty, with almost a hundred clients across seventeen states.
He explains why he runs a staff of fifteen AI agents but never hands them the final decision, drawing on military mission command principles. He notes that roughly 90 percent of breaches trace back to a user error, and points to deepfake voice impersonation and indirect prompt injection as emerging threats.
In this conversation
- Why securing 911 is unlike any other cyber work, when seconds of downtime can decide whether someone survives
- The military lesson that shaped his leadership: be a good follower first, with humility
- Applying military mission-command principles to a "staff" of fifteen AI agents, without handing them the decision
- Why cyber is an everyone problem, with 90 percent of breaches tracing back to user error
- The rise of deepfake social engineering and indirect prompt injection
- Scaling OTM from four people to nearly twenty, with almost a hundred clients across seventeen states
Full transcript
Welcome back to another episode of the Agentee Digital Podcast. Today I'm joined by Devin Lukomski, the president of OTM Cyber. Devin, it's great to have you here today.
Yeah, I'm really excited to be here, really excited to have a conversation and thank you. Thank you so much for having me on.
Great, so I guess to get this kind of going for anyone who doesn't know you yet, who are you and how did you end up running OTM Cyber?
So I it's a it's not the usual way. I'll I'll start with that. So I my entire career was military before I got to where I am now. And I actually only got out of the military a few years ago in twenty twenty two. And
In the military I did a lot of different things. I I started off enlisted, I was an infantryman, and then I was a field artillery officer and did some time as an instructor in that field. And then I transitioned to cyber and electronic warfare at the end of my military career. And then I had a really neat opportunity to be a part of creating this new type of unit that was focused on leveraging space information, cyber
electronic warfare capabilities in in a big theater wide application. It was a new type of unit. And that was a really cool experience. But I decided to make the transition out of service and go on to something new. And as part of that, I got to do an internship. And I went through the process of finding where I was going to do my internship. Stumbled upon this company called OTM Cyber and
said, hey, here's who I am, here's my background. I I'd like to do an internship with you guys. And I talked with the founder at the time, Jamie, and I'll probably mention him another other times during this call, but just because him and I work so closely together. But he was like, Yeah, I'd be really glad to have you on. There are some things I'm trying to do to to scale and grow this business. And I think your your input would be really valuable. So
Started that internship and I guess Jamie did see the value in what I was doing. e e even as an intern, I was doing things like organizing some of the big training events that we were putting on for clients and got us started with looking at how do we formalize procedures, SOPs, and even then kind of finished up the internship portion as
Okay, let's find some funding so we can scale this whole thing. And we didn't do we didn't get anything crazy. We did like a pre seed round of funding from angel investors just to get things kinda going. And got like a half million dollars. Again, nothing crazy, but enough to get get the ball rolling. And at that point in time we were by gosh, like four employees and a handful of clients and
Mm-hmm.
Here we are a few years later and I've stuck with it and we've grown this thing. We're we're now up near twenty employees. We've got clients across seventeen states in the US and almost a hundred clients, so it's been really cool.
Hm.
Hmm. That's great. And is there any lesson that you've learned from the time that you've been in the uniform? That kind of yeah.
my gosh. Yeah. I
I yeah, there's a lot. I I have a lot of things to be grateful for for my time in uniform and and really what that taught me about being in leadership, being a servant leader, and just the organizational skills. I think the biggest thing that I learned in uniform
Mm-hmm.
is it's important to be a good follower first. And I think that that applies to anything. I j I don't mean purely organizationally. I mean anytime you are approaching learning something new, you need to approach it with a level of humility and and learn how to be the follower before you're gonna before you're gonna master this thing and then
take off into y you know, maybe the leadership aspects of whatever it is. So I would say it has applications both organizationally as well as individually and how you approach just the process of learning.
Mm. And so now now you're at what, twenty people, you said? so where where do you spend most of your time these days? You know, when
So yeah, I I do a lot of traveling. like you and I were chatting a little bit before we started, but mentioned the fact that I I go and I do a lot of speaking engagements. We're we do po cybersecurity for public safety. So nine one one call centers when folks have emergencies where they call those hubs need cybersecurity and they're becoming
like everything else, ever more digitized. And so the need is becoming more apparent. And a a lot of what I do is traveling to these different trade shows, these different conferences, and delivering educational sessions about just that fact. And those range in everything from here's basic, like user level cybersecurity training, all the way to here is
Mm-hmm.
everything on the horizon in terms of AI and its implications for cybersecurity. So that's that's a lot of what I do. additionally I I focus on running the business. We are still very small and we are still what I would certainly consider a startup. So I do have to wear a lot of hats. I I do a lot of the things that a COO, a CTO, well not the CTO, the our founder handles that, CFO is what I meant to say.
But like COO and CFO type stuff are definitely things that are still in my lane. So focused on what are the market trends in terms of growth, how do we think that looks in terms of revenue and expenses projected out over the next five to ten years, management of that small pool of angel investors that we initially got, and just the day-to-day operations and policy changes and things like that for our company. And a lot of that
Mm.
has changed too with the big application of AI and and the boom that we've now seen with it too.
Hmm. And with all of these trade shows that you're doing, I I mu I must assume that like a lot of business gets through the door that way, right? When you when you provide valuable information. is that also like a way that you guys are kind of getting new people in the door or do you guys have any special tactic around that?
Yeah, that is that is really what it centers around, right? Is two two things. One is we do believe that 911 and public safety your critical infrastructure and they need to be secured and we should be getting the message out about that. Even if it's not us that ultimately provides the cybersecurity, it is important for them to have some form of cybersecurity and good cybersecurity practices. The second thing is kind of what you alluded to, is we get out there
we're showing we're building trust because we too truly believe in the cause and we are helping provide education, but additionally that establishes us as a thought leader in the space. It establishes us as an expert, a subject matter expert in the space. And yes, that does ultimately result in getting some some clients that head our way as a result.
Hmm. That's great. And and you know, in the work that you guys do in critical infrastructure and nine eleven systems, I think failure is not an option there, right? So what what is something that people in the cyber security kind of get wrong about?
Yeah.
protecting these systems that you know generally cannot go down.
Yeah, it's a good question. I do think that across the cybersecurity industry, certainly for those that are well meaning, everybody is striving for a hundred percent uptime on the clo the whoever the client is, they want to ensure they're never going down because of a cyber attack. But certainly in our space there is a level of criticality because if the if nine one one goes down
even even for seconds or minutes that can result in pretty high changes in terms of survivability for someone who's going through cardiac arrest, for instance. So the unique thing when it comes to this space, I think, really centers around its architecture and knowing the ins and outs of what nine one systems are like.
And this is true for cybersecurity companies. I think regardless of what industry they are focused on, there's always going to be specific nuances. But for us, we are specifically focused on continuity of operations and building in even extra resilience to our security for those clients. Additionally, we don't want to be in a situation where we become the bottleneck.
Or we become the thing that causes them to go down. For instance, I I've known of situations where a cybersecurity provider has maybe a hardware appliance in line that's providing providing it the telemetry. It's a sensor. And for some reason that thing loses connectivity and it becomes a block to that center's connectivity. We we we architect everything in a way so that that never becomes a problem.
And so that we have resiliency built in every step of the way. And I think a lot of security providers probably do those things regardless of who they're catering to. We're just especially aware of the resilience aspect because the consequences are so tangible for nine one one.
Mm.
Interesting. And where do you think these AI agents come into place? Because I know that you've written about you know applying military mission command principles to the to these AI agents. And so what what does mission command actually mean? And why do you think it matters for how
these autonomous agents, you know, should operate.
So great question. and yeah, I did I did an article on that very recently. And it is reflecting directly on my military experience. And the way everybody can think about Mission Command is it is just a fra it's just a leadership framework for how you tackle a set of problems. And the if folks want to read that article, they can. I I'm not gonna go too much into the like nitty gritty detail. But the idea is that framework provides
Hm.
roles for everybody within a given staff that I think are applicable even outside of the military. And the role of the commander, who is the head of an organization within the military, they need to understand, visualize, direct, lead, and assess. Those are the kind of the things that the commander is ultimately tasked with because the staff is then
Mm-hmm.
Doing the things, creating the products, looking at maps, looking at intelligence, looking at enemy capabilities, looking at our capabilities, and doing all those things and and providing information to the commander so that the commander can make decisions. The translation for all of that to c the corporate world, I think is like fairly clear for a lot of folks. You know, usually in the corporate world you have
a leader, you have a CEO, you have a president, you have a chief of staff that might work under that person and then manages the staff to do something very similar to what I just described. It's really translatable though, and this is the novel thing, to the use of AI agents. And we've used AI and agents in some pretty specific ways within OTM Cyber that I think are novel and I think are leading edge. And I can elaborate on those.
But it it's a little bit outscope outside the scope of this specific question. So I look at that mission command framework as something really applicable to the use of how you manage a set of AI agents. And really it centers around not turning over the decision-making power to the agents themselves. Because the human element
And our capability to critically think is even more important when you have the easy button of hitting AI agent, do this thing, determine the course of action, determine what the best one is, and then execute it. I think it's dangerous, certainly in cybersecurity dealing with critical infrastructure, to hand off all of that. That doesn't mean that I'm saying don't use AI.
Mm.
'Cause I love using AI. I've got an agentic staff of like fifteen agents and interact with them regularly. But I use this same framework because I sit there and I'm I'm the leader of that staff and I might not be the one making a presentation. I might not be the one updating the Excel document or whatever the end product is. But I am going through iterations with that staff to say.
Okay, this is this is the vision, this is the intent and the objective. Let let's discuss how we accomplish it. There's a little bit of collaboration there, and then I'm ultimately making the decision on on how things get executed in the end. And I think that that really replicates that mission command, at least that set of mission command principles that I discussed in that article, and the role of the commander.
ri really quite well. I and I just think it's important that the critical thinking still be done by people. And I and I know the temptation. I know the temptation to just hand the task off to AI. But what I think everybody will see, if they haven't already, in at least microcosm, I think everyone will see that the really good stuff happens when
we lend those human aspects of emotion, critical thinking, and those human elements to the light speed and efficiency of AI and and you you hybridize the approach and and that's really what the way we've been approaching a lot of things.
Hmm. Hmm. Got it. Yeah, I also sometimes find myself letting AI do like stuff that I think should be done by me in some sort. But yeah, you know, it's it's there is a very thin line I f I believe between what what AI should be doing and what you know where the leverage is for the human.
So it's
Yeah, certainly. And something that's a really good tool with that is you can have the AI interview you one question at a time to determine your intent, your vision for whatever this thing is. And then I think it captures a little bit more that's like one of those like really early useful tools in these kind of workflows that helps bring through your thoughts a little more instead of just having like
Mm-hmm.
Mm.
an AI generated social media post or an AI generated paper, whatever the end result might be.
Hmm. Yeah. Now Devin, you've must seen a lot of things, you know, over over the years of working in cyber. Now s so I guess there must be some common p patterns that occur when you know someone comes to you with a problem. So what is kind of the common mistake that you find these
Teams making
Good question. I think that the most common mistake is almost a cultural or philosophical one. And that is folks like to and I understand again it's it's comfortable to offload accountability and responsibility to someone else for something. and the truth of the matter is cyber is a not an IT problem.
It's an everybody problem. And the evidence of that is
I'd say this I'm reflecting on my own anecdotal evidence here. I know there's stats about this out online too, but the way that some sort of breach or some sort of cyber attack happens is traceable back to an error by a user like 90% of the time. It's very rare that
someone just hacked on in without something happening to the left of that, like there was a malicious link or there was sent in an email, for instance, or there was some sort of USB device that got plugged in somewhere, or things like that.
And I know that sounds very pedestrian, but it is the truth of the matter because folks a lot of times will think like I I'll just do the things that I do and and most people are getting more wary nowadays, especially when it comes to like phishing emails and stuff like that. But but the bad actors out there are getting more advanced too, especially with AI. And
have new ways to try and trick people and socially engineer people into doing things or giving up information that opens the door for the for the threat actor to get in. An example of the AI thing there is the deep fakes now. You know, you have folks impersonating the voice of people's supervisors to say like, yeah, you gotta give me VPN access. I forgot my credentials, stuff like that. And then you've given someone a remote session into your network.
That's that can be devastating. so those are some examples. But to the simple answer to your question is cyber is not an IT problem, it's an everyone problem. And and that mindset is really helpful when everybody internalizes that they have a part to play in the cyber defense of their organization.
Mm.
Mm-hmm.
Now that we're wrapping this up, I would like to ask you now that you know OTM is growing, there must be something that you would like to fix it with a snap of the finger. What would it be for you and where can people find you?
So let me I hate to answer a question with a question, but do you mean like something internally to my organization or like a big cybersecurity problem that I would want to fix?
Well we can do both.
Okay. gosh, that's a good question. And I'm gonna have to come up with s probably some subpar answers on the fly. But I think that internally, within my own organization, something I would love to fix is I would love to be able to I would love to be able to speed things up. We're growing at a huge rate and and things are moving very quickly and we've been able to provide
raises for our employees year after year that are like big chunky ones because we've been growing but we're still in that start up phase. The thing I would love to fix is I would love to be able to pay our employees closer to what I think that they are are worth. I I think they I think everybody deserves more. And I'm not saying myself or like Jamie or the executive staff. I mean literally I I want to be able to provide more benefits and pay the employees more. That's the thing I would fix internally. Externally
Like big s big big cybersecurity problem I would want to fix with with the wave of a magic wand would be I would want to have cyber tools that are quantum capable. And that is very much a magic wand, right? Because we o we don't even have we don't even have quantum capable computers just yet. But
Mm.
When I look at the cyber when I look at the landscape, cyber landscape and the evolutions of what we're having to protect against, the what what's the currently emerging threat is AI driven. It's the speed at which threat actors can get access to tools, capabilities, or even just vibe code them using AI agents.
As well as indirect prompt injection, IPI, that's a big emerging threat. Agents go out there, they look at code on a website, there's hidden stuff that redirects them to give away credentials or something like that. we've we've created technologies that protect against IPI, but it it's getting better all the time, like any cyber defense technology.
But the quantum thing is the big is the big next thing, right? Because, you know, quantum's gonna be created and it can break like all the encryption in the world in some like astoundingly short amount of time, like minutes. so that turns cybersecurity kind of on its on its head. And if I was thinking of a magic capability, that's it.
Hm.
Hm.
Hmm. Hmm. Okay. And to to the other part of the question, where can people find you, Devin?
yeah, I I totally missed that. My apologies. So I'm on LinkedIn. I try to be pretty pretty active on there. People can always find me on there. The OTM Cyber website is OTM Cyber dot com. So pretty easy to find stuff there. And we try to be pretty active with posting like thought leadership articles, things about new capabilities in the cyberspace on there as well. And certainly for those in the public safety space.
They can find me at any number of conferences over the year. The big national ones are coming up, National NENA and National Apco and I'll be I'll be there at those.
Great. Well thank you for joining, Devin.
Thanks. I really appreciate it. This has been a great discussion and I think you've got a great thing going here, so keep it up.
Thanks.