YouTube2Text

Why Hackers Are Winning the AI War (With Lee Rossey) - Ep #246 — Transcript

by Future Tech and Foresight Podcast · 10,983 words · 1,595 segments · language en · Watch on YouTube

Full transcript

  1. 0:00How have you found the edge cases in
  2. 0:03this new world that we're experiencing?
  3. 0:06Like my assumption is new edge cases are
  4. 0:08kind of coming up all the time because
  5. 0:09you got these hackers that are notorious
  6. 0:12and innovative and they're coming up
  7. 0:13with new ways of attacking. What we do
  8. 0:15is we create maybe hundreds or thousands
  9. 0:18of nodes and actual applications and
  10. 0:20users creating traffic. Real networks
  11. 0:22are dorky, messed up, misconfigured,
  12. 0:25have all kinds of weirdness. And so you
  13. 0:28want to be able to have legacy systems,
  14. 0:30mainframes, OT infrastructure that has
  15. 0:34like power company things in there. So
  16. 0:36you want to create all these different
  17. 0:37variations. So it's training and
  18. 0:39understanding all the nuances. But I
  19. 0:41think over time it's also important to
  20. 0:43be able to say I'm going to give you
  21. 0:46wrong data, misconfigured data,
  22. 0:48different policies. And now quote
  23. 0:50unquote agent, you got to make a
  24. 0:51decision just like a human would, which
  25. 0:54is I got conflicting, incomplete,
  26. 0:57erroneous data, yet I still need to make
  27. 0:59a decision. And so can these AI and
  28. 1:02agents start building that knowledge of
  29. 1:04what do they do under weird conditions?
  30. 1:06And that's I think where we are best in
  31. 1:08class to do all that.
  32. 1:17We're going through something absolutely
  33. 1:19historic. Technologies across the board
  34. 1:22are growing exponentially.
  35. 1:23>> It's a disruption that's going to
  36. 1:26completely redefine the way businesses
  37. 1:28compete.
  38. 1:28>> In the next decade, we're going to lose
  39. 1:2940% of today's Fortune 500 companies.
  40. 1:32>> The exponential growth of computing is
  41. 1:34continuing.
  42. 1:35>> AI is nowhere near its full potential.
  43. 1:38whether you like it or not, that the
  44. 1:41future cannot be stopped by anyone.
  45. 1:44>> Welcome back to the Future Tech and
  46. 1:45Foresight podcast. I'm your AI host,
  47. 1:48Mark Verbangov's Deep Fake Avatar, and
  48. 1:50this is episode number 246.
  49. 1:53Cyber Security used to be a highly
  50. 1:55technical game played mostly by nation
  51. 1:57states and elite military agencies.
  52. 2:00Today, artificial intelligence has
  53. 2:02completely lowered the barrier to entry,
  54. 2:04allowing amateur hackers to launch
  55. 2:06prolific automated attacks against easy
  56. 2:09targets like hospitals and small
  57. 2:11businesses. Threat actors now operate
  58. 2:13like highly efficient corporations,
  59. 2:15using advanced tools to aggressively
  60. 2:17scale their offensive capabilities. This
  61. 2:20massive shift means defensive strategies
  62. 2:23must evolve just as quickly to keep up
  63. 2:25with the chaos. To fight back,
  64. 2:27organizations can no longer rely on
  65. 2:30simple software updates or theoretical
  66. 2:32security protocols. They need to build
  67. 2:35realistic cyber ranges, essentially
  68. 2:37flight simulators for digital networks
  69. 2:39to safely test how AI agents and
  70. 2:42security tools actually perform under
  71. 2:44heavy fire. We are rapidly entering an
  72. 2:46era where having an AI proving ground is
  73. 2:49a fundamental requirement to stay
  74. 2:51online. Companies that take the time to
  75. 2:53stress test their systems today will be
  76. 2:56the ones left standing when these
  77. 2:57automated threats hit peak production in
  78. 2:59the coming years. A little bit about
  79. 3:01today's guest. Lee Rossi is the
  80. 3:04co-founder and chief technology officer
  81. 3:06at Simspace, bringing over 15 years of
  82. 3:09experience from MIT Lincoln Laboratory
  83. 3:11to the front lines of digital defense.
  84. 3:14Today he is focused on exposing a
  85. 3:16dangerous disconnect in modern business
  86. 3:18leadership. While 78% of executives feel
  87. 3:22highly confident in their cyber
  88. 3:23security, actual defensive readiness
  89. 3:26scores often sit as low as 30%. Having
  90. 3:29watched AI rapidly lower the barrier to
  91. 3:31entry for amateur hackers, Lee actively
  92. 3:34challenges the outdated we've always
  93. 3:37done it this way mentality, he helps
  94. 3:39organizations build rigorous AI proving
  95. 3:41grounds where security teams can safely
  96. 3:44find out what actually breaks before a
  97. 3:46live deployment. Through his work at
  98. 3:48Simspace, Lee continues to push the
  99. 3:50industry away from assumed safety and
  100. 3:53toward a future of truly battle tested
  101. 3:55cyber defenses.
  102. 3:57Cool. Um Lee, thank you so much for
  103. 4:00coming on to the podcast today. Uh as I
  104. 4:01mentioned right, uh you know, a couple
  105. 4:03minutes ago, I am very much looking
  106. 4:04forward to this. Um yeah, I think the
  107. 4:08audience knows that we've been hacked a
  108. 4:09couple times now. It wasn't us. It was
  109. 4:11actually through a client and then we
  110. 4:12got compromised or part of the system
  111. 4:14got compromised through them. and I kind
  112. 4:16of have a sense of what's going on in
  113. 4:18the cyber security and the hacking, you
  114. 4:21know, like crazy industry, but I'm I'm
  115. 4:23much more interested to hear what what
  116. 4:25your thoughts are on this today. So,
  117. 4:27thank you very much for coming on taking
  118. 4:28the time to chat.
  119. 4:30>> Absolutely. I'm excited to be here.
  120. 4:32>> So, uh before we dive into all that kind
  121. 4:34of interesting stuff, um what brought
  122. 4:36you into the cyber security world?
  123. 4:40>> Um accident I guess. So
  124. 4:44like any good young engineer graduating
  125. 4:47from school going off, I was a robotics
  126. 4:50double E doing computer engineering
  127. 4:52stuff and ended up at a shop and then uh
  128. 4:55over at another one. But uh quick answer
  129. 4:57is two years after school I ended up at
  130. 5:00a place called MIT Lincoln Lab which is
  131. 5:02one of these national uh national labs
  132. 5:04focused on applying you know advanced
  133. 5:06electronics and national security. So,
  134. 5:08it's what they call a fedally funded R&D
  135. 5:09center. And um you know, when we started
  136. 5:12going over there, started getting into
  137. 5:14more programming and software and test
  138. 5:16beds and environments. And I guess I'm
  139. 5:20old, but that was 26 years ago. Uh was
  140. 5:24laboratory. We were in the early phases
  141. 5:26of it.
  142. 5:27>> Um and started working there for 15
  143. 5:30years. And eventually we spun out the
  144. 5:32company in 2015 and here we are 11 years
  145. 5:35later uh with the company. Awesome.
  146. 5:37>> So the interest I guess by accident um
  147. 5:40young engineer you kind of just
  148. 5:42gravitate towards a particular field and
  149. 5:44um by the way it's been exciting. Uh you
  150. 5:47wouldn't imagine it kind of blows up to
  151. 5:49this point now but it's that's the
  152. 5:51starting point.
  153. 5:52>> Yeah. Well I think you know I as I
  154. 5:54mentioned before I've had a couple cyber
  155. 5:56security experts come on the podcast
  156. 5:57throughout the lifetime of the podcast a
  157. 5:59lot more in the last say 6 months or so.
  158. 6:02I'm I'm getting a sense that there's a
  159. 6:05bit of a change in the air, shall we
  160. 6:07say, in in your industry based on
  161. 6:10concerns or I don't know if confusion is
  162. 6:13the right term, but maybe like like it's
  163. 6:16a nebulous world like people don't know
  164. 6:18what's happening. They know that
  165. 6:20security is important. Um but anyways,
  166. 6:22I'm looking I'm looking forward to to
  167. 6:24diving into some into some things here.
  168. 6:26Uh yeah, but um my view is um it really
  169. 6:31hasn't changed much. There's always the
  170. 6:33cat and mouse game going back 20 30
  171. 6:35years. It was always attackers,
  172. 6:36defenders.
  173. 6:37>> Um but it used to be a small little
  174. 6:39niche audience that was just the guys
  175. 6:41hacking away. Nobody really knew. Then
  176. 6:43it was more into like the militaries and
  177. 6:45hacking each other or the intelligent
  178. 6:47agencies trying to steal data from other
  179. 6:48countries uh quietly and all that. But
  180. 6:50it was never really in the news. I would
  181. 6:52say that in the 20
  182. 6:552010s 2015s it started getting okay now
  183. 6:59companies are getting hacked like the
  184. 7:00banks and the other ones and then it's
  185. 7:02more like ransomware and a little bit so
  186. 7:04the awareness goes more and more and now
  187. 7:06with AI oh now it's everywhere to do
  188. 7:08this so it's always been happening but
  189. 7:11now it's faster and more aware so just
  190. 7:15like in your example it's not just
  191. 7:16hitting big banks and big militaries and
  192. 7:19large enterprises you know trying to
  193. 7:21take money. It's It's prolific. Why?
  194. 7:24Because the barrier to entry, if you
  195. 7:25will, got so low. It's easy to build the
  196. 7:27tools. It's easy to automate. It's like
  197. 7:29>> unleash and find stuff. And um before it
  198. 7:32used to be a bunch of like sophisticated
  199. 7:34guys that knew the craft, call them
  200. 7:36hackers, but it was people that knew the
  201. 7:38tech, knew the inards of how the stuff
  202. 7:40worked, could build and craft exploits
  203. 7:42and do it covertly.
  204. 7:44>> Now, a lot of that's been automated. So,
  205. 7:47right.
  206. 7:47>> Yeah. So, you're seeing it a lot more.
  207. 7:49>> Yeah. So, so there's more I mean there's
  208. 7:51just more as as you said the uh the
  209. 7:54barrier to entry has has gone down. So
  210. 7:56you just have more people
  211. 7:57unsophisticated people being able to do
  212. 7:59it like I think I think the the
  213. 8:02specifically the first hack in February
  214. 8:04for me was very sophisticated. It was it
  215. 8:07was you know months in the in the I
  216. 8:10don't know if it was a planning stage or
  217. 8:12if it was like you know one company
  218. 8:14hacked my client waited around sold the
  219. 8:16data right and then it just moved up the
  220. 8:18chain but it took it took the better
  221. 8:20part of like eight months for the
  222. 8:22compromise to finally hit to hit my
  223. 8:24company.
  224. 8:24>> Yeah. That sounds reasonable. And and a
  225. 8:27lot of things that by the time you see
  226. 8:28the the stuff in the news, it may it may
  227. 8:31be months or years of planning, of
  228. 8:33reconnaissance, of getting in, finding
  229. 8:34the right things, and eventually
  230. 8:36quotequote pulling the trigger on doing
  231. 8:38it. And that's always been the case. And
  232. 8:40you hear about this notion historically
  233. 8:42like script kitties, you have
  234. 8:43sophisticated guys that know what
  235. 8:44they're doing, and then the tools got
  236. 8:46commoditized like 10 years ago
  237. 8:48>> where you had less sophisticated
  238. 8:50operators that would use some of these
  239. 8:52tools to kind of go in. The bar got much
  240. 8:55lower now because the AI agents can
  241. 8:57start doing a lot of that work. So a lot
  242. 8:59of that tedious time consuming
  243. 9:02reconnaissance, understanding, finding
  244. 9:04vulnerabilities, making it
  245. 9:07>> would take weeks to months to a year.
  246. 9:09Now it's a lot faster. And so
  247. 9:13>> um yeah, I agree. I you know what we
  248. 9:16were doing something years ago. So we
  249. 9:18create cyber ranges, realistic
  250. 9:19environments for trading and testing.
  251. 9:20And we're working with some of the early
  252. 9:21cyber security companies and they wanted
  253. 9:23to figure out what adversaries are
  254. 9:25doing. They said, "Hey, you guys have a
  255. 9:26perfect environment. Let's create a
  256. 9:27deception network. Let's create an
  257. 9:29environment like a honeyet that we can
  258. 9:31put on the dark web, see it, see what
  259. 9:33adversaries are doing to kind of learn
  260. 9:35intent. What are they going after?"
  261. 9:37>> And 10 years ago, what they found is
  262. 9:40automated bots doing the scouring,
  263. 9:43collecting the data, seeing if there's
  264. 9:44something interesting like looking at
  265. 9:45the details on your computer, your
  266. 9:47network. Is this somebody just doing
  267. 9:48e-commerce or is there something here?
  268. 9:50But eventually that automated bot 10
  269. 9:52years ago would sell the data to a user
  270. 9:56to then say, "Hey, here's what we found
  271. 9:58on this particular network." And then
  272. 10:00they sell it off and then some human
  273. 10:01actor would go. I'm sure that by now
  274. 10:03it's just way more automated
  275. 10:06do that. But that was 10 years ago the
  276. 10:07the automation
  277. 10:09>> uh was going on.
  278. 10:11>> So yeah, so 10 10 years of
  279. 10:14pre-generative AI
  280. 10:16>> 100%. Yeah. automate automate like we
  281. 10:18we'll get into like the step change I
  282. 10:20think that that's been happening over
  283. 10:21the last couple years. I mean I also
  284. 10:23personally just start I mean I feel
  285. 10:26almost embarrassed to say this on a on a
  286. 10:27future tech podcast. I started using
  287. 10:29codecs like only only a week and a half
  288. 10:32ago or so and I like I'm my mind's blown
  289. 10:34right. So I can only imagine for these
  290. 10:36sophisticated and even unsophisticated
  291. 10:39hackers for lack of a better term um
  292. 10:41using these type of tools for for the
  293. 10:43better part of you know 6 7 8 months a
  294. 10:46year or something like that. It's just
  295. 10:47it's just it's just another world. Um,
  296. 10:50one one question that I have for you is
  297. 10:51like how how aware are people like I
  298. 10:55think you you work with like maybe more
  299. 10:57sophisticated larger enterprises
  300. 10:59>> in your industry and I'm sure you're
  301. 11:01touching base with other cyber security
  302. 11:03experts that might be working with like
  303. 11:05SMBs.
  304. 11:06>> Yeah.
  305. 11:06>> How aware is I don't know the general
  306. 11:11industry the general market of the need
  307. 11:14for cyber security now? Uh I think
  308. 11:17everybody recognizes there's a need at
  309. 11:19this point. So everybody it used to be
  310. 11:21just have antivirus and all that.
  311. 11:22Everybody to some degree has some amount
  312. 11:23of cyber security and that's
  313. 11:25>> for two reasons. A because it's in the
  314. 11:27news and people are getting attacked and
  315. 11:29all that. But also I think to your point
  316. 11:30third party supplier to large
  317. 11:32enterprises eventually that risk that
  318. 11:34these enterprise are having whether
  319. 11:36you're bank or a hospital or others they
  320. 11:37would say hey show me that you got some
  321. 11:39level of risk and management and
  322. 11:41security and containment because I'm not
  323. 11:43going to connect you to a network do
  324. 11:44business with you if you don't actually
  325. 11:46have some minimum level and there was
  326. 11:48some government standards that started
  327. 11:49trying to push some of this too. It's
  328. 11:50called CMMC, which is, hey, let's raise
  329. 11:52the bar for the defense industrial base
  330. 11:54to be able to I'm not saying you're
  331. 11:56going to be perfect, but let's at least
  332. 11:58get the basic hygiene and let's start
  333. 11:59getting the stuff in there to do that.
  334. 12:01>> Having said that, the large enterprises
  335. 12:04of course are going to spend the money.
  336. 12:05They're going to hire the people,
  337. 12:06they're going to hire the tech, they're
  338. 12:07going to customize it, they're going to
  339. 12:08go into it, and and they're going to
  340. 12:10have some good people and and and that's
  341. 12:11all true, but that's not appropriate for
  342. 12:13everybody. So, I think the SMB is more
  343. 12:15managed services. Let me get some tool
  344. 12:18something like and I'm I'm not picking
  345. 12:20on any vendor particular but I'm just
  346. 12:21saying the popular ones. Something like
  347. 12:23Crowd Strike. It's easy. It sets up. It
  348. 12:25finds most of the tools that are in
  349. 12:26there. Or even Microsoft Defender. Hey,
  350. 12:29turn this thing on. It does a good job.
  351. 12:31Honestly, that does that. That's a
  352. 12:33really good starting point for a lot of
  353. 12:35these. I'm not saying that mediumsiz or
  354. 12:37small needs to have a dedicated security
  355. 12:38team and experts and all that. The
  356. 12:40managed services and those apply apply
  357. 12:44to the bulk. The large enterprises have
  358. 12:46different challenges when they've been
  359. 12:49around for 50 years. They got
  360. 12:50mainframes. They got IT networks. They
  361. 12:53got manufacturing if necessary. They got
  362. 12:55cloud. They got and and they're
  363. 12:57international and they got different um
  364. 13:00different locations, rules, laws, those
  365. 13:02are more of a challenge. And as much as
  366. 13:04you know when we started off as a cyber
  367. 13:06security company uh 10 years ago, we
  368. 13:08just started with the cloud solutions.
  369. 13:11So we started with Slack and the Google
  370. 13:12Suite and everything else which if ever
  371. 13:15back in the days you have your domain
  372. 13:16controllers and exchange servers and
  373. 13:19your office and that was a target but
  374. 13:22but new companies are just all
  375. 13:24cloudnative and all that. Having said
  376. 13:25that
  377. 13:26>> um a lot of the historical ones you
  378. 13:28don't just throw away 20 years of
  379. 13:30mainframes and things that make you
  380. 13:31money just because there's a new shiny
  381. 13:34that that's out there. So there's always
  382. 13:36that challenge of transforming,
  383. 13:38maintaining the business, transforming
  384. 13:40what you're doing and I think the
  385. 13:43challenge now is the speed of which
  386. 13:45things are going which large enterprises
  387. 13:47are not always used to
  388. 13:48>> Yeah.
  389. 13:49>> changing on a dime.
  390. 13:50>> Yeah. Yeah. Yeah. And that's I think one
  391. 13:53of the things that we keep hearing you
  392. 13:55know from all guests working in you know
  393. 13:58very different industries. Yeah, the
  394. 14:00this the speed of these transformations
  395. 14:02that specifically, you know, these these
  396. 14:05agents or generative AI over the last
  397. 14:07couple years is bringing about is
  398. 14:08>> it's uh it's, you know, almost breaking
  399. 14:11your neck, right? It's break neck speed.
  400. 14:13It's it's too fast. Um, how
  401. 14:17I mean, I kind I kind of want to uh pull
  402. 14:20from you like your understanding a
  403. 14:23little bit more about the hacking space,
  404. 14:25right? Like as I understand it, it's a
  405. 14:28pretty sophisticated industry now
  406. 14:30compared to what it was 10 years ago or
  407. 14:33so. And like
  408. 14:36are they the ones using some of the most
  409. 14:38sophisticated tools out there in
  410. 14:39compared to you know us?
  411. 14:42>> I'm going to put it into broad buckets.
  412. 14:44I'd say that nations and wellresourced
  413. 14:48nations have always been doing a lot of
  414. 14:50the full spectrum. And what I mean by
  415. 14:52that one is it's I'm developing tools.
  416. 14:55I'm developing custom tools. I'm
  417. 14:57training people to be able to operate.
  418. 14:59So take US Cyber Command. So it didn't
  419. 15:01exist 10 years ago. Didn't exist 15
  420. 15:03years ago. They stood up a whole command
  421. 15:05dedicated on cyber operations for the US
  422. 15:07military. And um when we started as a
  423. 15:10company, it was like 6,000 operators
  424. 15:13dedicated to attacking and defending.
  425. 15:14Again, that was like 10 years ago
  426. 15:16>> to do that. And with that comes just
  427. 15:18like if you're a fighter pilot. If I'm a
  428. 15:20pilot, I need an airplane. I need a
  429. 15:21runway. I need a crew. I need logistics
  430. 15:23and all that. So now I have these
  431. 15:25operators. I need to have dedicated
  432. 15:27tools. I need to be able to learn how to
  433. 15:29attack and defend. I need to have my own
  434. 15:30dedicated environment for developing and
  435. 15:33training and rehearsals. And so that was
  436. 15:35all built out and and what I'm driving
  437. 15:38at is there's there's the development of
  438. 15:40the unique cyber capabilities, defensive
  439. 15:42and offensive. There's the training of
  440. 15:44the people to be able to do that and and
  441. 15:46run through. that a large nation state
  442. 15:49has more than a bunch of guys on
  443. 15:50keyboards. They have um satellites and
  444. 15:54submarines and people that can break
  445. 15:56into a building and stick a USB stick
  446. 15:58into that. And so when you think of the
  447. 16:00full set of capabilities that the US,
  448. 16:03Russia, China, these big guys, it's like
  449. 16:05it's not just the guy on keyboard trying
  450. 16:06to hack into the front door. They may be
  451. 16:08having
  452. 16:09>> a whole slew of other assets to be able
  453. 16:11to do that. That hasn't changed. So, and
  454. 16:15then you have money that comes into the
  455. 16:17picture. So, when whatever criminal
  456. 16:19group started figuring out I can extort
  457. 16:21A, B or C or I can hire some guys, break
  458. 16:24into a network, ransomware your machine
  459. 16:27and make money. So, okay, now there's a
  460. 16:28money incentive to this too. But there's
  461. 16:32still some skilled operators to do that.
  462. 16:34AI is effectively just accelerating what
  463. 16:37these guys are already doing um for
  464. 16:40that. So I would say that the top
  465. 16:42countries are still the top countries,
  466. 16:44the medium ones are so and then you have
  467. 16:46random people here and there that are
  468. 16:48doing stuff um for that. But it it I
  469. 16:53still think that cat and mouse in other
  470. 16:54words the adversaries get more
  471. 16:56sophisticated with automation and AI but
  472. 16:59defense has a voice too. You know your
  473. 17:01network you can learn your patterns. The
  474. 17:03good news about AI is like I can learn
  475. 17:05what's normal. I can learn the stuff. So
  476. 17:07if you start seeing deviations from
  477. 17:09what's going on, okay, that's a problem.
  478. 17:11So
  479. 17:11>> it's not clear to me that like offense
  480. 17:14is significantly better or worse than
  481. 17:15defense. It's always been
  482. 17:17>> yeah,
  483. 17:18>> bouncing up and down a little bit. The
  484. 17:20key though is are you making the change?
  485. 17:23Are you making a transformation? Are you
  486. 17:25one of these orgs that are
  487. 17:26forwardleaning and thinking about AI and
  488. 17:28transformation or are you sitting on the
  489. 17:30sidelines um waiting to see what
  490. 17:34happens? If you're sitting on the
  491. 17:34sideline, uh, you may be the next victim
  492. 17:38for that.
  493. 17:39>> Well, I think that I think that's part
  494. 17:41of the goal of this podcast is to to
  495. 17:42make people, you know, realize that some
  496. 17:44action needs to be taken. Um, ve very
  497. 17:48interesting. Okay. So, and then and then
  498. 17:50so that's like kind of nation, state,
  499. 17:53larger, like the the the the most
  500. 17:55sophisticated out there. What about uh
  501. 17:58going back to what you were saying
  502. 18:00before like the the private industry,
  503. 18:02the private hacking industry, right?
  504. 18:04Like the people that hacked my clients
  505. 18:05and then compromised me. Like I'm
  506. 18:08understanding
  507. 18:09that they have multiple specialized
  508. 18:13companies, right? They've got like COO,
  509. 18:15CTO, CEOs in these companies and they
  510. 18:19just operate by, you know, uh um selling
  511. 18:22compromised data up a chain to to
  512. 18:25somebody actually doing the the
  513. 18:26essential hack and the the manipulation
  514. 18:28of, you know, funds and stuff like that.
  515. 18:30Is that is that like a correct
  516. 18:32assumption here?
  517. 18:34>> Yes. Uh the quick answer is yes. It's
  518. 18:36not directly my space. I deal with more
  519. 18:37of the nation states and all that kind
  520. 18:39of stuff. But in in general, yeah, it is
  521. 18:40a business at this point. it is a
  522. 18:42business and they are running it like a
  523. 18:44business. Um so they are hacking um
  524. 18:47they're hacking and they're going to go
  525. 18:48after the easiest targets and sometimes
  526. 18:50I have to say is you know the banks if
  527. 18:52you will got more sophisticated they got
  528. 18:54the stuff in there so they move on to
  529. 18:56some other ones. Do you remember
  530. 18:57Colonial Pipeline years ago where there
  531. 18:59was a hack on so
  532. 19:01>> familiar?
  533. 19:02>> This was like five, six years ago. It
  534. 19:03was a hack on the um an oil and gas
  535. 19:06company down in Texas. I think it was
  536. 19:08Texas down in the south that was moving
  537. 19:10uh gas across the thing. What happened
  538. 19:12there is, you know, there was a network,
  539. 19:14there was a there was a VPN connection
  540. 19:16that was unsecured. So, somebody quote
  541. 19:17unquote got into the IT portion of it
  542. 19:20and took out quote unquote the billing
  543. 19:22server. So, they didn't really hack the
  544. 19:24pipeline. what they did is take over the
  545. 19:26billing server, but the company didn't
  546. 19:28really know what was going on,
  547. 19:29>> so they shot everything down.
  548. 19:31>> Um, for that, was that a sophisticated
  549. 19:34group? No, it's more of the guys that
  550. 19:35you were just talking about. They're
  551. 19:36just going after some money, broadly
  552. 19:38speaking, and and that was an easy
  553. 19:40target. I hate to say it, but like
  554. 19:41hospitals, hospitals are focused on
  555. 19:43medicine. They're focused on keeping
  556. 19:45people going. They're not security
  557. 19:46experts, know what you expect them to
  558. 19:48be,
  559. 19:48>> but yet they're going to go in and
  560. 19:50ransomware because they know they need
  561. 19:52to keep the
  562. 19:54keep the things running and all that.
  563. 19:56>> Yeah,
  564. 19:56>> it's it it it it sucks, but that's where
  565. 19:59um you go after the easiest target
  566. 20:01sometimes and
  567. 20:03>> and when the bar has been raised on the
  568. 20:06more sophisticated companies, you go
  569. 20:09after the easier ones to do that. And so
  570. 20:13yeah, so I think that's my my blanket
  571. 20:15statement over there. And by the way,
  572. 20:16it's probably worldwide and the US has
  573. 20:18money. So go after the countries that
  574. 20:20have the money,
  575. 20:21>> right? Makes sense. Makes sense.
  576. 20:23>> It's like why do you why do you round
  577. 20:24out the back? Because that's where the
  578. 20:25money is.
  579. 20:26>> Yeah. Yeah.
  580. 20:28Um so okay so
  581. 20:32with the advent of you know generative
  582. 20:35AI and now you know the these AI agents
  583. 20:40are you like we we feel that we're
  584. 20:43unsafe
  585. 20:45>> the companies that have taken action are
  586. 20:48they are they perceiving to be safe now
  587. 20:51or are they still like
  588. 20:53we've done all these things but you know
  589. 20:55maybe there's another 30% % or 50% that
  590. 20:58we can do like what's the what's the
  591. 21:00perceived sense of safety for for for
  592. 21:03the companies and you know the uh the
  593. 21:05countries that you're working with.
  594. 21:06>> Yeah. Let me make two broad statements.
  595. 21:09Um the first one is um
  596. 21:15is AI has been around for decades. Yeah.
  597. 21:18It's just the fact that the memory
  598. 21:20compute all that became affordable
  599. 21:22enough to be able to really make it
  600. 21:24going on. I remember when I was at
  601. 21:25Lincoln Lab many many years ago before
  602. 21:28it was called the IT or the infosc or
  603. 21:30the cyber group it was the speech and
  604. 21:32language processing and speech
  605. 21:34processing was all about uh neural
  606. 21:36networks and trying to find a speaker in
  607. 21:39the middle of a bunch of other ones and
  608. 21:40figure out the language and all that but
  609. 21:42the models have been developed for many
  610. 21:43many years it was just not
  611. 21:45computationally effective to be able to
  612. 21:47run it
  613. 21:48>> cheaper memory and processing made it
  614. 21:51quote unquote explode and typically the
  615. 21:53first one that really made or these
  616. 21:55models could could could
  617. 21:58build off a lot a lot of data. Um, so
  618. 22:00that's part one of the comment. Part two
  619. 22:03is I'm going to use a self-driving car
  620. 22:06analogy and eventually going to get into
  621. 22:07the question. So
  622. 22:08>> I like Whimo as an example. Whimo, if
  623. 22:10you remember, or you've seen them riding
  624. 22:12around San Francisco. It's a beautiful
  625. 22:14car. Well, forget the aesthetics. It's a
  626. 22:16car that's riding around San Francisco
  627. 22:17with no pilot in there that um got
  628. 22:20approval to to run. So, picture this is
  629. 22:23like a vendor, Whimo, a car getting
  630. 22:26approval from the city of San Francisco
  631. 22:28to say, "I'm going to allow this machine
  632. 22:31to run around my city with people in it
  633. 22:34with pedestrians all over the place, and
  634. 22:36I've built enough trust that I am safe
  635. 22:39to be able to actually navigate on my
  636. 22:41own around a crowded city with all the
  637. 22:44silliness that happens in the city." And
  638. 22:46you can picture that. people jumping in
  639. 22:48front of the car and families and kids
  640. 22:50and skateboarders on a rainy day and
  641. 22:52snowy and whatever else is happening.
  642. 22:55>> That did not happen overnight. that took
  643. 22:57um there was a DARPA grand challenge 20
  644. 22:59years prior where DARPA started creating
  645. 23:01a lot of these autonomous vehicles that
  646. 23:02became the national labs or the labs
  647. 23:04from Stanford and MIT and others that
  648. 23:05eventually created some of the companies
  649. 23:07as a spin out that even when got it took
  650. 23:10him like 10 years worth of data getting
  651. 23:13all this data to be able to build up
  652. 23:15enough information to handle not the
  653. 23:18ideal case but the corner cases by the
  654. 23:20corner cases is if you're doing an indie
  655. 23:22track and you're just looping around
  656. 23:24cool the challenge for all these cars
  657. 23:26was what happens when I get ambiguous
  658. 23:30and weird conditions and failure modes.
  659. 23:32Do I do I do something that's that's
  660. 23:35appropriate? I say that because
  661. 23:38in the level of autonomy, so we hear
  662. 23:40this word about agentic agent being, but
  663. 23:43there's levels of autonomy just like in
  664. 23:44the cars level zero to level five ways
  665. 23:47at a level four. If I make the analogy
  666. 23:49for cyber, we're at a level two. So when
  667. 23:52you hear about these cyber security
  668. 23:53companies saying I am helping you out do
  669. 23:55that um it's really what they're doing
  670. 23:58is saying there's a lot of alerts
  671. 24:00there's a lot of data coming in and I'm
  672. 24:02going to use AI to quoteunquote triage
  673. 24:04I'm going to actually help you kind of
  674. 24:06go from whatever a million alerts to
  675. 24:10>> a hundred that are more interested in a
  676. 24:12human can actually keep up with what's
  677. 24:13going on. Cool. So there's AI through
  678. 24:15but they're not responding. They're
  679. 24:17triaging. They're helping kind of sift
  680. 24:19through the noise to be able to find the
  681. 24:22interesting stuff. Cool. But attacks are
  682. 24:25not are more some of the things that are
  683. 24:27out there are more at a level four. So
  684. 24:29if you think about what happened with
  685. 24:31Open AI that was testing some of their
  686. 24:33new models uh without the guard you know
  687. 24:36what they want to say is like I'm
  688. 24:37creating powerful models. Awesome. How
  689. 24:40bad will this be if it gets into the
  690. 24:42hands of an adversary that they want to
  691. 24:44use against? So they took the guard
  692. 24:45rails off. By taking the guarders off,
  693. 24:47they want to say, "Okay, let me test and
  694. 24:49see how sophisticated the model figured
  695. 24:51out, broadly speaking, how to hack the
  696. 24:53network, get out of the sandbox, get
  697. 24:55into another company, take the data to
  698. 24:57be able to pass the challenge to go
  699. 24:58through that." Okay, impressive. And
  700. 25:00there's a couple of examples here where
  701. 25:01there's self-propagating autonomous
  702. 25:03software going around and doing it. So,
  703. 25:05that's a level four. So, we need to be
  704. 25:07able So, the defensive side is moving up
  705. 25:10that chain to increase the automation,
  706. 25:12which is going to be better for
  707. 25:13everybody. But in my mind, just like the
  708. 25:17Whimo running around San Francisco, a
  709. 25:19vendor showing up with a product saying,
  710. 25:20"I'm awesome. It works in my lab. I've
  711. 25:23tested it for three days under my
  712. 25:25conditions of five machines is not
  713. 25:27enough to allow big bank number one or
  714. 25:31FA to say, I'm going to trust this thing
  715. 25:34to put it on my production network, and
  716. 25:36the whole safety of the uh airline
  717. 25:38network is great." there's going to be
  718. 25:40some time to be able to prove that that
  719. 25:42thing does what you want it to do versus
  720. 25:44not.
  721. 25:45>> And my subtler point here is there's a
  722. 25:48risk of not doing anything because
  723. 25:50you're going to get attacked by the by
  724. 25:52the systems. I hate to say but like even
  725. 25:54in your case if you do nothing you are
  726. 25:56potentially going to get overrun. If you
  727. 25:58are too aggressive it may do something
  728. 26:01damaging but there's this sweet spot in
  729. 26:03between is like have I built enough
  730. 26:05trust and confidence where this can help
  731. 26:07me? I can keep up with it. Um, but not
  732. 26:10destroy me. By destroying is like doing
  733. 26:12things that can actually wipe your
  734. 26:14network or not doing anything that can
  735. 26:16that can. So, we're going through this
  736. 26:19really interesting time to me because
  737. 26:20it's in the news. It's out there. We can
  738. 26:22argue about regulations and this and
  739. 26:24that, but the models are powerful and
  740. 26:26they're getting more and more powerful
  741. 26:28every quarter and it's helping both
  742. 26:30offense and defense. I'm on a longwinded
  743. 26:33thing here, but to me the biggest thing
  744. 26:36for companies is not necessarily the
  745. 26:38tech, but is their ability to transform.
  746. 26:42The companies that are going to start
  747. 26:44thinking rapidly, start thinking
  748. 26:46innovation, start thinking about how do
  749. 26:47I apply these things to do that are
  750. 26:49probably the ones that are going to be
  751. 26:51succeeding and making a journey. The
  752. 26:53ones who don't make the change are the
  753. 26:55ones that are going to be probably left
  754. 26:57behind. Do you remember during the cloud
  755. 26:59days there was this whole transformation
  756. 27:00of onrem and there was all these cloud
  757. 27:02providers and in the early days there
  758. 27:04was like thousands of companies and
  759. 27:06there was a wild west and
  760. 27:08>> and now we're down to whatever three
  761. 27:09four five Amazon or AWS GCP some of the
  762. 27:12other ones
  763. 27:13>> you get you consolidated and mature all
  764. 27:15that we're going through the same thing
  765. 27:16with AI where there's thousands of
  766. 27:18companies some new some old that are all
  767. 27:21trying to go through that it's going to
  768. 27:23shrink down to something more stable and
  769. 27:24and all that over time but
  770. 27:26>> okay But we are going through big
  771. 27:28change. We are going through big changes
  772. 27:30right now. And it's and it's a messy
  773. 27:32time. It's a fun time depending on your
  774. 27:34perspective. But it's
  775. 27:38>> it's a you could say yeah maybe fun
  776. 27:40might not be well yeah I guess it
  777. 27:42depends on your perspective. It's an
  778. 27:44educational time. We can we can say you
  779. 27:46know it
  780. 27:46>> it is and and again it's more than
  781. 27:48cyber. It's everything.
  782. 27:49>> Yeah.
  783. 27:50>> I I use it for just looking up you name
  784. 27:52it. And it's it's impressive how good
  785. 27:55these models are becoming. And it it
  786. 27:57it's just impressive.
  787. 27:59>> Yeah. Yeah. Yeah. I mean I I'm I'm
  788. 28:01personally blown away by you know I'm
  789. 28:03I'm using codecs all the time right now.
  790. 28:06Um maybe also a question here. So
  791. 28:09like cyber security
  792. 28:12in general is done by you know like at
  793. 28:14the smallest scale like you know as you
  794. 28:16said before Windows Defender or
  795. 28:18something like that or malware bites or
  796. 28:20so or and then you get into like you
  797. 28:22know managed services and then you know
  798. 28:24larger nation state uh large um
  799. 28:28corporate uh options there.
  800. 28:32What do you think is like do you think
  801. 28:34that these coding options are going to
  802. 28:38enable smaller companies to build their
  803. 28:41own cyber security tools or is that
  804. 28:43still a little bit too too outlandish?
  805. 28:46>> I think it's dangerous. Um and the
  806. 28:49reason why I say it is um
  807. 28:52the models are good but there's a
  808. 28:54difference you know good coding good
  809. 28:56practices testing life cycle there's
  810. 29:00value to that. So slapping together a
  811. 29:02couple of models and code and saying I'm
  812. 29:05secure is that really better than again
  813. 29:08I'm going to pick on Crowd Strike and
  814. 29:09Google and all that. They have teams of
  815. 29:11engineers that know what they're doing
  816. 29:13that that that know how to build quality
  817. 29:16software leverage AI but know how to
  818. 29:18build quality software. So to me a good
  819. 29:19company there a has to know how to
  820. 29:22actually build and engineer something
  821. 29:23robust scalable that works and and all
  822. 29:27the good things about that. They need to
  823. 29:29understand cyber security. So just
  824. 29:31because I can code, cool. I need to
  825. 29:33understand the cyber security. What are
  826. 29:34the threats? What are the aspects? What
  827. 29:36are the things I need to attack and
  828. 29:37defend? And I got to understand machine
  829. 29:39learning and reinforcements and AI. And
  830. 29:42so that mix of those three things I
  831. 29:45think makes it successful. By the way,
  832. 29:47I'm not saying that just because you're
  833. 29:48a big company you're going to be
  834. 29:49successful and you're the answer. No,
  835. 29:51there's a lot of new upstarts as
  836. 29:52spin-offs that are coming out of these
  837. 29:54that are going to do wonderful work. But
  838. 29:56but I do think that just um throwing
  839. 29:59together some quick code and saying I
  840. 30:00got a solution that is better than uh
  841. 30:03some of these guys that are experts in
  842. 30:06the field
  843. 30:08>> is probably not the right answer.
  844. 30:10>> Yeah. Yeah. Yeah. Fair enough. And I
  845. 30:12guess also one of the things is if you
  846. 30:14miss one small thing with these new AI
  847. 30:16tools, they could find that
  848. 30:18vulnerability and you think you're safe
  849. 30:19and you're not. So yeah. and and some of
  850. 30:24these there's an aspect of these cyber
  851. 30:26security the larger cyber security
  852. 30:27companies that um I don't want to call
  853. 30:29it a network effect but take take
  854. 30:32crossstrike or sentinel one or or Google
  855. 30:35a lot of the cloud-based tools they're
  856. 30:37monitoring your network and potentially
  857. 30:39responding but they're also in a million
  858. 30:42other networks so they're seeing the
  859. 30:44patterns that are happening in Asia that
  860. 30:48perhaps in Europe that perhaps in the US
  861. 30:50and they're able to from those patterns
  862. 30:52push the updates out to all the other
  863. 30:54companies that are a little bit able to
  864. 30:57do that. Do you remember the Crowd
  865. 30:59Strike? There was an incident with Crowd
  866. 31:00Strike, I want to just say a year and a
  867. 31:02half ago where it took down the
  868. 31:04airlines. It took it there was basically
  869. 31:06there was an update that was made to
  870. 31:07crowd strike that made all the Windows
  871. 31:09machines crash and those
  872. 31:10>> Yeah, sounds familiar.
  873. 31:12>> If you remember, you went into the
  874. 31:13airport terminal and there was a bunch
  875. 31:14of crash things and the airline systems
  876. 31:15went down and all that. It started in
  877. 31:17Asia and it took down all that stuff but
  878. 31:19the company over time was able to update
  879. 31:21it to not make it as damaging to so okay
  880. 31:25so there's multiple issues with that com
  881. 31:27one that a single company could have
  882. 31:28such worldwide impact and dependency on
  883. 31:31it but um but they do have this broader
  884. 31:33perspective on on the threat of India
  885. 31:36having said that I think there's another
  886. 31:38big change that's happening where you
  887. 31:40used to think about big nation states
  888. 31:42and what are the Russians or the Chinese
  889. 31:43or the Iranians doing in terms of trying
  890. 31:45to hack into Yumi any other ones.
  891. 31:47>> And a lot of these companies will spend
  892. 31:48a lot of time on what they call threat
  893. 31:50info. What are the adversaries doing?
  894. 31:51What are the name threats? What's going
  895. 31:53on to be able to break in to do that and
  896. 31:55you would basically spend a lot of time
  897. 31:57making sure that you are secure against
  898. 31:58that particular actor threat. That's
  899. 32:00still true. Um, and you would tune your
  900. 32:03to. But I think there's a new class of
  901. 32:05threats that is emerging which is these
  902. 32:07AI agentic system which is I'm not
  903. 32:10modeling a specific actor. I am a bot.
  904. 32:12I'm an agent with a goal to get into
  905. 32:15your network, figure out what's going
  906. 32:17on, and do blah. And it's going to find
  907. 32:20some way of actually doing that. And
  908. 32:22that's a equally valid and powerful new
  909. 32:25set that you can't just put in some new
  910. 32:27rule change or some new thing in there
  911. 32:29to to stop it. So, um
  912. 32:33yeah, so that I lost my train of
  913. 32:34thought, but that that's to totally
  914. 32:37fine. Yeah, we can. Um, you know, I I
  915. 32:40want to dive in a little bit more like I
  916. 32:41want to ask questions about Mythos and
  917. 32:43stuff like that. Um, I see our time, you
  918. 32:45know, we still have some time obviously,
  919. 32:46but can we touch on like what exactly
  920. 32:49you guys are doing?
  921. 32:50>> Oh, of course. So, we So, at a basic
  922. 32:54level, we are a cyber range. A cyber
  923. 32:56range is a realistic environment that
  924. 32:57you can use to be able to train and test
  925. 33:00uh test technology, train people with
  926. 33:02it. So, think of it as almost like a
  927. 33:04replica of your enterprise network,
  928. 33:05whether it's a hospital, a back and all
  929. 33:07that. Create that replica. Now, put in
  930. 33:09the tools, see how they work against
  931. 33:10adversaries, and train the people. A
  932. 33:13good analogy here is a flight simulator.
  933. 33:15If you're a pilot looking to actually
  934. 33:16fly a plane, you're going to go through
  935. 33:18the manuals are going to read the books
  936. 33:19and all kind, but at some point, you
  937. 33:21want to get a certain number of hours in
  938. 33:23front of the thing to do that. And the
  939. 33:25nice thing about a flight simulator is
  940. 33:26you can put it into all kinds of failure
  941. 33:28modes. What happen when your engine goes
  942. 33:29out? What happens you're struck by
  943. 33:30lightning? what happens when u the fuel
  944. 33:33goes blah blah blah you have to do x or
  945. 33:34y. So you want to be able to get that
  946. 33:35muscle memory and try it out and go
  947. 33:37through and run it. So we are the
  948. 33:39equivalent of the flight simulator for
  949. 33:41cyber security a very realistic
  950. 33:43environment that you can put the tech in
  951. 33:45to be able to actually try it. We now
  952. 33:46call this the AI proving ground. So
  953. 33:49think of our environment now as being
  954. 33:51the reinforcement learning environment
  955. 33:53where you can put in AI solutions
  956. 33:55defensive. Let them learn the patterns
  957. 33:57of what is normal for a hospital, a
  958. 34:00financial company, a bank. Put all the
  959. 34:02failure modes, the attacks, the outside,
  960. 34:04the inside. Yeah. And now you can start
  961. 34:06seeing how good two answers. A let the
  962. 34:09tech builders create better models and
  963. 34:12more robust models. Back to that Whimo
  964. 34:13example that needed 10 years of data
  965. 34:15before they could. We're generating that
  966. 34:17data to be able to let the security
  967. 34:19tools make sure they can handle all the
  968. 34:21corner cases and the real world
  969. 34:23conditions that's going on at some
  970. 34:25point. But that's for the builders. The
  971. 34:26builders at some point there's a buyer.
  972. 34:28The buyer is the bank. It is the
  973. 34:31hospital. How do I choose which
  974. 34:33technology is right for me and how do I
  975. 34:36tune it to be appropriate for what I'm
  976. 34:38doing? uh to do that.
  977. 34:40>> So the notion of a proving ground is
  978. 34:42similar to
  979. 34:44>> it's been around for decades, which is I
  980. 34:45have new technology. I'm going to bring
  981. 34:47it out to a desert or a thing to do
  982. 34:49that. I like my analogy with Top Gun and
  983. 34:51I'm sure you've seen Maverick and all
  984. 34:52that kind of guy and it's wonderful. So
  985. 34:54the US I do a little military stuff. The
  986. 34:57US would bring a bunch of pilots out to
  987. 34:58the middle of a desert. One of them is
  988. 35:00called Red Flag for the Air Force.
  989. 35:01There's Top Gun for the Navy guys and
  990. 35:03all that.
  991. 35:04>> But if you remember Tom Cruz is like
  992. 35:06here he is, there's a machine. There's
  993. 35:08an airplane. So a you want to make sure
  994. 35:09that the airplane works. So the the
  995. 35:11engineers take it out to make sure that
  996. 35:12all works. Eventually you're going to
  997. 35:13hand it to a pilot and now how do you
  998. 35:15make sure that the pilot can fully take
  999. 35:18advantage of that plane and really bring
  1000. 35:20it to its limits. So
  1001. 35:23>> effective what we're doing is and the
  1002. 35:24whole thing about Top Gun Maverick and
  1003. 35:26all those is like you're going to
  1004. 35:27practice the mission before doing
  1005. 35:29whatever it was dropping some bomb in
  1006. 35:30some silo to do all that. So you do all
  1007. 35:33that in a synthetic environment, try it
  1008. 35:35all out to find the limits of what is
  1009. 35:36possible to do that. So from a SIM space
  1010. 35:39standpoint, um, we create the realistic
  1011. 35:42environment. We have virtual users
  1012. 35:44generating traffic just like a normal
  1013. 35:46thing. Think of little AI bots that are
  1014. 35:47pretending to be programmers and
  1015. 35:49administrative users and guys logging
  1016. 35:51into stuff. Attackers that are in the
  1017. 35:53middle of it. And the job of the
  1018. 35:55security products is to sift through all
  1019. 35:56that and make sense and then the
  1020. 35:58operators to use all that to be able to
  1021. 36:00actually run and do their thing. So
  1022. 36:02that's we are the playground. Okay, bad
  1023. 36:05analogy, but
  1024. 36:07Very interesting. Um, so okay, a
  1025. 36:10question following up from that. You you
  1026. 36:11were talking about like Whimo, the main
  1027. 36:13thing that they needed to figure out was
  1028. 36:14the edge cases. Like how how have you
  1029. 36:18found the edge cases in this new world
  1030. 36:21that we're experiencing where I like my
  1031. 36:24assumption is new edge cases are kind of
  1032. 36:26coming up all the time because you got
  1033. 36:28these hackers that are notorious and
  1034. 36:31innovative and they're coming up with
  1035. 36:32new ways of attacking.
  1036. 36:34>> Um, yeah. Yeah. So, it's always a
  1037. 36:36challenge to be able to say that this
  1038. 36:38twin or this copy that you're creating
  1039. 36:40looks 100% like the real network. It's
  1040. 36:42not a model is is is just that. It's an
  1041. 36:45approximation. It's good enough. We try
  1042. 36:48and get as close to possible without
  1043. 36:50breaking the bank and having infinite
  1044. 36:52time to be able to do that. So, there's
  1045. 36:54there's a lot of automation that's
  1046. 36:55getting into it. Um, you'll hear some
  1047. 36:58people talking about creating a
  1048. 36:59synthetic network and and an
  1049. 37:01environment. And when they try these
  1050. 37:02things out, it may have like a couple of
  1051. 37:04servers and a couple of clients with no
  1052. 37:06users and traffic. And that's like maybe
  1053. 37:08five ten machines that are simplistic.
  1054. 37:10What we do is we create maybe hundreds
  1055. 37:12or thousands of nodes and actual
  1056. 37:14applications and users creating traffic.
  1057. 37:16And
  1058. 37:17>> you know what? If you're going to create
  1059. 37:18the synthetic environment, it can't be
  1060. 37:20built and perfect on day one that was
  1061. 37:22just created three days ago and all
  1062. 37:24that. Real networks are dorky, messed
  1063. 37:27up, misconfigured, have all kinds of
  1064. 37:29weirdness. And so you want to be able to
  1065. 37:32have legacy systems, mainframes, OT,
  1066. 37:36infrastructure that has like power
  1067. 37:38company things in there. So you want to
  1068. 37:40create all these different variations.
  1069. 37:41So, it's training and understanding all
  1070. 37:44the nuances, but I think over time it's
  1071. 37:47also important to be able to say, I'm
  1072. 37:49going to give you wrong data,
  1073. 37:52misconfigure data, different policies,
  1074. 37:55and now quote unquote agent, you got to
  1075. 37:57make a decision
  1076. 37:58>> just like a human would, which is I got
  1077. 38:01conflicting, incomplete, erroneous data,
  1078. 38:05yet I still need to make a decision.
  1079. 38:07Back to the Whimo example, there's
  1080. 38:08there's always a decision that's going
  1081. 38:10to make between
  1082. 38:12um do I go left or right? If I got a
  1083. 38:14baby jumping in front of the car on the
  1084. 38:15right side, I got a grandmother jumping
  1085. 38:16in front on the left side and there's a
  1086. 38:18puddle and all that, at some point the
  1087. 38:20decision is going to make about which is
  1088. 38:22the best course of action to do that.
  1089. 38:24And so can these AI and agents start
  1090. 38:27building that knowledge of what do they
  1091. 38:29do under weird conditions? And that's I
  1092. 38:32think where we are best in class to do
  1093. 38:35all that and and recreating ideally we
  1094. 38:38can push a magic button says I'm big
  1095. 38:39bank pull all the data create the super
  1096. 38:42duper version and run and we're getting
  1097. 38:44to that but um yeah but but there's a
  1098. 38:47lot of automation and there's a lot of
  1099. 38:48stuff that goes into uh working that
  1100. 38:50through
  1101. 38:51>> right
  1102. 38:52>> so that's where we think about real
  1103. 38:53world conditions and and realism.
  1104. 38:55>> Okay. And to make it a little bit
  1105. 38:58tangible for for me as well, like how
  1106. 39:01long, like I've got this image of, you
  1107. 39:03know, this this test environment that
  1108. 39:06can do thousands or hundreds of
  1109. 39:08thousands of iterations in like a day or
  1110. 39:10something like that. M probably not. Um
  1111. 39:12what's what's the what's the like
  1112. 39:14>> real world timeline that we're looking
  1113. 39:16on here for for like you know proper
  1114. 39:18testing?
  1115. 39:20When we do when we used to create these
  1116. 39:22custom environments that look like an
  1117. 39:24Air Force base or a bank and all that,
  1118. 39:27people would do it for a training event
  1119. 39:29or an exercise and they could spend like
  1120. 39:31weeks building it out, make it perfect,
  1121. 39:33get it all up and running, run this
  1122. 39:35exercise for a day or two, and then tear
  1123. 39:38it down.
  1124. 39:39>> And it's cool, but that doesn't work
  1125. 39:40when, to your point, I want to make
  1126. 39:42hundreds and of runs and iterations and
  1127. 39:45get all the various conditions. um a
  1128. 39:48typical buildup and all that maybe a day
  1129. 39:50or so if you're starting from scratch a
  1130. 39:52day to kind of build something up from
  1131. 39:53from that has a decent amount of
  1132. 39:54complexity run the traffic run the
  1133. 39:56attacks
  1134. 39:58>> run the tools pull the data out make
  1135. 40:00your decisions did it do well or not
  1136. 40:02tear down and rerun it so there's a
  1137. 40:04number of ways to speed it up but I
  1138. 40:05think there's a difference between
  1139. 40:07simulation which is I'm going to pretend
  1140. 40:09to be a flight simulator versus
  1141. 40:11emulation like we're driving real
  1142. 40:13software real applications real attacks
  1143. 40:16real exploits those move at the speed of
  1144. 40:18a network that it goes through. So I
  1145. 40:20would say that um because if you look at
  1146. 40:22a full attack running through that could
  1147. 40:24take 30 minutes to go from the outside
  1148. 40:27picture the thing that hit you even
  1149. 40:29though it was months of prep the actual
  1150. 40:31execution. Some code probably got into
  1151. 40:33your network compromised some systems
  1152. 40:35moved around stole some they would have
  1153. 40:38to do and pull it out that can take 30
  1154. 40:41minutes to two hours.
  1155. 40:42>> The right
  1156. 40:43>> all the stuff ahead of time took months
  1157. 40:45to kind of figure out how to quite tune
  1158. 40:47it. So each attack may take 30 minutes
  1159. 40:49or so to do that and and we will run
  1160. 40:51through those. So we are always looking
  1161. 40:53to speed up more over time, but that's
  1162. 40:56that's the flavor of where where we're
  1163. 40:58at. I'd say hundreds um let's just say
  1164. 41:02hundreds of variations of attacks and
  1165. 41:04networks and all that per week because
  1166. 41:07there's time to analyze and collect and
  1167. 41:09did it do the right thing and go. The
  1168. 41:11the goal here is we want to get to 99.9%
  1169. 41:16of time the system is running fully
  1170. 41:18automated. No human in the loop. It's
  1171. 41:20just iterating, collecting, extracting.
  1172. 41:23Um we're not quite there yet, but that's
  1173. 41:25that's where we want to be able to get
  1174. 41:26to uh soon enough.
  1175. 41:28>> Interesting. Interesting. And then with
  1176. 41:31this and and I think that's a good
  1177. 41:32point, simulation or emulation not
  1178. 41:34simulation. Um,
  1179. 41:37do you like is it is it like how long
  1180. 41:40does that need to be running for in
  1181. 41:42order to get to this um what you were
  1182. 41:45saying before and I forgot the the
  1183. 41:46specific term but like good enough to
  1184. 41:48start implementing
  1185. 41:50>> I
  1186. 41:52the so there's um and maybe there's
  1187. 41:55steps over here. The first one is when
  1188. 41:57you put it into the thing break. Uh
  1189. 42:00it sounds stupid but sometimes you know
  1190. 42:04when there's a lot of money being dumped
  1191. 42:05into a field there's a lot of things
  1192. 42:07that look wonderful on a website and
  1193. 42:09they worked on somebody's laptop and it
  1194. 42:12did a great demo but you put into real
  1195. 42:14network and did it
  1196. 42:15>> did it handle something that was um of
  1197. 42:18reasonable complexity. So, um,
  1198. 42:22so it does come down to testing and you
  1199. 42:23can run through a battery of tests to be
  1200. 42:25able to actually go through those. But I
  1201. 42:27think I think this maybe is a there's a
  1202. 42:29broader comment here which is we used to
  1203. 42:31have enterprise networks. We would do
  1204. 42:33maybe a pentest once a year or making
  1205. 42:36sure that the scans are all good and
  1206. 42:37there would be like a yearly or
  1207. 42:39semianual check and says, "Yep, you're
  1208. 42:41looking good. You're a partner. I can
  1209. 42:42trust you."
  1210. 42:43I think that model is kind of going out
  1211. 42:46the window a bit where the attacks are
  1212. 42:49moving fast enough where they're finding
  1213. 42:51vulnerabilities in software. They're
  1214. 42:52finding vulnerabilities of things that
  1215. 42:53you can kind of move around. Um you
  1216. 42:56can't just patch fast enough to do that.
  1217. 42:58So it's coming down to how do I
  1218. 43:01continually
  1219. 43:03um test continually run to make sure
  1220. 43:06that the latest models are being used
  1221. 43:08the latest advances are being used. I
  1222. 43:10think every company decent size is going
  1223. 43:13to be on this journey for this AI
  1224. 43:15transformation, the AI transformation to
  1225. 43:17the security stack. So, it's not like
  1226. 43:18I'm going to put in some magic box and
  1227. 43:20I'm done and I can walk away. The tools
  1228. 43:22are evolving fast. The attacks are
  1229. 43:24moving fast. And I think what's going to
  1230. 43:26start happening over time is there's
  1231. 43:28going to be this continual adaptation
  1232. 43:30and learning of the tools. As the tools
  1233. 43:33get more and more advanced, there's more
  1234. 43:34and more automation. there's more and
  1235. 43:36more tuning, not tuning, learning of the
  1236. 43:39tool for your network. Think almost like
  1237. 43:41you mentioned uh mythos
  1238. 43:44>> back to maybe two years worth of
  1239. 43:46advancements of what you see from open
  1240. 43:48AI or anthropic. You look at what
  1241. 43:50Anthropic does today versus a year ago
  1242. 43:53and you can already see
  1243. 43:55>> the rate of change uh that's going on.
  1244. 43:59So I think there's going to be a point
  1245. 44:01here where for these models and these
  1246. 44:03agents to be appropriate and relevant
  1247. 44:05for an enterprise they need to be
  1248. 44:07trained and tuned to that enterprise. So
  1249. 44:11then how do you actually because again a
  1250. 44:12generic model what does it know about a
  1251. 44:14mainframe and a bank and an ATM machine
  1252. 44:17and a defibrill. So it needs to
  1253. 44:19understand what normal is and so you're
  1254. 44:21going to be retraining that model on
  1255. 44:23your environment so that it can actually
  1256. 44:26make a smart decision when it comes down
  1257. 44:28to react and going through that. So I
  1258. 44:31think there's going to be a continual
  1259. 44:33update and learning in your enterprise
  1260. 44:36context. Um especially because there's
  1261. 44:39new models, new technologies, new things
  1262. 44:41that are moving fast. So
  1263. 44:42>> I guess what I'm trying to say is the
  1264. 44:44culture needs to change a bit so there's
  1265. 44:45a continual refresh. Actually, by the
  1266. 44:47way, the people need to change with it
  1267. 44:49um as well for that. So, that's that's
  1268. 44:52my view of what things are going to look
  1269. 44:54like. So, if I were to kind of look out
  1270. 44:56a little bit, 2026 is the year of
  1271. 44:58experimentation. 2026, everybody's
  1272. 45:01playing around. They're toying around.
  1273. 45:03I'm If you're a company's like, I know
  1274. 45:05these things are out there. Let me try
  1275. 45:07some. Let me see what's But nobody's
  1276. 45:09really pushing to a large degree to
  1277. 45:11enterprise. They're not quite robust on
  1278. 45:13that yet. They're not quite
  1279. 45:14>> handling a lot of the automation. The
  1280. 45:16tech companies are pushing the buyers,
  1281. 45:18the enterprise are looking at. So 2026
  1282. 45:21is experimentation pilots. Let me try
  1283. 45:23this out. 2027 is going to be more okay.
  1284. 45:25Now let's start putting some of the
  1285. 45:26stuff into production. Let's start
  1286. 45:28putting stuff into for Rio. Let's start
  1287. 45:29changing things around. Let's start
  1288. 45:31doing it. As we move from there, the
  1289. 45:34whole security stack is going to evolve
  1290. 45:35because as the tech evolves, the people
  1291. 45:38need to be reskilled to now figure out
  1292. 45:40I've moved up a level of automation.
  1293. 45:42It's governance. It's control. It's
  1294. 45:44safety. what is this thing doing and how
  1295. 45:46do I keep this loop up and so now I've
  1296. 45:48transformed my sock and my culture to go
  1297. 45:51through faster but I also think there's
  1298. 45:53going to be a tailoring of these models
  1299. 45:56and agents to specific enterprises and
  1300. 45:58then you start getting into data
  1301. 45:59sovereignty and do if I'm a bank do I
  1302. 46:03want all of my sensitive banking
  1303. 46:05applications and data out into a
  1304. 46:07foundational model
  1305. 46:08>> or more a little bit internally
  1306. 46:11>> that's you so I think 26 and 27 there's
  1307. 46:14A lot of that data is going to be going
  1308. 46:15out to the big F. They want to slurp up
  1309. 46:18your data.
  1310. 46:18>> Sure. Sure.
  1311. 46:19>> There's going to be a there's going to
  1312. 46:20be a balance here for these large enterp
  1313. 46:24and I'm not saying which way is the
  1314. 46:26right way,
  1315. 46:26>> but there's going to be a trade-off here
  1316. 46:28that these companies are going to make
  1317. 46:29to do that.
  1318. 46:31>> Um, yeah. So, I think long term lot more
  1319. 46:34automation from the offense, a lot more
  1320. 46:36automation from the defense. The human
  1321. 46:38role is going to move up to governance,
  1322. 46:40control, swim lanes. Can it is it safe?
  1323. 46:43Is it do the guardos in place? And
  1324. 46:45there's this risk tradeoff that
  1325. 46:46everybody's going to be making for how
  1326. 46:49much do I turn on the quoteunquote AI
  1327. 46:51for defense to keep up with the AI going
  1328. 46:54on with offense and manage that risk of
  1329. 46:57my business still running.
  1330. 47:00>> Very very interesting.
  1331. 47:02>> Okay, I'm on a rant and I'll shut up
  1332. 47:03here in one second.
  1333. 47:04>> No, no, it's fine. I I Yeah, go ahead.
  1334. 47:06You remember how like NSA and some of
  1335. 47:07the Intel shops were telephones and they
  1336. 47:10figured out the whole computer thing and
  1337. 47:11let me take data and they were swamped
  1338. 47:12with data. There just so much data
  1339. 47:14coming in.
  1340. 47:15>> It's like I don't have analysts to keep
  1341. 47:17up with every packet that's going on. So
  1342. 47:18you automated all the process. So the
  1343. 47:22same number of analysts just processing
  1344. 47:23a lot more data to go through,
  1345. 47:25>> right?
  1346. 47:26>> The same is going to be going on over
  1347. 47:27here. It's just the AI and the agents
  1348. 47:29are just going to elevate the they're
  1349. 47:31going to do a lot more of the work and
  1350. 47:33let the human be still in the loop. to
  1351. 47:36be able to oversee and control, but
  1352. 47:38they're not going to be doing the
  1353. 47:39day-to-day stuff because they're not
  1354. 47:40going to keep up.
  1355. 47:41>> Yeah. And and this is this is one of the
  1356. 47:43kind of light bulb moments that I've
  1357. 47:45been having recently, you know, testing
  1358. 47:47with codeex building a couple mock tools
  1359. 47:49here is that oh like the the doing the
  1360. 47:53actual actions are now starting to be
  1361. 47:56automated and work seems to be I'm
  1362. 47:59extrapolating here a little bit but work
  1363. 48:00seems to be shifting into like real
  1364. 48:02knowledge work like you're you're the
  1365. 48:04differentiator is your brain because
  1366. 48:06everybody has access theoretically to
  1367. 48:09the the actor that can actually do the
  1368. 48:12actions. Um, it's very very interesting.
  1369. 48:15>> And in general, I'll make a blanket
  1370. 48:17statement. Um,
  1371. 48:20vulnerabilities and exploit live in
  1372. 48:22complexity. The more complicated a
  1373. 48:24system is, the easier it is for somebody
  1374. 48:26to kind of find a little crack in there
  1375. 48:28to be able to do something. So, the more
  1376. 48:30complicated these things are, the more
  1377. 48:32maneuver space there is for an adversary
  1378. 48:34to get in there
  1379. 48:35>> and do it. And especially if these are
  1380. 48:36black boxes, how do you kind of get a
  1381. 48:39little bit more insight? So back to that
  1382. 48:40knowledge work, you need to start having
  1383. 48:43some good controls and understanding of
  1384. 48:45what's happening um for for going. Okay,
  1385. 48:50I'll stop. I could keep going from here.
  1386. 48:51>> No, it's I I mean our our time's winding
  1387. 48:54down unfortunately here. No, but this is
  1388. 48:55fascinating. I think like you know
  1389. 48:57focusing on the the how should I say
  1390. 49:00this? The the more sophisticated like
  1391. 49:02the larger organizations, the the
  1392. 49:04country states and stuff. I think you've
  1393. 49:06made a really interesting you've you've
  1394. 49:08shared some interesting insight there.
  1395. 49:10Maybe going back down to kind of where
  1396. 49:12we started w within the last couple
  1397. 49:14minutes. Again, maybe a little bit
  1398. 49:15biased and and selfish here talking
  1399. 49:17about codeex. One of the things that a
  1400. 49:19lot of the people that I'm speaking to
  1401. 49:21like they're building their own tools
  1402. 49:23and their own little apps, right?
  1403. 49:24>> And I think as I'm doing that as well,
  1404. 49:27I'm like, okay, I don't want to get
  1405. 49:29hacked again. like am I building
  1406. 49:30something that is now enabling a a a a
  1407. 49:34gateway for hackers to get in? So like
  1408. 49:36how should I and maybe you know smaller
  1409. 49:39business um owners and you know maybe
  1410. 49:41even some medium-sized business owners
  1411. 49:43that are building these things how
  1412. 49:44should we be thinking about cyber
  1413. 49:46security like there's a is there a whole
  1414. 49:48other layer that we need to be adding on
  1415. 49:50to these
  1416. 49:51>> tools that we're building. The quick
  1417. 49:52answer is you're doing the right thing.
  1418. 49:54In my mind, you always you learn by
  1419. 49:55doing instead of this big scary monster
  1420. 49:57that's out there
  1421. 49:58>> just like you're doing. You're getting
  1422. 49:59around there. You're getting smart.
  1423. 50:01You're using it. You're understanding.
  1424. 50:03You're figuring out what works, what
  1425. 50:04doesn't, what you the limits of what you
  1426. 50:06do and don't know. And so
  1427. 50:07>> in my mind, and whether you're a small
  1428. 50:09shop, a medium or large, if you don't
  1429. 50:11start getting your hands dirty and
  1430. 50:13understanding the tech and
  1431. 50:14understanding, hey, yeah, I can do this
  1432. 50:15myself. I got a perfect answer. I'm a
  1433. 50:17small enough. Yeah, this thing does. Or
  1434. 50:19like, you know what? I've reached the
  1435. 50:21limit of what I can practically do. I
  1436. 50:23can buy this thing for 50 bucks from
  1437. 50:24company X, but now I have a better
  1438. 50:26understanding of how to properly use it,
  1439. 50:28size it. I'm oldfashioned. I like when
  1440. 50:32you learn when you do something, you
  1441. 50:33understand that technology. And that
  1442. 50:36honestly, that's 90% of the way there.
  1443. 50:38Okay, I'm exaggerating a number, but
  1444. 50:39once you understand the domain and the
  1445. 50:41problem and the limits and how things
  1446. 50:43are going, now it's not the scary
  1447. 50:45monster. um now you're a little bit more
  1448. 50:48and and those exact questions you're
  1449. 50:50going through it's like okay now I get
  1450. 50:51it and then you can formulate the right
  1451. 50:54questions for what to buy what to use
  1452. 50:56what to make and and it's not just
  1453. 50:59here's some widget buy it put it in and
  1454. 51:01you're going to be awesome um for that I
  1455. 51:05I love that that's that's a that's a
  1456. 51:06perfect tangible like real action thing
  1457. 51:10that that people can take and yeah I
  1458. 51:12think that's also how I'm doing I'm just
  1459. 51:13bumbling through it right and then and
  1460. 51:15then real, oh, I need this. Oh, this can
  1461. 51:17this can happen. Yeah. Okay, fair
  1462. 51:18enough.
  1463. 51:19>> Um, yeah.
  1464. 51:21>> Um, Lee, I see our time is is pretty
  1465. 51:24much uh done here.
  1466. 51:25>> Um, it's it's been very very interesting
  1467. 51:28having you on. Um, again, I think
  1468. 51:32it's it's hard like if I'm talking to
  1469. 51:34myself from like 8 months ago, it's it's
  1470. 51:37hard to communicate to that person who
  1471. 51:39hasn't gone through a hack and see just
  1472. 51:41how disruptive it is. So, like I'm
  1473. 51:43really paying attention to what you're
  1474. 51:45saying because I understand how how
  1475. 51:47disruptive a hack can be to to a small
  1476. 51:51business like a new business like mine.
  1477. 51:53I I can't even imagine to to to a large
  1478. 51:55company. So, for anybody listening, you
  1479. 51:58know, I think it's hard to communicate
  1480. 52:00these things, which is probably a
  1481. 52:01challenge that you have as well, but you
  1482. 52:02know, thank you so much for coming on
  1483. 52:03and sharing these ideas.
  1484. 52:06>> That's awesome. I love it. And again,
  1485. 52:07it's always great to talk with somebody
  1486. 52:09that's curious and and and and is
  1487. 52:11getting around to doing it. But that's
  1488. 52:12where you start seeing why people talk
  1489. 52:13about disaster recovery and backups and
  1490. 52:16and doing all these um Yeah. I it's it's
  1491. 52:20it's by the way, it's going to happen to
  1492. 52:22more or less everybody.
  1493. 52:24>> Yeah. Yeah. Well, may maybe that's also
  1494. 52:26another good point, right? With these
  1495. 52:27tools, everybody is going to go through
  1496. 52:30some kind of comp if it's a total hack
  1497. 52:32or, you know, a minor compromise. So,
  1498. 52:34um, cyber security is going to become
  1499. 52:36more and more more important.
  1500. 52:38>> It it just pervasive. Yeah.
  1501. 52:41>> Yeah. Yeah. Uh, Lee, uh, we'll have
  1502. 52:43your, uh, website in the show notes and
  1503. 52:45your LinkedIn. Are there any other
  1504. 52:46places that you want people to reach out
  1505. 52:48or follow what you're up to? Is that
  1506. 52:49good?
  1507. 52:49>> I I I I think that's good. Those are
  1508. 52:51those are good. Thank you.
  1509. 52:53>> Perfect. Perfect. Well, thank you so
  1510. 52:54much for coming on. A real pleasure.
  1511. 52:56I'll have to have you back on in like
  1512. 52:582028 or something like that once
  1513. 52:59everybody's implementing this stuff and
  1514. 53:01you know what kind of craziness uh will
  1515. 53:03be happening over over the next couple.
  1516. 53:05>> It's going to be a ride. I don't know
  1517. 53:07what's going to happen in 20.
  1518. 53:09>> Yeah. And I've stopped asking people
  1519. 53:11like you know when I first started the
  1520. 53:12podcast like what's happening over the
  1521. 53:14next 5 to 10 years? Like you can't you
  1522. 53:15can't do that now. It's it's uh it's
  1523. 53:17it's too crazy.
  1524. 53:18>> You know I'll leave you I know we're
  1525. 53:19over time but I think the automation,
  1526. 53:22robotics, all that kind of stuff is
  1527. 53:24going to be quite interesting. So
  1528. 53:26there's a lot of cyber things now that
  1529. 53:27that cyber physical with AI applied to
  1530. 53:30smart machines and manufacturing and
  1531. 53:32space and all that. It's it's you can
  1532. 53:35see this with the cars and the I that's
  1533. 53:38an area that maybe it's because I like
  1534. 53:39robotics and that's my background a
  1535. 53:40little bit but
  1536. 53:42>> you can see that the machines are
  1537. 53:43getting a lot smarter too, right?
  1538. 53:45>> And and I don't know what the long-term
  1539. 53:47answer is but but it's going to get
  1540. 53:49interesting there more than just the
  1541. 53:50computer networks.
  1542. 53:52>> Yes. Yeah. Completely agree. Awesome.
  1543. 53:56Well, Lee, thanks again for coming on.
  1544. 53:58Um, it's been a pleasure.
  1545. 53:59>> Thank you. Thank you.
  1546. 54:03>> Well, thanks for listening to this
  1547. 54:04week's Future Tech and Foresight
  1548. 54:06podcast. If you like what you've heard
  1549. 54:08here, there are, of course, a number of
  1550. 54:10ways that you can support the podcast.
  1551. 54:12The best way would be to leave a review
  1552. 54:14on Apple Podcasts or give a rating on
  1553. 54:17Spotify, which you can find a
  1554. 54:19step-by-step explanation for on the
  1555. 54:21future technandforsight.com
  1556. 54:24website. Alternatively, feel free to
  1557. 54:26leave a comment either on the episode
  1558. 54:28show notes or the YouTube channel where
  1559. 54:31you can see video recordings of the
  1560. 54:33interviews. And finally, if you are part
  1561. 54:35of an organization that is aware of the
  1562. 54:37disruptive and transformational impact
  1563. 54:39that emerging and future technologies
  1564. 54:41will bring and want to know more, please
  1565. 54:43get in touch to hear about the strategic
  1566. 54:45foresight services that we offer and how
  1567. 54:47we can help futureproof your
  1568. 54:49organization and take advantage of the
  1569. 54:51phenomenal opportunities available to
  1570. 54:53survive and thrive in the future.
  1571. 54:58A lot of future shocked people and
  1572. 55:00future shocked institutions in our
  1573. 55:02society are simply overwhelmed.
  1574. 55:04>> Once there is super intelligence, the
  1575. 55:06fate of humanity may depend on what the
  1576. 55:08super intelligence does.
  1577. 55:10>> Science fact is catching up to science
  1578. 55:12fiction.
  1579. 55:13>> The first truly intelligent machine will
  1580. 55:15be the last invention that humanity
  1581. 55:17needs to make.
  1582. 55:18>> The only scarcity that will exist in the
  1583. 55:20future is that which we decide to create
  1584. 55:22ourselves as humans. Within a 10-year
  1585. 55:24design revolution, we can have all
  1586. 55:26humanity living the highest stand living
  1587. 55:28anybody's ever known.
  1588. 55:29>> Progress is accelerating at an
  1589. 55:31exponential pace, and it's going to
  1590. 55:33reach a point where progress is so fast,
  1591. 55:35it's going to be a singularity.
  1592. 55:37>> We are probably one of the last
  1593. 55:39generations of homo sapiens.
  1594. 55:41>> Every single headline points to the
  1595. 55:44birth pangs of a type one civilization.

About this transcript

This page contains the full transcript of Why Hackers Are Winning the AI War (With Lee Rossey) - Ep #246 by Future Tech and Foresight Podcast, generated from the public captions YouTube serves with the video. The transcript has 10,983 words across 1,595 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.