Why Hackers Are Winning the AI War (With Lee Rossey) - Ep #246 — Transcript
Full transcript
- 0:00How have you found the edge cases in
- 0:03this new world that we're experiencing?
- 0:06Like my assumption is new edge cases are
- 0:08kind of coming up all the time because
- 0:09you got these hackers that are notorious
- 0:12and innovative and they're coming up
- 0:13with new ways of attacking. What we do
- 0:15is we create maybe hundreds or thousands
- 0:18of nodes and actual applications and
- 0:20users creating traffic. Real networks
- 0:22are dorky, messed up, misconfigured,
- 0:25have all kinds of weirdness. And so you
- 0:28want to be able to have legacy systems,
- 0:30mainframes, OT infrastructure that has
- 0:34like power company things in there. So
- 0:36you want to create all these different
- 0:37variations. So it's training and
- 0:39understanding all the nuances. But I
- 0:41think over time it's also important to
- 0:43be able to say I'm going to give you
- 0:46wrong data, misconfigured data,
- 0:48different policies. And now quote
- 0:50unquote agent, you got to make a
- 0:51decision just like a human would, which
- 0:54is I got conflicting, incomplete,
- 0:57erroneous data, yet I still need to make
- 0:59a decision. And so can these AI and
- 1:02agents start building that knowledge of
- 1:04what do they do under weird conditions?
- 1:06And that's I think where we are best in
- 1:08class to do all that.
- 1:17We're going through something absolutely
- 1:19historic. Technologies across the board
- 1:22are growing exponentially.
- 1:23>> It's a disruption that's going to
- 1:26completely redefine the way businesses
- 1:28compete.
- 1:28>> In the next decade, we're going to lose
- 1:2940% of today's Fortune 500 companies.
- 1:32>> The exponential growth of computing is
- 1:34continuing.
- 1:35>> AI is nowhere near its full potential.
- 1:38whether you like it or not, that the
- 1:41future cannot be stopped by anyone.
- 1:44>> Welcome back to the Future Tech and
- 1:45Foresight podcast. I'm your AI host,
- 1:48Mark Verbangov's Deep Fake Avatar, and
- 1:50this is episode number 246.
- 1:53Cyber Security used to be a highly
- 1:55technical game played mostly by nation
- 1:57states and elite military agencies.
- 2:00Today, artificial intelligence has
- 2:02completely lowered the barrier to entry,
- 2:04allowing amateur hackers to launch
- 2:06prolific automated attacks against easy
- 2:09targets like hospitals and small
- 2:11businesses. Threat actors now operate
- 2:13like highly efficient corporations,
- 2:15using advanced tools to aggressively
- 2:17scale their offensive capabilities. This
- 2:20massive shift means defensive strategies
- 2:23must evolve just as quickly to keep up
- 2:25with the chaos. To fight back,
- 2:27organizations can no longer rely on
- 2:30simple software updates or theoretical
- 2:32security protocols. They need to build
- 2:35realistic cyber ranges, essentially
- 2:37flight simulators for digital networks
- 2:39to safely test how AI agents and
- 2:42security tools actually perform under
- 2:44heavy fire. We are rapidly entering an
- 2:46era where having an AI proving ground is
- 2:49a fundamental requirement to stay
- 2:51online. Companies that take the time to
- 2:53stress test their systems today will be
- 2:56the ones left standing when these
- 2:57automated threats hit peak production in
- 2:59the coming years. A little bit about
- 3:01today's guest. Lee Rossi is the
- 3:04co-founder and chief technology officer
- 3:06at Simspace, bringing over 15 years of
- 3:09experience from MIT Lincoln Laboratory
- 3:11to the front lines of digital defense.
- 3:14Today he is focused on exposing a
- 3:16dangerous disconnect in modern business
- 3:18leadership. While 78% of executives feel
- 3:22highly confident in their cyber
- 3:23security, actual defensive readiness
- 3:26scores often sit as low as 30%. Having
- 3:29watched AI rapidly lower the barrier to
- 3:31entry for amateur hackers, Lee actively
- 3:34challenges the outdated we've always
- 3:37done it this way mentality, he helps
- 3:39organizations build rigorous AI proving
- 3:41grounds where security teams can safely
- 3:44find out what actually breaks before a
- 3:46live deployment. Through his work at
- 3:48Simspace, Lee continues to push the
- 3:50industry away from assumed safety and
- 3:53toward a future of truly battle tested
- 3:55cyber defenses.
- 3:57Cool. Um Lee, thank you so much for
- 4:00coming on to the podcast today. Uh as I
- 4:01mentioned right, uh you know, a couple
- 4:03minutes ago, I am very much looking
- 4:04forward to this. Um yeah, I think the
- 4:08audience knows that we've been hacked a
- 4:09couple times now. It wasn't us. It was
- 4:11actually through a client and then we
- 4:12got compromised or part of the system
- 4:14got compromised through them. and I kind
- 4:16of have a sense of what's going on in
- 4:18the cyber security and the hacking, you
- 4:21know, like crazy industry, but I'm I'm
- 4:23much more interested to hear what what
- 4:25your thoughts are on this today. So,
- 4:27thank you very much for coming on taking
- 4:28the time to chat.
- 4:30>> Absolutely. I'm excited to be here.
- 4:32>> So, uh before we dive into all that kind
- 4:34of interesting stuff, um what brought
- 4:36you into the cyber security world?
- 4:40>> Um accident I guess. So
- 4:44like any good young engineer graduating
- 4:47from school going off, I was a robotics
- 4:50double E doing computer engineering
- 4:52stuff and ended up at a shop and then uh
- 4:55over at another one. But uh quick answer
- 4:57is two years after school I ended up at
- 5:00a place called MIT Lincoln Lab which is
- 5:02one of these national uh national labs
- 5:04focused on applying you know advanced
- 5:06electronics and national security. So,
- 5:08it's what they call a fedally funded R&D
- 5:09center. And um you know, when we started
- 5:12going over there, started getting into
- 5:14more programming and software and test
- 5:16beds and environments. And I guess I'm
- 5:20old, but that was 26 years ago. Uh was
- 5:24laboratory. We were in the early phases
- 5:26of it.
- 5:27>> Um and started working there for 15
- 5:30years. And eventually we spun out the
- 5:32company in 2015 and here we are 11 years
- 5:35later uh with the company. Awesome.
- 5:37>> So the interest I guess by accident um
- 5:40young engineer you kind of just
- 5:42gravitate towards a particular field and
- 5:44um by the way it's been exciting. Uh you
- 5:47wouldn't imagine it kind of blows up to
- 5:49this point now but it's that's the
- 5:51starting point.
- 5:52>> Yeah. Well I think you know I as I
- 5:54mentioned before I've had a couple cyber
- 5:56security experts come on the podcast
- 5:57throughout the lifetime of the podcast a
- 5:59lot more in the last say 6 months or so.
- 6:02I'm I'm getting a sense that there's a
- 6:05bit of a change in the air, shall we
- 6:07say, in in your industry based on
- 6:10concerns or I don't know if confusion is
- 6:13the right term, but maybe like like it's
- 6:16a nebulous world like people don't know
- 6:18what's happening. They know that
- 6:20security is important. Um but anyways,
- 6:22I'm looking I'm looking forward to to
- 6:24diving into some into some things here.
- 6:26Uh yeah, but um my view is um it really
- 6:31hasn't changed much. There's always the
- 6:33cat and mouse game going back 20 30
- 6:35years. It was always attackers,
- 6:36defenders.
- 6:37>> Um but it used to be a small little
- 6:39niche audience that was just the guys
- 6:41hacking away. Nobody really knew. Then
- 6:43it was more into like the militaries and
- 6:45hacking each other or the intelligent
- 6:47agencies trying to steal data from other
- 6:48countries uh quietly and all that. But
- 6:50it was never really in the news. I would
- 6:52say that in the 20
- 6:552010s 2015s it started getting okay now
- 6:59companies are getting hacked like the
- 7:00banks and the other ones and then it's
- 7:02more like ransomware and a little bit so
- 7:04the awareness goes more and more and now
- 7:06with AI oh now it's everywhere to do
- 7:08this so it's always been happening but
- 7:11now it's faster and more aware so just
- 7:15like in your example it's not just
- 7:16hitting big banks and big militaries and
- 7:19large enterprises you know trying to
- 7:21take money. It's It's prolific. Why?
- 7:24Because the barrier to entry, if you
- 7:25will, got so low. It's easy to build the
- 7:27tools. It's easy to automate. It's like
- 7:29>> unleash and find stuff. And um before it
- 7:32used to be a bunch of like sophisticated
- 7:34guys that knew the craft, call them
- 7:36hackers, but it was people that knew the
- 7:38tech, knew the inards of how the stuff
- 7:40worked, could build and craft exploits
- 7:42and do it covertly.
- 7:44>> Now, a lot of that's been automated. So,
- 7:47right.
- 7:47>> Yeah. So, you're seeing it a lot more.
- 7:49>> Yeah. So, so there's more I mean there's
- 7:51just more as as you said the uh the
- 7:54barrier to entry has has gone down. So
- 7:56you just have more people
- 7:57unsophisticated people being able to do
- 7:59it like I think I think the the
- 8:02specifically the first hack in February
- 8:04for me was very sophisticated. It was it
- 8:07was you know months in the in the I
- 8:10don't know if it was a planning stage or
- 8:12if it was like you know one company
- 8:14hacked my client waited around sold the
- 8:16data right and then it just moved up the
- 8:18chain but it took it took the better
- 8:20part of like eight months for the
- 8:22compromise to finally hit to hit my
- 8:24company.
- 8:24>> Yeah. That sounds reasonable. And and a
- 8:27lot of things that by the time you see
- 8:28the the stuff in the news, it may it may
- 8:31be months or years of planning, of
- 8:33reconnaissance, of getting in, finding
- 8:34the right things, and eventually
- 8:36quotequote pulling the trigger on doing
- 8:38it. And that's always been the case. And
- 8:40you hear about this notion historically
- 8:42like script kitties, you have
- 8:43sophisticated guys that know what
- 8:44they're doing, and then the tools got
- 8:46commoditized like 10 years ago
- 8:48>> where you had less sophisticated
- 8:50operators that would use some of these
- 8:52tools to kind of go in. The bar got much
- 8:55lower now because the AI agents can
- 8:57start doing a lot of that work. So a lot
- 8:59of that tedious time consuming
- 9:02reconnaissance, understanding, finding
- 9:04vulnerabilities, making it
- 9:07>> would take weeks to months to a year.
- 9:09Now it's a lot faster. And so
- 9:13>> um yeah, I agree. I you know what we
- 9:16were doing something years ago. So we
- 9:18create cyber ranges, realistic
- 9:19environments for trading and testing.
- 9:20And we're working with some of the early
- 9:21cyber security companies and they wanted
- 9:23to figure out what adversaries are
- 9:25doing. They said, "Hey, you guys have a
- 9:26perfect environment. Let's create a
- 9:27deception network. Let's create an
- 9:29environment like a honeyet that we can
- 9:31put on the dark web, see it, see what
- 9:33adversaries are doing to kind of learn
- 9:35intent. What are they going after?"
- 9:37>> And 10 years ago, what they found is
- 9:40automated bots doing the scouring,
- 9:43collecting the data, seeing if there's
- 9:44something interesting like looking at
- 9:45the details on your computer, your
- 9:47network. Is this somebody just doing
- 9:48e-commerce or is there something here?
- 9:50But eventually that automated bot 10
- 9:52years ago would sell the data to a user
- 9:56to then say, "Hey, here's what we found
- 9:58on this particular network." And then
- 10:00they sell it off and then some human
- 10:01actor would go. I'm sure that by now
- 10:03it's just way more automated
- 10:06do that. But that was 10 years ago the
- 10:07the automation
- 10:09>> uh was going on.
- 10:11>> So yeah, so 10 10 years of
- 10:14pre-generative AI
- 10:16>> 100%. Yeah. automate automate like we
- 10:18we'll get into like the step change I
- 10:20think that that's been happening over
- 10:21the last couple years. I mean I also
- 10:23personally just start I mean I feel
- 10:26almost embarrassed to say this on a on a
- 10:27future tech podcast. I started using
- 10:29codecs like only only a week and a half
- 10:32ago or so and I like I'm my mind's blown
- 10:34right. So I can only imagine for these
- 10:36sophisticated and even unsophisticated
- 10:39hackers for lack of a better term um
- 10:41using these type of tools for for the
- 10:43better part of you know 6 7 8 months a
- 10:46year or something like that. It's just
- 10:47it's just it's just another world. Um,
- 10:50one one question that I have for you is
- 10:51like how how aware are people like I
- 10:55think you you work with like maybe more
- 10:57sophisticated larger enterprises
- 10:59>> in your industry and I'm sure you're
- 11:01touching base with other cyber security
- 11:03experts that might be working with like
- 11:05SMBs.
- 11:06>> Yeah.
- 11:06>> How aware is I don't know the general
- 11:11industry the general market of the need
- 11:14for cyber security now? Uh I think
- 11:17everybody recognizes there's a need at
- 11:19this point. So everybody it used to be
- 11:21just have antivirus and all that.
- 11:22Everybody to some degree has some amount
- 11:23of cyber security and that's
- 11:25>> for two reasons. A because it's in the
- 11:27news and people are getting attacked and
- 11:29all that. But also I think to your point
- 11:30third party supplier to large
- 11:32enterprises eventually that risk that
- 11:34these enterprise are having whether
- 11:36you're bank or a hospital or others they
- 11:37would say hey show me that you got some
- 11:39level of risk and management and
- 11:41security and containment because I'm not
- 11:43going to connect you to a network do
- 11:44business with you if you don't actually
- 11:46have some minimum level and there was
- 11:48some government standards that started
- 11:49trying to push some of this too. It's
- 11:50called CMMC, which is, hey, let's raise
- 11:52the bar for the defense industrial base
- 11:54to be able to I'm not saying you're
- 11:56going to be perfect, but let's at least
- 11:58get the basic hygiene and let's start
- 11:59getting the stuff in there to do that.
- 12:01>> Having said that, the large enterprises
- 12:04of course are going to spend the money.
- 12:05They're going to hire the people,
- 12:06they're going to hire the tech, they're
- 12:07going to customize it, they're going to
- 12:08go into it, and and they're going to
- 12:10have some good people and and and that's
- 12:11all true, but that's not appropriate for
- 12:13everybody. So, I think the SMB is more
- 12:15managed services. Let me get some tool
- 12:18something like and I'm I'm not picking
- 12:20on any vendor particular but I'm just
- 12:21saying the popular ones. Something like
- 12:23Crowd Strike. It's easy. It sets up. It
- 12:25finds most of the tools that are in
- 12:26there. Or even Microsoft Defender. Hey,
- 12:29turn this thing on. It does a good job.
- 12:31Honestly, that does that. That's a
- 12:33really good starting point for a lot of
- 12:35these. I'm not saying that mediumsiz or
- 12:37small needs to have a dedicated security
- 12:38team and experts and all that. The
- 12:40managed services and those apply apply
- 12:44to the bulk. The large enterprises have
- 12:46different challenges when they've been
- 12:49around for 50 years. They got
- 12:50mainframes. They got IT networks. They
- 12:53got manufacturing if necessary. They got
- 12:55cloud. They got and and they're
- 12:57international and they got different um
- 13:00different locations, rules, laws, those
- 13:02are more of a challenge. And as much as
- 13:04you know when we started off as a cyber
- 13:06security company uh 10 years ago, we
- 13:08just started with the cloud solutions.
- 13:11So we started with Slack and the Google
- 13:12Suite and everything else which if ever
- 13:15back in the days you have your domain
- 13:16controllers and exchange servers and
- 13:19your office and that was a target but
- 13:22but new companies are just all
- 13:24cloudnative and all that. Having said
- 13:25that
- 13:26>> um a lot of the historical ones you
- 13:28don't just throw away 20 years of
- 13:30mainframes and things that make you
- 13:31money just because there's a new shiny
- 13:34that that's out there. So there's always
- 13:36that challenge of transforming,
- 13:38maintaining the business, transforming
- 13:40what you're doing and I think the
- 13:43challenge now is the speed of which
- 13:45things are going which large enterprises
- 13:47are not always used to
- 13:48>> Yeah.
- 13:49>> changing on a dime.
- 13:50>> Yeah. Yeah. Yeah. And that's I think one
- 13:53of the things that we keep hearing you
- 13:55know from all guests working in you know
- 13:58very different industries. Yeah, the
- 14:00this the speed of these transformations
- 14:02that specifically, you know, these these
- 14:05agents or generative AI over the last
- 14:07couple years is bringing about is
- 14:08>> it's uh it's, you know, almost breaking
- 14:11your neck, right? It's break neck speed.
- 14:13It's it's too fast. Um, how
- 14:17I mean, I kind I kind of want to uh pull
- 14:20from you like your understanding a
- 14:23little bit more about the hacking space,
- 14:25right? Like as I understand it, it's a
- 14:28pretty sophisticated industry now
- 14:30compared to what it was 10 years ago or
- 14:33so. And like
- 14:36are they the ones using some of the most
- 14:38sophisticated tools out there in
- 14:39compared to you know us?
- 14:42>> I'm going to put it into broad buckets.
- 14:44I'd say that nations and wellresourced
- 14:48nations have always been doing a lot of
- 14:50the full spectrum. And what I mean by
- 14:52that one is it's I'm developing tools.
- 14:55I'm developing custom tools. I'm
- 14:57training people to be able to operate.
- 14:59So take US Cyber Command. So it didn't
- 15:01exist 10 years ago. Didn't exist 15
- 15:03years ago. They stood up a whole command
- 15:05dedicated on cyber operations for the US
- 15:07military. And um when we started as a
- 15:10company, it was like 6,000 operators
- 15:13dedicated to attacking and defending.
- 15:14Again, that was like 10 years ago
- 15:16>> to do that. And with that comes just
- 15:18like if you're a fighter pilot. If I'm a
- 15:20pilot, I need an airplane. I need a
- 15:21runway. I need a crew. I need logistics
- 15:23and all that. So now I have these
- 15:25operators. I need to have dedicated
- 15:27tools. I need to be able to learn how to
- 15:29attack and defend. I need to have my own
- 15:30dedicated environment for developing and
- 15:33training and rehearsals. And so that was
- 15:35all built out and and what I'm driving
- 15:38at is there's there's the development of
- 15:40the unique cyber capabilities, defensive
- 15:42and offensive. There's the training of
- 15:44the people to be able to do that and and
- 15:46run through. that a large nation state
- 15:49has more than a bunch of guys on
- 15:50keyboards. They have um satellites and
- 15:54submarines and people that can break
- 15:56into a building and stick a USB stick
- 15:58into that. And so when you think of the
- 16:00full set of capabilities that the US,
- 16:03Russia, China, these big guys, it's like
- 16:05it's not just the guy on keyboard trying
- 16:06to hack into the front door. They may be
- 16:08having
- 16:09>> a whole slew of other assets to be able
- 16:11to do that. That hasn't changed. So, and
- 16:15then you have money that comes into the
- 16:17picture. So, when whatever criminal
- 16:19group started figuring out I can extort
- 16:21A, B or C or I can hire some guys, break
- 16:24into a network, ransomware your machine
- 16:27and make money. So, okay, now there's a
- 16:28money incentive to this too. But there's
- 16:32still some skilled operators to do that.
- 16:34AI is effectively just accelerating what
- 16:37these guys are already doing um for
- 16:40that. So I would say that the top
- 16:42countries are still the top countries,
- 16:44the medium ones are so and then you have
- 16:46random people here and there that are
- 16:48doing stuff um for that. But it it I
- 16:53still think that cat and mouse in other
- 16:54words the adversaries get more
- 16:56sophisticated with automation and AI but
- 16:59defense has a voice too. You know your
- 17:01network you can learn your patterns. The
- 17:03good news about AI is like I can learn
- 17:05what's normal. I can learn the stuff. So
- 17:07if you start seeing deviations from
- 17:09what's going on, okay, that's a problem.
- 17:11So
- 17:11>> it's not clear to me that like offense
- 17:14is significantly better or worse than
- 17:15defense. It's always been
- 17:17>> yeah,
- 17:18>> bouncing up and down a little bit. The
- 17:20key though is are you making the change?
- 17:23Are you making a transformation? Are you
- 17:25one of these orgs that are
- 17:26forwardleaning and thinking about AI and
- 17:28transformation or are you sitting on the
- 17:30sidelines um waiting to see what
- 17:34happens? If you're sitting on the
- 17:34sideline, uh, you may be the next victim
- 17:38for that.
- 17:39>> Well, I think that I think that's part
- 17:41of the goal of this podcast is to to
- 17:42make people, you know, realize that some
- 17:44action needs to be taken. Um, ve very
- 17:48interesting. Okay. So, and then and then
- 17:50so that's like kind of nation, state,
- 17:53larger, like the the the the most
- 17:55sophisticated out there. What about uh
- 17:58going back to what you were saying
- 18:00before like the the private industry,
- 18:02the private hacking industry, right?
- 18:04Like the people that hacked my clients
- 18:05and then compromised me. Like I'm
- 18:08understanding
- 18:09that they have multiple specialized
- 18:13companies, right? They've got like COO,
- 18:15CTO, CEOs in these companies and they
- 18:19just operate by, you know, uh um selling
- 18:22compromised data up a chain to to
- 18:25somebody actually doing the the
- 18:26essential hack and the the manipulation
- 18:28of, you know, funds and stuff like that.
- 18:30Is that is that like a correct
- 18:32assumption here?
- 18:34>> Yes. Uh the quick answer is yes. It's
- 18:36not directly my space. I deal with more
- 18:37of the nation states and all that kind
- 18:39of stuff. But in in general, yeah, it is
- 18:40a business at this point. it is a
- 18:42business and they are running it like a
- 18:44business. Um so they are hacking um
- 18:47they're hacking and they're going to go
- 18:48after the easiest targets and sometimes
- 18:50I have to say is you know the banks if
- 18:52you will got more sophisticated they got
- 18:54the stuff in there so they move on to
- 18:56some other ones. Do you remember
- 18:57Colonial Pipeline years ago where there
- 18:59was a hack on so
- 19:01>> familiar?
- 19:02>> This was like five, six years ago. It
- 19:03was a hack on the um an oil and gas
- 19:06company down in Texas. I think it was
- 19:08Texas down in the south that was moving
- 19:10uh gas across the thing. What happened
- 19:12there is, you know, there was a network,
- 19:14there was a there was a VPN connection
- 19:16that was unsecured. So, somebody quote
- 19:17unquote got into the IT portion of it
- 19:20and took out quote unquote the billing
- 19:22server. So, they didn't really hack the
- 19:24pipeline. what they did is take over the
- 19:26billing server, but the company didn't
- 19:28really know what was going on,
- 19:29>> so they shot everything down.
- 19:31>> Um, for that, was that a sophisticated
- 19:34group? No, it's more of the guys that
- 19:35you were just talking about. They're
- 19:36just going after some money, broadly
- 19:38speaking, and and that was an easy
- 19:40target. I hate to say it, but like
- 19:41hospitals, hospitals are focused on
- 19:43medicine. They're focused on keeping
- 19:45people going. They're not security
- 19:46experts, know what you expect them to
- 19:48be,
- 19:48>> but yet they're going to go in and
- 19:50ransomware because they know they need
- 19:52to keep the
- 19:54keep the things running and all that.
- 19:56>> Yeah,
- 19:56>> it's it it it it sucks, but that's where
- 19:59um you go after the easiest target
- 20:01sometimes and
- 20:03>> and when the bar has been raised on the
- 20:06more sophisticated companies, you go
- 20:09after the easier ones to do that. And so
- 20:13yeah, so I think that's my my blanket
- 20:15statement over there. And by the way,
- 20:16it's probably worldwide and the US has
- 20:18money. So go after the countries that
- 20:20have the money,
- 20:21>> right? Makes sense. Makes sense.
- 20:23>> It's like why do you why do you round
- 20:24out the back? Because that's where the
- 20:25money is.
- 20:26>> Yeah. Yeah.
- 20:28Um so okay so
- 20:32with the advent of you know generative
- 20:35AI and now you know the these AI agents
- 20:40are you like we we feel that we're
- 20:43unsafe
- 20:45>> the companies that have taken action are
- 20:48they are they perceiving to be safe now
- 20:51or are they still like
- 20:53we've done all these things but you know
- 20:55maybe there's another 30% % or 50% that
- 20:58we can do like what's the what's the
- 21:00perceived sense of safety for for for
- 21:03the companies and you know the uh the
- 21:05countries that you're working with.
- 21:06>> Yeah. Let me make two broad statements.
- 21:09Um the first one is um
- 21:15is AI has been around for decades. Yeah.
- 21:18It's just the fact that the memory
- 21:20compute all that became affordable
- 21:22enough to be able to really make it
- 21:24going on. I remember when I was at
- 21:25Lincoln Lab many many years ago before
- 21:28it was called the IT or the infosc or
- 21:30the cyber group it was the speech and
- 21:32language processing and speech
- 21:34processing was all about uh neural
- 21:36networks and trying to find a speaker in
- 21:39the middle of a bunch of other ones and
- 21:40figure out the language and all that but
- 21:42the models have been developed for many
- 21:43many years it was just not
- 21:45computationally effective to be able to
- 21:47run it
- 21:48>> cheaper memory and processing made it
- 21:51quote unquote explode and typically the
- 21:53first one that really made or these
- 21:55models could could could
- 21:58build off a lot a lot of data. Um, so
- 22:00that's part one of the comment. Part two
- 22:03is I'm going to use a self-driving car
- 22:06analogy and eventually going to get into
- 22:07the question. So
- 22:08>> I like Whimo as an example. Whimo, if
- 22:10you remember, or you've seen them riding
- 22:12around San Francisco. It's a beautiful
- 22:14car. Well, forget the aesthetics. It's a
- 22:16car that's riding around San Francisco
- 22:17with no pilot in there that um got
- 22:20approval to to run. So, picture this is
- 22:23like a vendor, Whimo, a car getting
- 22:26approval from the city of San Francisco
- 22:28to say, "I'm going to allow this machine
- 22:31to run around my city with people in it
- 22:34with pedestrians all over the place, and
- 22:36I've built enough trust that I am safe
- 22:39to be able to actually navigate on my
- 22:41own around a crowded city with all the
- 22:44silliness that happens in the city." And
- 22:46you can picture that. people jumping in
- 22:48front of the car and families and kids
- 22:50and skateboarders on a rainy day and
- 22:52snowy and whatever else is happening.
- 22:55>> That did not happen overnight. that took
- 22:57um there was a DARPA grand challenge 20
- 22:59years prior where DARPA started creating
- 23:01a lot of these autonomous vehicles that
- 23:02became the national labs or the labs
- 23:04from Stanford and MIT and others that
- 23:05eventually created some of the companies
- 23:07as a spin out that even when got it took
- 23:10him like 10 years worth of data getting
- 23:13all this data to be able to build up
- 23:15enough information to handle not the
- 23:18ideal case but the corner cases by the
- 23:20corner cases is if you're doing an indie
- 23:22track and you're just looping around
- 23:24cool the challenge for all these cars
- 23:26was what happens when I get ambiguous
- 23:30and weird conditions and failure modes.
- 23:32Do I do I do something that's that's
- 23:35appropriate? I say that because
- 23:38in the level of autonomy, so we hear
- 23:40this word about agentic agent being, but
- 23:43there's levels of autonomy just like in
- 23:44the cars level zero to level five ways
- 23:47at a level four. If I make the analogy
- 23:49for cyber, we're at a level two. So when
- 23:52you hear about these cyber security
- 23:53companies saying I am helping you out do
- 23:55that um it's really what they're doing
- 23:58is saying there's a lot of alerts
- 24:00there's a lot of data coming in and I'm
- 24:02going to use AI to quoteunquote triage
- 24:04I'm going to actually help you kind of
- 24:06go from whatever a million alerts to
- 24:10>> a hundred that are more interested in a
- 24:12human can actually keep up with what's
- 24:13going on. Cool. So there's AI through
- 24:15but they're not responding. They're
- 24:17triaging. They're helping kind of sift
- 24:19through the noise to be able to find the
- 24:22interesting stuff. Cool. But attacks are
- 24:25not are more some of the things that are
- 24:27out there are more at a level four. So
- 24:29if you think about what happened with
- 24:31Open AI that was testing some of their
- 24:33new models uh without the guard you know
- 24:36what they want to say is like I'm
- 24:37creating powerful models. Awesome. How
- 24:40bad will this be if it gets into the
- 24:42hands of an adversary that they want to
- 24:44use against? So they took the guard
- 24:45rails off. By taking the guarders off,
- 24:47they want to say, "Okay, let me test and
- 24:49see how sophisticated the model figured
- 24:51out, broadly speaking, how to hack the
- 24:53network, get out of the sandbox, get
- 24:55into another company, take the data to
- 24:57be able to pass the challenge to go
- 24:58through that." Okay, impressive. And
- 25:00there's a couple of examples here where
- 25:01there's self-propagating autonomous
- 25:03software going around and doing it. So,
- 25:05that's a level four. So, we need to be
- 25:07able So, the defensive side is moving up
- 25:10that chain to increase the automation,
- 25:12which is going to be better for
- 25:13everybody. But in my mind, just like the
- 25:17Whimo running around San Francisco, a
- 25:19vendor showing up with a product saying,
- 25:20"I'm awesome. It works in my lab. I've
- 25:23tested it for three days under my
- 25:25conditions of five machines is not
- 25:27enough to allow big bank number one or
- 25:31FA to say, I'm going to trust this thing
- 25:34to put it on my production network, and
- 25:36the whole safety of the uh airline
- 25:38network is great." there's going to be
- 25:40some time to be able to prove that that
- 25:42thing does what you want it to do versus
- 25:44not.
- 25:45>> And my subtler point here is there's a
- 25:48risk of not doing anything because
- 25:50you're going to get attacked by the by
- 25:52the systems. I hate to say but like even
- 25:54in your case if you do nothing you are
- 25:56potentially going to get overrun. If you
- 25:58are too aggressive it may do something
- 26:01damaging but there's this sweet spot in
- 26:03between is like have I built enough
- 26:05trust and confidence where this can help
- 26:07me? I can keep up with it. Um, but not
- 26:10destroy me. By destroying is like doing
- 26:12things that can actually wipe your
- 26:14network or not doing anything that can
- 26:16that can. So, we're going through this
- 26:19really interesting time to me because
- 26:20it's in the news. It's out there. We can
- 26:22argue about regulations and this and
- 26:24that, but the models are powerful and
- 26:26they're getting more and more powerful
- 26:28every quarter and it's helping both
- 26:30offense and defense. I'm on a longwinded
- 26:33thing here, but to me the biggest thing
- 26:36for companies is not necessarily the
- 26:38tech, but is their ability to transform.
- 26:42The companies that are going to start
- 26:44thinking rapidly, start thinking
- 26:46innovation, start thinking about how do
- 26:47I apply these things to do that are
- 26:49probably the ones that are going to be
- 26:51succeeding and making a journey. The
- 26:53ones who don't make the change are the
- 26:55ones that are going to be probably left
- 26:57behind. Do you remember during the cloud
- 26:59days there was this whole transformation
- 27:00of onrem and there was all these cloud
- 27:02providers and in the early days there
- 27:04was like thousands of companies and
- 27:06there was a wild west and
- 27:08>> and now we're down to whatever three
- 27:09four five Amazon or AWS GCP some of the
- 27:12other ones
- 27:13>> you get you consolidated and mature all
- 27:15that we're going through the same thing
- 27:16with AI where there's thousands of
- 27:18companies some new some old that are all
- 27:21trying to go through that it's going to
- 27:23shrink down to something more stable and
- 27:24and all that over time but
- 27:26>> okay But we are going through big
- 27:28change. We are going through big changes
- 27:30right now. And it's and it's a messy
- 27:32time. It's a fun time depending on your
- 27:34perspective. But it's
- 27:38>> it's a you could say yeah maybe fun
- 27:40might not be well yeah I guess it
- 27:42depends on your perspective. It's an
- 27:44educational time. We can we can say you
- 27:46know it
- 27:46>> it is and and again it's more than
- 27:48cyber. It's everything.
- 27:49>> Yeah.
- 27:50>> I I use it for just looking up you name
- 27:52it. And it's it's impressive how good
- 27:55these models are becoming. And it it
- 27:57it's just impressive.
- 27:59>> Yeah. Yeah. Yeah. I mean I I'm I'm
- 28:01personally blown away by you know I'm
- 28:03I'm using codecs all the time right now.
- 28:06Um maybe also a question here. So
- 28:09like cyber security
- 28:12in general is done by you know like at
- 28:14the smallest scale like you know as you
- 28:16said before Windows Defender or
- 28:18something like that or malware bites or
- 28:20so or and then you get into like you
- 28:22know managed services and then you know
- 28:24larger nation state uh large um
- 28:28corporate uh options there.
- 28:32What do you think is like do you think
- 28:34that these coding options are going to
- 28:38enable smaller companies to build their
- 28:41own cyber security tools or is that
- 28:43still a little bit too too outlandish?
- 28:46>> I think it's dangerous. Um and the
- 28:49reason why I say it is um
- 28:52the models are good but there's a
- 28:54difference you know good coding good
- 28:56practices testing life cycle there's
- 29:00value to that. So slapping together a
- 29:02couple of models and code and saying I'm
- 29:05secure is that really better than again
- 29:08I'm going to pick on Crowd Strike and
- 29:09Google and all that. They have teams of
- 29:11engineers that know what they're doing
- 29:13that that that know how to build quality
- 29:16software leverage AI but know how to
- 29:18build quality software. So to me a good
- 29:19company there a has to know how to
- 29:22actually build and engineer something
- 29:23robust scalable that works and and all
- 29:27the good things about that. They need to
- 29:29understand cyber security. So just
- 29:31because I can code, cool. I need to
- 29:33understand the cyber security. What are
- 29:34the threats? What are the aspects? What
- 29:36are the things I need to attack and
- 29:37defend? And I got to understand machine
- 29:39learning and reinforcements and AI. And
- 29:42so that mix of those three things I
- 29:45think makes it successful. By the way,
- 29:47I'm not saying that just because you're
- 29:48a big company you're going to be
- 29:49successful and you're the answer. No,
- 29:51there's a lot of new upstarts as
- 29:52spin-offs that are coming out of these
- 29:54that are going to do wonderful work. But
- 29:56but I do think that just um throwing
- 29:59together some quick code and saying I
- 30:00got a solution that is better than uh
- 30:03some of these guys that are experts in
- 30:06the field
- 30:08>> is probably not the right answer.
- 30:10>> Yeah. Yeah. Yeah. Fair enough. And I
- 30:12guess also one of the things is if you
- 30:14miss one small thing with these new AI
- 30:16tools, they could find that
- 30:18vulnerability and you think you're safe
- 30:19and you're not. So yeah. and and some of
- 30:24these there's an aspect of these cyber
- 30:26security the larger cyber security
- 30:27companies that um I don't want to call
- 30:29it a network effect but take take
- 30:32crossstrike or sentinel one or or Google
- 30:35a lot of the cloud-based tools they're
- 30:37monitoring your network and potentially
- 30:39responding but they're also in a million
- 30:42other networks so they're seeing the
- 30:44patterns that are happening in Asia that
- 30:48perhaps in Europe that perhaps in the US
- 30:50and they're able to from those patterns
- 30:52push the updates out to all the other
- 30:54companies that are a little bit able to
- 30:57do that. Do you remember the Crowd
- 30:59Strike? There was an incident with Crowd
- 31:00Strike, I want to just say a year and a
- 31:02half ago where it took down the
- 31:04airlines. It took it there was basically
- 31:06there was an update that was made to
- 31:07crowd strike that made all the Windows
- 31:09machines crash and those
- 31:10>> Yeah, sounds familiar.
- 31:12>> If you remember, you went into the
- 31:13airport terminal and there was a bunch
- 31:14of crash things and the airline systems
- 31:15went down and all that. It started in
- 31:17Asia and it took down all that stuff but
- 31:19the company over time was able to update
- 31:21it to not make it as damaging to so okay
- 31:25so there's multiple issues with that com
- 31:27one that a single company could have
- 31:28such worldwide impact and dependency on
- 31:31it but um but they do have this broader
- 31:33perspective on on the threat of India
- 31:36having said that I think there's another
- 31:38big change that's happening where you
- 31:40used to think about big nation states
- 31:42and what are the Russians or the Chinese
- 31:43or the Iranians doing in terms of trying
- 31:45to hack into Yumi any other ones.
- 31:47>> And a lot of these companies will spend
- 31:48a lot of time on what they call threat
- 31:50info. What are the adversaries doing?
- 31:51What are the name threats? What's going
- 31:53on to be able to break in to do that and
- 31:55you would basically spend a lot of time
- 31:57making sure that you are secure against
- 31:58that particular actor threat. That's
- 32:00still true. Um, and you would tune your
- 32:03to. But I think there's a new class of
- 32:05threats that is emerging which is these
- 32:07AI agentic system which is I'm not
- 32:10modeling a specific actor. I am a bot.
- 32:12I'm an agent with a goal to get into
- 32:15your network, figure out what's going
- 32:17on, and do blah. And it's going to find
- 32:20some way of actually doing that. And
- 32:22that's a equally valid and powerful new
- 32:25set that you can't just put in some new
- 32:27rule change or some new thing in there
- 32:29to to stop it. So, um
- 32:33yeah, so that I lost my train of
- 32:34thought, but that that's to totally
- 32:37fine. Yeah, we can. Um, you know, I I
- 32:40want to dive in a little bit more like I
- 32:41want to ask questions about Mythos and
- 32:43stuff like that. Um, I see our time, you
- 32:45know, we still have some time obviously,
- 32:46but can we touch on like what exactly
- 32:49you guys are doing?
- 32:50>> Oh, of course. So, we So, at a basic
- 32:54level, we are a cyber range. A cyber
- 32:56range is a realistic environment that
- 32:57you can use to be able to train and test
- 33:00uh test technology, train people with
- 33:02it. So, think of it as almost like a
- 33:04replica of your enterprise network,
- 33:05whether it's a hospital, a back and all
- 33:07that. Create that replica. Now, put in
- 33:09the tools, see how they work against
- 33:10adversaries, and train the people. A
- 33:13good analogy here is a flight simulator.
- 33:15If you're a pilot looking to actually
- 33:16fly a plane, you're going to go through
- 33:18the manuals are going to read the books
- 33:19and all kind, but at some point, you
- 33:21want to get a certain number of hours in
- 33:23front of the thing to do that. And the
- 33:25nice thing about a flight simulator is
- 33:26you can put it into all kinds of failure
- 33:28modes. What happen when your engine goes
- 33:29out? What happens you're struck by
- 33:30lightning? what happens when u the fuel
- 33:33goes blah blah blah you have to do x or
- 33:34y. So you want to be able to get that
- 33:35muscle memory and try it out and go
- 33:37through and run it. So we are the
- 33:39equivalent of the flight simulator for
- 33:41cyber security a very realistic
- 33:43environment that you can put the tech in
- 33:45to be able to actually try it. We now
- 33:46call this the AI proving ground. So
- 33:49think of our environment now as being
- 33:51the reinforcement learning environment
- 33:53where you can put in AI solutions
- 33:55defensive. Let them learn the patterns
- 33:57of what is normal for a hospital, a
- 34:00financial company, a bank. Put all the
- 34:02failure modes, the attacks, the outside,
- 34:04the inside. Yeah. And now you can start
- 34:06seeing how good two answers. A let the
- 34:09tech builders create better models and
- 34:12more robust models. Back to that Whimo
- 34:13example that needed 10 years of data
- 34:15before they could. We're generating that
- 34:17data to be able to let the security
- 34:19tools make sure they can handle all the
- 34:21corner cases and the real world
- 34:23conditions that's going on at some
- 34:25point. But that's for the builders. The
- 34:26builders at some point there's a buyer.
- 34:28The buyer is the bank. It is the
- 34:31hospital. How do I choose which
- 34:33technology is right for me and how do I
- 34:36tune it to be appropriate for what I'm
- 34:38doing? uh to do that.
- 34:40>> So the notion of a proving ground is
- 34:42similar to
- 34:44>> it's been around for decades, which is I
- 34:45have new technology. I'm going to bring
- 34:47it out to a desert or a thing to do
- 34:49that. I like my analogy with Top Gun and
- 34:51I'm sure you've seen Maverick and all
- 34:52that kind of guy and it's wonderful. So
- 34:54the US I do a little military stuff. The
- 34:57US would bring a bunch of pilots out to
- 34:58the middle of a desert. One of them is
- 35:00called Red Flag for the Air Force.
- 35:01There's Top Gun for the Navy guys and
- 35:03all that.
- 35:04>> But if you remember Tom Cruz is like
- 35:06here he is, there's a machine. There's
- 35:08an airplane. So a you want to make sure
- 35:09that the airplane works. So the the
- 35:11engineers take it out to make sure that
- 35:12all works. Eventually you're going to
- 35:13hand it to a pilot and now how do you
- 35:15make sure that the pilot can fully take
- 35:18advantage of that plane and really bring
- 35:20it to its limits. So
- 35:23>> effective what we're doing is and the
- 35:24whole thing about Top Gun Maverick and
- 35:26all those is like you're going to
- 35:27practice the mission before doing
- 35:29whatever it was dropping some bomb in
- 35:30some silo to do all that. So you do all
- 35:33that in a synthetic environment, try it
- 35:35all out to find the limits of what is
- 35:36possible to do that. So from a SIM space
- 35:39standpoint, um, we create the realistic
- 35:42environment. We have virtual users
- 35:44generating traffic just like a normal
- 35:46thing. Think of little AI bots that are
- 35:47pretending to be programmers and
- 35:49administrative users and guys logging
- 35:51into stuff. Attackers that are in the
- 35:53middle of it. And the job of the
- 35:55security products is to sift through all
- 35:56that and make sense and then the
- 35:58operators to use all that to be able to
- 36:00actually run and do their thing. So
- 36:02that's we are the playground. Okay, bad
- 36:05analogy, but
- 36:07Very interesting. Um, so okay, a
- 36:10question following up from that. You you
- 36:11were talking about like Whimo, the main
- 36:13thing that they needed to figure out was
- 36:14the edge cases. Like how how have you
- 36:18found the edge cases in this new world
- 36:21that we're experiencing where I like my
- 36:24assumption is new edge cases are kind of
- 36:26coming up all the time because you got
- 36:28these hackers that are notorious and
- 36:31innovative and they're coming up with
- 36:32new ways of attacking.
- 36:34>> Um, yeah. Yeah. So, it's always a
- 36:36challenge to be able to say that this
- 36:38twin or this copy that you're creating
- 36:40looks 100% like the real network. It's
- 36:42not a model is is is just that. It's an
- 36:45approximation. It's good enough. We try
- 36:48and get as close to possible without
- 36:50breaking the bank and having infinite
- 36:52time to be able to do that. So, there's
- 36:54there's a lot of automation that's
- 36:55getting into it. Um, you'll hear some
- 36:58people talking about creating a
- 36:59synthetic network and and an
- 37:01environment. And when they try these
- 37:02things out, it may have like a couple of
- 37:04servers and a couple of clients with no
- 37:06users and traffic. And that's like maybe
- 37:08five ten machines that are simplistic.
- 37:10What we do is we create maybe hundreds
- 37:12or thousands of nodes and actual
- 37:14applications and users creating traffic.
- 37:16And
- 37:17>> you know what? If you're going to create
- 37:18the synthetic environment, it can't be
- 37:20built and perfect on day one that was
- 37:22just created three days ago and all
- 37:24that. Real networks are dorky, messed
- 37:27up, misconfigured, have all kinds of
- 37:29weirdness. And so you want to be able to
- 37:32have legacy systems, mainframes, OT,
- 37:36infrastructure that has like power
- 37:38company things in there. So you want to
- 37:40create all these different variations.
- 37:41So, it's training and understanding all
- 37:44the nuances, but I think over time it's
- 37:47also important to be able to say, I'm
- 37:49going to give you wrong data,
- 37:52misconfigure data, different policies,
- 37:55and now quote unquote agent, you got to
- 37:57make a decision
- 37:58>> just like a human would, which is I got
- 38:01conflicting, incomplete, erroneous data,
- 38:05yet I still need to make a decision.
- 38:07Back to the Whimo example, there's
- 38:08there's always a decision that's going
- 38:10to make between
- 38:12um do I go left or right? If I got a
- 38:14baby jumping in front of the car on the
- 38:15right side, I got a grandmother jumping
- 38:16in front on the left side and there's a
- 38:18puddle and all that, at some point the
- 38:20decision is going to make about which is
- 38:22the best course of action to do that.
- 38:24And so can these AI and agents start
- 38:27building that knowledge of what do they
- 38:29do under weird conditions? And that's I
- 38:32think where we are best in class to do
- 38:35all that and and recreating ideally we
- 38:38can push a magic button says I'm big
- 38:39bank pull all the data create the super
- 38:42duper version and run and we're getting
- 38:44to that but um yeah but but there's a
- 38:47lot of automation and there's a lot of
- 38:48stuff that goes into uh working that
- 38:50through
- 38:51>> right
- 38:52>> so that's where we think about real
- 38:53world conditions and and realism.
- 38:55>> Okay. And to make it a little bit
- 38:58tangible for for me as well, like how
- 39:01long, like I've got this image of, you
- 39:03know, this this test environment that
- 39:06can do thousands or hundreds of
- 39:08thousands of iterations in like a day or
- 39:10something like that. M probably not. Um
- 39:12what's what's the what's the like
- 39:14>> real world timeline that we're looking
- 39:16on here for for like you know proper
- 39:18testing?
- 39:20When we do when we used to create these
- 39:22custom environments that look like an
- 39:24Air Force base or a bank and all that,
- 39:27people would do it for a training event
- 39:29or an exercise and they could spend like
- 39:31weeks building it out, make it perfect,
- 39:33get it all up and running, run this
- 39:35exercise for a day or two, and then tear
- 39:38it down.
- 39:39>> And it's cool, but that doesn't work
- 39:40when, to your point, I want to make
- 39:42hundreds and of runs and iterations and
- 39:45get all the various conditions. um a
- 39:48typical buildup and all that maybe a day
- 39:50or so if you're starting from scratch a
- 39:52day to kind of build something up from
- 39:53from that has a decent amount of
- 39:54complexity run the traffic run the
- 39:56attacks
- 39:58>> run the tools pull the data out make
- 40:00your decisions did it do well or not
- 40:02tear down and rerun it so there's a
- 40:04number of ways to speed it up but I
- 40:05think there's a difference between
- 40:07simulation which is I'm going to pretend
- 40:09to be a flight simulator versus
- 40:11emulation like we're driving real
- 40:13software real applications real attacks
- 40:16real exploits those move at the speed of
- 40:18a network that it goes through. So I
- 40:20would say that um because if you look at
- 40:22a full attack running through that could
- 40:24take 30 minutes to go from the outside
- 40:27picture the thing that hit you even
- 40:29though it was months of prep the actual
- 40:31execution. Some code probably got into
- 40:33your network compromised some systems
- 40:35moved around stole some they would have
- 40:38to do and pull it out that can take 30
- 40:41minutes to two hours.
- 40:42>> The right
- 40:43>> all the stuff ahead of time took months
- 40:45to kind of figure out how to quite tune
- 40:47it. So each attack may take 30 minutes
- 40:49or so to do that and and we will run
- 40:51through those. So we are always looking
- 40:53to speed up more over time, but that's
- 40:56that's the flavor of where where we're
- 40:58at. I'd say hundreds um let's just say
- 41:02hundreds of variations of attacks and
- 41:04networks and all that per week because
- 41:07there's time to analyze and collect and
- 41:09did it do the right thing and go. The
- 41:11the goal here is we want to get to 99.9%
- 41:16of time the system is running fully
- 41:18automated. No human in the loop. It's
- 41:20just iterating, collecting, extracting.
- 41:23Um we're not quite there yet, but that's
- 41:25that's where we want to be able to get
- 41:26to uh soon enough.
- 41:28>> Interesting. Interesting. And then with
- 41:31this and and I think that's a good
- 41:32point, simulation or emulation not
- 41:34simulation. Um,
- 41:37do you like is it is it like how long
- 41:40does that need to be running for in
- 41:42order to get to this um what you were
- 41:45saying before and I forgot the the
- 41:46specific term but like good enough to
- 41:48start implementing
- 41:50>> I
- 41:52the so there's um and maybe there's
- 41:55steps over here. The first one is when
- 41:57you put it into the thing break. Uh
- 42:00it sounds stupid but sometimes you know
- 42:04when there's a lot of money being dumped
- 42:05into a field there's a lot of things
- 42:07that look wonderful on a website and
- 42:09they worked on somebody's laptop and it
- 42:12did a great demo but you put into real
- 42:14network and did it
- 42:15>> did it handle something that was um of
- 42:18reasonable complexity. So, um,
- 42:22so it does come down to testing and you
- 42:23can run through a battery of tests to be
- 42:25able to actually go through those. But I
- 42:27think I think this maybe is a there's a
- 42:29broader comment here which is we used to
- 42:31have enterprise networks. We would do
- 42:33maybe a pentest once a year or making
- 42:36sure that the scans are all good and
- 42:37there would be like a yearly or
- 42:39semianual check and says, "Yep, you're
- 42:41looking good. You're a partner. I can
- 42:42trust you."
- 42:43I think that model is kind of going out
- 42:46the window a bit where the attacks are
- 42:49moving fast enough where they're finding
- 42:51vulnerabilities in software. They're
- 42:52finding vulnerabilities of things that
- 42:53you can kind of move around. Um you
- 42:56can't just patch fast enough to do that.
- 42:58So it's coming down to how do I
- 43:01continually
- 43:03um test continually run to make sure
- 43:06that the latest models are being used
- 43:08the latest advances are being used. I
- 43:10think every company decent size is going
- 43:13to be on this journey for this AI
- 43:15transformation, the AI transformation to
- 43:17the security stack. So, it's not like
- 43:18I'm going to put in some magic box and
- 43:20I'm done and I can walk away. The tools
- 43:22are evolving fast. The attacks are
- 43:24moving fast. And I think what's going to
- 43:26start happening over time is there's
- 43:28going to be this continual adaptation
- 43:30and learning of the tools. As the tools
- 43:33get more and more advanced, there's more
- 43:34and more automation. there's more and
- 43:36more tuning, not tuning, learning of the
- 43:39tool for your network. Think almost like
- 43:41you mentioned uh mythos
- 43:44>> back to maybe two years worth of
- 43:46advancements of what you see from open
- 43:48AI or anthropic. You look at what
- 43:50Anthropic does today versus a year ago
- 43:53and you can already see
- 43:55>> the rate of change uh that's going on.
- 43:59So I think there's going to be a point
- 44:01here where for these models and these
- 44:03agents to be appropriate and relevant
- 44:05for an enterprise they need to be
- 44:07trained and tuned to that enterprise. So
- 44:11then how do you actually because again a
- 44:12generic model what does it know about a
- 44:14mainframe and a bank and an ATM machine
- 44:17and a defibrill. So it needs to
- 44:19understand what normal is and so you're
- 44:21going to be retraining that model on
- 44:23your environment so that it can actually
- 44:26make a smart decision when it comes down
- 44:28to react and going through that. So I
- 44:31think there's going to be a continual
- 44:33update and learning in your enterprise
- 44:36context. Um especially because there's
- 44:39new models, new technologies, new things
- 44:41that are moving fast. So
- 44:42>> I guess what I'm trying to say is the
- 44:44culture needs to change a bit so there's
- 44:45a continual refresh. Actually, by the
- 44:47way, the people need to change with it
- 44:49um as well for that. So, that's that's
- 44:52my view of what things are going to look
- 44:54like. So, if I were to kind of look out
- 44:56a little bit, 2026 is the year of
- 44:58experimentation. 2026, everybody's
- 45:01playing around. They're toying around.
- 45:03I'm If you're a company's like, I know
- 45:05these things are out there. Let me try
- 45:07some. Let me see what's But nobody's
- 45:09really pushing to a large degree to
- 45:11enterprise. They're not quite robust on
- 45:13that yet. They're not quite
- 45:14>> handling a lot of the automation. The
- 45:16tech companies are pushing the buyers,
- 45:18the enterprise are looking at. So 2026
- 45:21is experimentation pilots. Let me try
- 45:23this out. 2027 is going to be more okay.
- 45:25Now let's start putting some of the
- 45:26stuff into production. Let's start
- 45:28putting stuff into for Rio. Let's start
- 45:29changing things around. Let's start
- 45:31doing it. As we move from there, the
- 45:34whole security stack is going to evolve
- 45:35because as the tech evolves, the people
- 45:38need to be reskilled to now figure out
- 45:40I've moved up a level of automation.
- 45:42It's governance. It's control. It's
- 45:44safety. what is this thing doing and how
- 45:46do I keep this loop up and so now I've
- 45:48transformed my sock and my culture to go
- 45:51through faster but I also think there's
- 45:53going to be a tailoring of these models
- 45:56and agents to specific enterprises and
- 45:58then you start getting into data
- 45:59sovereignty and do if I'm a bank do I
- 46:03want all of my sensitive banking
- 46:05applications and data out into a
- 46:07foundational model
- 46:08>> or more a little bit internally
- 46:11>> that's you so I think 26 and 27 there's
- 46:14A lot of that data is going to be going
- 46:15out to the big F. They want to slurp up
- 46:18your data.
- 46:18>> Sure. Sure.
- 46:19>> There's going to be a there's going to
- 46:20be a balance here for these large enterp
- 46:24and I'm not saying which way is the
- 46:26right way,
- 46:26>> but there's going to be a trade-off here
- 46:28that these companies are going to make
- 46:29to do that.
- 46:31>> Um, yeah. So, I think long term lot more
- 46:34automation from the offense, a lot more
- 46:36automation from the defense. The human
- 46:38role is going to move up to governance,
- 46:40control, swim lanes. Can it is it safe?
- 46:43Is it do the guardos in place? And
- 46:45there's this risk tradeoff that
- 46:46everybody's going to be making for how
- 46:49much do I turn on the quoteunquote AI
- 46:51for defense to keep up with the AI going
- 46:54on with offense and manage that risk of
- 46:57my business still running.
- 47:00>> Very very interesting.
- 47:02>> Okay, I'm on a rant and I'll shut up
- 47:03here in one second.
- 47:04>> No, no, it's fine. I I Yeah, go ahead.
- 47:06You remember how like NSA and some of
- 47:07the Intel shops were telephones and they
- 47:10figured out the whole computer thing and
- 47:11let me take data and they were swamped
- 47:12with data. There just so much data
- 47:14coming in.
- 47:15>> It's like I don't have analysts to keep
- 47:17up with every packet that's going on. So
- 47:18you automated all the process. So the
- 47:22same number of analysts just processing
- 47:23a lot more data to go through,
- 47:25>> right?
- 47:26>> The same is going to be going on over
- 47:27here. It's just the AI and the agents
- 47:29are just going to elevate the they're
- 47:31going to do a lot more of the work and
- 47:33let the human be still in the loop. to
- 47:36be able to oversee and control, but
- 47:38they're not going to be doing the
- 47:39day-to-day stuff because they're not
- 47:40going to keep up.
- 47:41>> Yeah. And and this is this is one of the
- 47:43kind of light bulb moments that I've
- 47:45been having recently, you know, testing
- 47:47with codeex building a couple mock tools
- 47:49here is that oh like the the doing the
- 47:53actual actions are now starting to be
- 47:56automated and work seems to be I'm
- 47:59extrapolating here a little bit but work
- 48:00seems to be shifting into like real
- 48:02knowledge work like you're you're the
- 48:04differentiator is your brain because
- 48:06everybody has access theoretically to
- 48:09the the actor that can actually do the
- 48:12actions. Um, it's very very interesting.
- 48:15>> And in general, I'll make a blanket
- 48:17statement. Um,
- 48:20vulnerabilities and exploit live in
- 48:22complexity. The more complicated a
- 48:24system is, the easier it is for somebody
- 48:26to kind of find a little crack in there
- 48:28to be able to do something. So, the more
- 48:30complicated these things are, the more
- 48:32maneuver space there is for an adversary
- 48:34to get in there
- 48:35>> and do it. And especially if these are
- 48:36black boxes, how do you kind of get a
- 48:39little bit more insight? So back to that
- 48:40knowledge work, you need to start having
- 48:43some good controls and understanding of
- 48:45what's happening um for for going. Okay,
- 48:50I'll stop. I could keep going from here.
- 48:51>> No, it's I I mean our our time's winding
- 48:54down unfortunately here. No, but this is
- 48:55fascinating. I think like you know
- 48:57focusing on the the how should I say
- 49:00this? The the more sophisticated like
- 49:02the larger organizations, the the
- 49:04country states and stuff. I think you've
- 49:06made a really interesting you've you've
- 49:08shared some interesting insight there.
- 49:10Maybe going back down to kind of where
- 49:12we started w within the last couple
- 49:14minutes. Again, maybe a little bit
- 49:15biased and and selfish here talking
- 49:17about codeex. One of the things that a
- 49:19lot of the people that I'm speaking to
- 49:21like they're building their own tools
- 49:23and their own little apps, right?
- 49:24>> And I think as I'm doing that as well,
- 49:27I'm like, okay, I don't want to get
- 49:29hacked again. like am I building
- 49:30something that is now enabling a a a a
- 49:34gateway for hackers to get in? So like
- 49:36how should I and maybe you know smaller
- 49:39business um owners and you know maybe
- 49:41even some medium-sized business owners
- 49:43that are building these things how
- 49:44should we be thinking about cyber
- 49:46security like there's a is there a whole
- 49:48other layer that we need to be adding on
- 49:50to these
- 49:51>> tools that we're building. The quick
- 49:52answer is you're doing the right thing.
- 49:54In my mind, you always you learn by
- 49:55doing instead of this big scary monster
- 49:57that's out there
- 49:58>> just like you're doing. You're getting
- 49:59around there. You're getting smart.
- 50:01You're using it. You're understanding.
- 50:03You're figuring out what works, what
- 50:04doesn't, what you the limits of what you
- 50:06do and don't know. And so
- 50:07>> in my mind, and whether you're a small
- 50:09shop, a medium or large, if you don't
- 50:11start getting your hands dirty and
- 50:13understanding the tech and
- 50:14understanding, hey, yeah, I can do this
- 50:15myself. I got a perfect answer. I'm a
- 50:17small enough. Yeah, this thing does. Or
- 50:19like, you know what? I've reached the
- 50:21limit of what I can practically do. I
- 50:23can buy this thing for 50 bucks from
- 50:24company X, but now I have a better
- 50:26understanding of how to properly use it,
- 50:28size it. I'm oldfashioned. I like when
- 50:32you learn when you do something, you
- 50:33understand that technology. And that
- 50:36honestly, that's 90% of the way there.
- 50:38Okay, I'm exaggerating a number, but
- 50:39once you understand the domain and the
- 50:41problem and the limits and how things
- 50:43are going, now it's not the scary
- 50:45monster. um now you're a little bit more
- 50:48and and those exact questions you're
- 50:50going through it's like okay now I get
- 50:51it and then you can formulate the right
- 50:54questions for what to buy what to use
- 50:56what to make and and it's not just
- 50:59here's some widget buy it put it in and
- 51:01you're going to be awesome um for that I
- 51:05I love that that's that's a that's a
- 51:06perfect tangible like real action thing
- 51:10that that people can take and yeah I
- 51:12think that's also how I'm doing I'm just
- 51:13bumbling through it right and then and
- 51:15then real, oh, I need this. Oh, this can
- 51:17this can happen. Yeah. Okay, fair
- 51:18enough.
- 51:19>> Um, yeah.
- 51:21>> Um, Lee, I see our time is is pretty
- 51:24much uh done here.
- 51:25>> Um, it's it's been very very interesting
- 51:28having you on. Um, again, I think
- 51:32it's it's hard like if I'm talking to
- 51:34myself from like 8 months ago, it's it's
- 51:37hard to communicate to that person who
- 51:39hasn't gone through a hack and see just
- 51:41how disruptive it is. So, like I'm
- 51:43really paying attention to what you're
- 51:45saying because I understand how how
- 51:47disruptive a hack can be to to a small
- 51:51business like a new business like mine.
- 51:53I I can't even imagine to to to a large
- 51:55company. So, for anybody listening, you
- 51:58know, I think it's hard to communicate
- 52:00these things, which is probably a
- 52:01challenge that you have as well, but you
- 52:02know, thank you so much for coming on
- 52:03and sharing these ideas.
- 52:06>> That's awesome. I love it. And again,
- 52:07it's always great to talk with somebody
- 52:09that's curious and and and and is
- 52:11getting around to doing it. But that's
- 52:12where you start seeing why people talk
- 52:13about disaster recovery and backups and
- 52:16and doing all these um Yeah. I it's it's
- 52:20it's by the way, it's going to happen to
- 52:22more or less everybody.
- 52:24>> Yeah. Yeah. Well, may maybe that's also
- 52:26another good point, right? With these
- 52:27tools, everybody is going to go through
- 52:30some kind of comp if it's a total hack
- 52:32or, you know, a minor compromise. So,
- 52:34um, cyber security is going to become
- 52:36more and more more important.
- 52:38>> It it just pervasive. Yeah.
- 52:41>> Yeah. Yeah. Uh, Lee, uh, we'll have
- 52:43your, uh, website in the show notes and
- 52:45your LinkedIn. Are there any other
- 52:46places that you want people to reach out
- 52:48or follow what you're up to? Is that
- 52:49good?
- 52:49>> I I I I think that's good. Those are
- 52:51those are good. Thank you.
- 52:53>> Perfect. Perfect. Well, thank you so
- 52:54much for coming on. A real pleasure.
- 52:56I'll have to have you back on in like
- 52:582028 or something like that once
- 52:59everybody's implementing this stuff and
- 53:01you know what kind of craziness uh will
- 53:03be happening over over the next couple.
- 53:05>> It's going to be a ride. I don't know
- 53:07what's going to happen in 20.
- 53:09>> Yeah. And I've stopped asking people
- 53:11like you know when I first started the
- 53:12podcast like what's happening over the
- 53:14next 5 to 10 years? Like you can't you
- 53:15can't do that now. It's it's uh it's
- 53:17it's too crazy.
- 53:18>> You know I'll leave you I know we're
- 53:19over time but I think the automation,
- 53:22robotics, all that kind of stuff is
- 53:24going to be quite interesting. So
- 53:26there's a lot of cyber things now that
- 53:27that cyber physical with AI applied to
- 53:30smart machines and manufacturing and
- 53:32space and all that. It's it's you can
- 53:35see this with the cars and the I that's
- 53:38an area that maybe it's because I like
- 53:39robotics and that's my background a
- 53:40little bit but
- 53:42>> you can see that the machines are
- 53:43getting a lot smarter too, right?
- 53:45>> And and I don't know what the long-term
- 53:47answer is but but it's going to get
- 53:49interesting there more than just the
- 53:50computer networks.
- 53:52>> Yes. Yeah. Completely agree. Awesome.
- 53:56Well, Lee, thanks again for coming on.
- 53:58Um, it's been a pleasure.
- 53:59>> Thank you. Thank you.
- 54:03>> Well, thanks for listening to this
- 54:04week's Future Tech and Foresight
- 54:06podcast. If you like what you've heard
- 54:08here, there are, of course, a number of
- 54:10ways that you can support the podcast.
- 54:12The best way would be to leave a review
- 54:14on Apple Podcasts or give a rating on
- 54:17Spotify, which you can find a
- 54:19step-by-step explanation for on the
- 54:21future technandforsight.com
- 54:24website. Alternatively, feel free to
- 54:26leave a comment either on the episode
- 54:28show notes or the YouTube channel where
- 54:31you can see video recordings of the
- 54:33interviews. And finally, if you are part
- 54:35of an organization that is aware of the
- 54:37disruptive and transformational impact
- 54:39that emerging and future technologies
- 54:41will bring and want to know more, please
- 54:43get in touch to hear about the strategic
- 54:45foresight services that we offer and how
- 54:47we can help futureproof your
- 54:49organization and take advantage of the
- 54:51phenomenal opportunities available to
- 54:53survive and thrive in the future.
- 54:58A lot of future shocked people and
- 55:00future shocked institutions in our
- 55:02society are simply overwhelmed.
- 55:04>> Once there is super intelligence, the
- 55:06fate of humanity may depend on what the
- 55:08super intelligence does.
- 55:10>> Science fact is catching up to science
- 55:12fiction.
- 55:13>> The first truly intelligent machine will
- 55:15be the last invention that humanity
- 55:17needs to make.
- 55:18>> The only scarcity that will exist in the
- 55:20future is that which we decide to create
- 55:22ourselves as humans. Within a 10-year
- 55:24design revolution, we can have all
- 55:26humanity living the highest stand living
- 55:28anybody's ever known.
- 55:29>> Progress is accelerating at an
- 55:31exponential pace, and it's going to
- 55:33reach a point where progress is so fast,
- 55:35it's going to be a singularity.
- 55:37>> We are probably one of the last
- 55:39generations of homo sapiens.
- 55:41>> Every single headline points to the
- 55:44birth pangs of a type one civilization.
About this transcript
This page contains the full transcript of Why Hackers Are Winning the AI War (With Lee Rossey) - Ep #246 by Future Tech and Foresight Podcast, generated from the public captions YouTube serves with the video. The transcript has 10,983 words across 1,595 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.