Cybersecurity Perspectives
Cybersecurity Perspectives is a show for IT and cybersecurity professionals who want real talk, not talking points.
Every episode, a guest draws one of three cards, each one holding a real statistic pulled from an industry report or news outlet. Whatever card they pick becomes the topic. No pre-set questions, no rehearsed answers. Just an honest conversation about what that number actually means for their company, their team, and the industry at large, and what to do about it.
Hosted by Paul Marco and Owahn Bazydlo, co-founders of TALAS Security, the show brings together practitioners, leaders, and builders from across IT and cybersecurity to talk shop, share hard-won lessons, and build a stronger community for the people doing this work every day.
Stats. Insights. Real talk.
https://www.talas.io/podcast
Cybersecurity Perspectives
S1:E3 - 130 Vulnerabilities Disclosed A Day in 2025 & 29 Minute Average Breakout Time in 2026
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
AI watermarking, 130 new vulnerabilities a day, and a breakout time that dropped to 29 minutes, this episode shows exactly why cybersecurity now feels like a race you cannot afford to lose. Paul Marco breaks down the numbers that sound terrifying at first, then turns them into a practical framework for understanding what actually matters in your environment.
Using a new card-based format inspired by Wildcard, Paul and Owahn make the conversation intentionally unscripted and high-stakes, then use a 2025 vulnerability statistic and CrowdStrike's latest breakout-time data to uncover what defenders should really be paying attention to. The result is a fast, candid, and surprisingly usable conversation about how to stop drowning in noise and start reducing real risk.
Paul also walks through a real-world example of an organization with 2.4 million open vulnerabilities, showing how fixing process and ownership can cut that number in half without chasing every alert. The conversation then shifts to breakout time, where the 2025 48-minute average has collapsed to 29 minutes in 2026 according to the 2026 CrowdStrike Threat Report, forcing a bigger question: can human teams keep up when attackers are moving that fast?
If you work in cybersecurity, vulnerability management, SOC operations, or any role where you're trying to defend a modern stack with finite time and staff, this episode gives you the perspective shift you need. The numbers are scary, but the message is clear - you are not powerless, and the teams that win are the ones that prioritize, contain, and reduce blast radius before the attackers move again.
Essential listening if you want less fear, more clarity, and a sharper way to think about cyber defense in an AI-accelerated world.
https://www.talas.io/podcast
All right. Well, here we are. I guess welcome back. Welcome. I guess it is welcome back. I mean, we've done we've done bonus content. You know, that's been cool to release that. And we've put that on our socials a bit. Got some decent feedback from that. But I guess, yeah, this is welcome back, but first inaugural, like we're going to eat our own dog food, do the show and the proper structure kind of thing.
SPEAKER_00Yeah. I mean, we have to mess it up first, right?
SPEAKER_01So, you know what? I feel like this entire thing is going to be a train wreck, but we're going to have fun doing it, right? It's going to be a good opportunity, build some community, talk with some folks, meet some people from outside industries we've never met before. So yeah, man, I'm I'm looking forward to this thing. I'm really psyched about it. 110%. Um definitely looking forward to trying to give it a go this first one. Absolutely. Any so any wild stuff this week? Anything crazy happening to you this week or anything that you kind of read about or saw in the news?
SPEAKER_00Um, not necessarily particularly that trying to get caught back up on the real world um coming off of Black Hat and Vacation. It really stifles kind of uh daily output, if you will.
SPEAKER_01Dude, I was compressed for two weeks. Like meetings were backed up, like work had to get done. But it's important. It's important to get out there and see what's in the industry and see what's happening. 110%. Yeah, man. So I did see this wild article this week. And apparently Anthropic is going to start like watermarking content that they're producing, right? So like people can understand now like what's being produced by AI and what's not. Uh what do you think about that?
SPEAKER_00Um I think it's what the industry's been asking for, at least the common user, to say, how do I know things are driven via AI or not? Um I think this is the world of copyright, right? It's nothing that new. Um I'm appreciative that some of the AI content is moving towards this. Um, but again, I I think it's also a band aid on a larger issue or a problem, right? And that's just uh the fidelity on how this has been done, right? Or how often will happen, how what's the quality of it, right?
SPEAKER_01Um, so again, I think it's a new bells and whistles in the industry, but I mean, like, I I'll I'll definitely like I'll admit to you and the audience, it caught me off guard. Like, I knew this was coming. I knew in my art of hearts, like generative AI had gotten so good that it's getting really, really hard to figure out like what is actually real, what is not. And then of course we see article after article, this this big accounting firm use AI, this big consulting firm used AI, and the reports were wrong. We're starting to see things where people are using them in litigation and like it's producing like, you know, poor citations for case law. So like I knew that this stuff was coming. Um, but it's kind of interesting to like have it be real now, you know?
SPEAKER_00Yeah, I don't know. I mean, I think it's the application of how people use it, right? Um, I know internally with us, um, we use it as a tool, just like Microsoft Excel or Word or anything else that's out there, right? Yeah. Um, some people already think are using this too much and they're looking to have final output of a product to be solely AI driven. Um again, I think from a service-based perspective, right? Um CPA firms or law firms that use that to do end-to-end, I think they're making a mistake on that. Um, but I'm not as concerned with a watermark or use of AI within helping to be more efficient to get to my end product, right? And if I need citation for that, fine, I guess. Um, but again, I'm not seeing other places say that, hey, I use SPSS when I was there to crunch out numbers, right? They don't advertise that internally. Right. So it's like, what are we advertising here for, right? If we can't trust our product or cite our product properly, I don't know what watermark's gonna do for it.
SPEAKER_01Yeah, definitely interesting. And and definitely interesting to see like how it's actually applied, who leans into it, who doesn't lean into it. Like it's definitely gonna be, and the thing I still don't understand is like how they're gonna do it from a text perspective. I gotta do some more research from that perspective. I get the I get the image stuff. They'll be able to lay the the watermark within the image, within the image pixels itself. But like the text, I don't know. Is it gonna be a sequence thing? Whatever. We'll let them solve those problems. I'll also be curious to see who follows suit, right? If anthropic is the first one out of the gate, who's next? Is it Gemini? Is it Chappy GPT? Have they already been doing these things? We just don't know.
SPEAKER_00Uh we'll see. We'll kind of see how it goes. Yeah, it'll be interesting too to see how you it works from a licensing perspective as well, right? If I'm a paid client, do I actually have to have that watermark? Do I not? Good point. Um again, right? A lot of this is for mass public consumption. Um, and that's I think a fair opportunity to use that, right? Teachers are gonna love this. I'll try. Okay, now I get to see where this has been used or generated by AI. Um, so yeah, we'll we'll see. But again, for I think the the heavy power users of this, um, not much has changed. Um, potentially reputation play with your clients, but that's the same thing as anything else that you do uh an output of product, right?
SPEAKER_01Yeah, pretty interesting. All right. I think it's time to get into it. I think it's time to lean into to how we've designed, you know, kind of this podcast. In fact, Owen, like this is one of the things that you had brought up. You this format that we're gonna lean into here, this comes from a different podcast we're borrowing it from, correct?
SPEAKER_00Yeah, I definitely have to give shout-outs um in recognition, right, from a psychation perspective, that Wildcard uh hosted on the NPR um podcast network is where this really sparked the idea from. Um and so having the kind of the three-card layout, right? And again, order of we're using A, B, and C to distribute those three piles, um, and then just make a choice at random, right? Um doesn't have to be in order, and it kind of flips a card and allows for a talking point, right? Whether it's statistic, uh a quilt, um a theme within uh cybersecurity or adjacent industries to really just help to spark conversation and open up how people think about things um that are vastly different from ourselves. So that's kind of the gist of it. Um and we're gonna kind of see how this plays out.
SPEAKER_01I know, I know. And and look, I gotta say, I love this because for me, this is about shared vulnerability, right? You, me, we don't know what the what the actual statistic is gonna be. The guest isn't gonna know when they join. We're truly coming at this from a shared vulnerable space. And the guest is gonna be allowed to pick whichever card they want to pick. They'll we'll hit them with that statistic, and then we get to talk about what does that mean for you? What does that mean for your business? What does that mean for your industry? And like to get these different perspectives from people across like the different industries that we don't typically interact with, with companies we don't typically interact with, like it's kind of exciting to get out of our bubble, right? To be to get away from kind of the enterprise financial services network that we've we've built up and used forever, right? But like to be able to see like what does this mean for someone in a different, uh, in a different county or a different state or a different part of the world. Um, so in honor of this, Owen, because this was your idea, I would like you to pick the very first card. So we have three cards laid out. We have card A, card B, card C. Don't necessarily know what's going to be on these cards, but why don't you go ahead and select and uh and let's let's go for it. Just like my default in the SAT exam. See. C. All right. We're going for the last one. Interesting. You know, before we pick, I was a little worried about that. I was a little worried about using ABC. Because like, I don't know, like, is there a psychological thing where people will typically pick A or or or like the first card? I was wondering if we need to change this to like circle square triangle.
SPEAKER_00I think there's always gonna be an inherent move towards something, and it's always gonna trigger someone's mind in some fashion when you use any form of icon or order system. Um, so I would say irrelevant.
SPEAKER_01Irrelevant. Awesome. All right. Well, let's go ahead and go for it. We're gonna go ahead and pick card C. And the card that you chose on is a statistic that comes from 2025. So in 2025, the vulnerability data came out that there were roughly 130 vulnerabilities discovered per day and disclosed. So now we're talking about things like volume. We're talking about things like, you know, uh, you know, the actual speed at which things were being disclosed and what that meant for people's attack surface in 2025 as they're trying to keep up with all of this information coming at them and keeping their and keeping their organization safe. So let's start with it. Well, you read this card initially, what does that mean to you?
SPEAKER_00Yeah, again, um, I think 130 attacks per day um reported, right? So there's a couple of different things that are interesting there. One is the reported nature that doesn't speak to all the other ones that are out there that aren't actually being recorded, right? So it's a disability play. Um, the other element for me is just the unsurmountable tasks that vulnerability teams kind of are faced with, right? Um, and how to basically I don't want to say it's easy to identify vulnerabilities, but that's always the biggest problem is it's one thing to identify, but then how do we actually ingest that and actually prioritize and remediate that? Every single vulnerability isn't gonna have the exact same impact for every single organization. Um, so it's the notion of kind of slowing down with some of these things and really understanding what is the impact um for your organization specifically. Um, but yeah, these numbers are daunting, right? If you look at the global numbers versus just your individual organization, this is where that notion of feeling overwhelmed and drained and not really having an opportunity for a solution. Um but these are one of the numbers too, as I got more in developed with cybersecurity, is it's less of a scare when you start to see these things. Um, but it is honestly really important to understand, like you're saying before, how does this cover across our entire environment, right? Um, because they're usually going to be or never located in just one specific spot, right? It's gonna be throughout your network.
SPEAKER_01You're spot on. Like this is one of those things where it's definitely shock and awe. Like you see that, and immediately your brain goes to like, oh my God, what's the math? Right. So like while you were talking, I did some math. This works out to a total number of vulnerabilities disclosed, right? Actually released in via, you know, the the you know, the the CVS scores, via vendor releases, whatever they were, to 47,450 in 2025 based on this average. Might be a little higher, might be a little less, right? But this was the statistic we came across. Now, what's interesting is like, yes, immediately that's terrifying, but I think you're actually right, right? Like the thing is, not all vulnerabilities one are created equal. That's number one. Two, not all vulnerabilities are gonna apply to every organization, right? Depends on your tech stack, depends on your exposures, depends on what applications people are using. So, like the example I love to give is, you know, where we use Microsoft, right? So that means email is gonna fall to the Microsoft product exchange. So if there's a disclosure for something like IBM Lotus Notes, well, all right, so what? Doesn't matter, right? They can be the worst vulnerability on the planet. It doesn't apply to us. The other thing that comes to mind here is like a couple of years ago, there was a very, very cool project that came out where it wasn't just C VSS. And C VSS talked about like how bad the app, the vulnerability was, like what it allowed an attacker to do and how that attacker could utilize that for whatever the end game was gain access, bypass, you know, cross-stage scripting, whatever. Like the the number of attacks that could be tied to these vulnerabilities is almost limitless. But what's cool is a couple of years ago, this new project came out that was basically ties to EPSS, right? So where C VSS talks about criticality, EPSS talks about how easy or hard it is to use a vulnerability in order to actually enact the exploit. Is it trivial? Is the exploit as simple as like pushing a button and running a single line command that automatically gives you remote code execution? Or does it require multiple steps, including capturing packets on the wire, modifying the packet, sending it to the target, and then you know taking 17 or 18 different steps after that? So I think I think what I'm thinking here is like you think about this statistic, 130 a day, 47,000 over the course of the year in 2025, immediately it's shock and awe, immediately it's fear, immediately it's like how do we keep up with these things? But then as we start to break it down to your point, what applies to us? And then for the ones that actually apply, how easy or hard is it for them to actually exploit us? I mean, I feel like that's really what makes this a little bit more manageable, as long as we can gain that visibility for our organizations individually.
SPEAKER_00Yeah, I think that's the hardest, it's easy to say here to do, um, but I think that's the hardest thing to establish through your organizational teams. Um, to getting the knowledge of having the span of all vulnerabilities, but then getting someone that actually knows not only your network from a systems perspective, but can actually dive down deep into the actual coding languages that your systems require. Right. So to your point, is if it requires an insider threat that actually has credentials that has to be on-prem, it makes it vastly more difficult for someone to exploit that, right? Um, but being able to get these this information and having internal knowledge of how likely things are, and then what's the expectation of that to occur. Like we're talking about multiple teams within a cybersecurity organization that have to do that, right? Your threat team, your volume team, your remediation team, probably your technology team from the perspective of if you really need to dive into that code to understand how that actually function works, right? So this is cutting across multiple organizations. And that's why I think it becomes extremely difficult for organizations to manage this at scale. Um, right. Different application owners are going to say that they're the most important thing in the world and their vulnerabilities need to be addressed. But then they say you can't do code changes and patches and updates. Right. So that's why I'm saying that this space is one of the, I think, most difficult spaces to execute at a high level to decrease what are quote unquote just volume numbers because that's what management looks at, rather than, hey, this is the highest risk in our environment. And we're really addressing those for our most critical applications. Right. That's where the conversation doesn't really flow back and forth between the business and cyber. Um, but the more that those two organizations can kind of come together to understand and prioritize how do we really focus on how it needs the focal, then again, you're going to be ahead of the game, not chasing the numbers, but truly reducing the risk where it's needed.
SPEAKER_01Oh, it's, you know what, you know, that reminds me of it, reminds me of like the nomenclature, like the cut, the phrases we used to use in enterprise, right? Those enterprisesms, right? And then what would everyone say? We take a risk-based approach on X, Y, or Z. And in this case, that does make a ton of sense for vulnerability management, right? And again, look, nothing we're saying here is like groundbreaking, but like again, it's interesting to look at the statistic and then like try to put this into context because like I remember I was working with an organization and we're trying to get vulnerabilities under control. And when I first stepped into the org and tried to get an understanding of like what we're looking at, their vulnerability count was at something like 2.4 million. 2.4 million open vulnerabilities across the entire organization. They had great visibility, right? So from a technology perspective, they had the system fiber scanning, they were doing authenticated scans, they were doing unauthenticated scans, they were scanning regularly, daily, weekly, differentials, like they had everything right. So they knew what was there, but they were lacking process, right? They didn't have process to be able to say, all right, here's that, here's how we're gonna go through and identify what needs to be done and how we're gonna do it, and what change windows we're gonna use, and when we're gonna do our patching, and how we're gonna test those patches. None of that existed. So even though they solved the technology problem from a visibility perspective, I can see all the vulnerabilities I have. They didn't solve the problem from a process perspective. And more importantly, it didn't solve the problem from a people perspective. Because what they didn't have is they didn't have assigned accountability back to the various platforms to say, you're responsible for this platform, you're responsible for its health. Right. So if we're breaking this down across control elements, right? If we're looking at things like the Taus Control Stack, like this is how we would dissect that issue. And one of the most amazing things that happened is once we sorted accountability and process, like we were able to patch, I think it was something like 12 or 14 applications, and it knocked off a million vulnerabilities. It cut them in half, right? Because the other issue with vulnerabilities, you know, we we're talking about like size and scale. I feel like volume becomes a really big conversation when we talk about vulnerabilities, is that you have these vulnerabilities that come out, right? But one vulnerability that's released might result in a thousand vulnerabilities on your network if you have that application installed across a thousand endpoints, or you know, 500 people are using it, or 250 individuals have that app, whatever the whatever the actual volume and sprawl is, like this is where the numbers start to get out of control. But the inverse is also true. So if you can solve for process, if you can solve for people on an accountability perspective, then you can come back and you can say, look, these are our highest levels, going back to our risk-based approach. These are the ones that are most critical, they're forward-facing, they're accessible externally. Whatever the criteria is, if we patch these, we can start to take out entire swaths of vulnerability, data of vulnerability count to actually get this to a manageable level where you truly are mitigating risk. Is that it?
SPEAKER_00Did we kill vulnerability? Is that the stat going underground being buried?
SPEAKER_01I guess so. All right. Well, I think I think we're good at vulnerability. Any more comments on that one?
SPEAKER_00Or do we want to pick another truck? No, again, I think, you know, again coming out of Black Hat, um, this problem isn't going anywhere. It's going to again be expedited, right? Um, with the capability of AI to uh unleash and identify. Um and this also goes back to we certainly understand that there's a lot of legacy systems out there, right?
SPEAKER_01Um I didn't even think of that.
SPEAKER_00And those are the things that are not going to be coming out of the picture of the purview, right? You can't hide any longer by being a 2008 shop or anything like that. Um so again, it's just as you talked about and highlighted, it's it's not to be overwhelmed or scared by the numbers, but to understand that this is a legitimate tactic that would be taken advantage of. And organizations need to build a strategy around for defending it, right?
SPEAKER_01So no, you're you're absolutely you're absolutely spot on. I actually didn't I didn't even think about that, right? So like we we we started this by thinking about the 130 vulnerabilities that existed that were, that were disclosed per day on average in 2025. But those are new, right? Like let's not forget that these things are compounding over the last 15 years or however long CBSS has been like recording, you know, recording these these vulnerabilities. So like the thing that's interesting is you talk about out-of-support software. And I've actually I've actually interacted with a couple clients who have had this issue where like they have software where the company may have gone out of business. This is a real thing. Like they were using something and the company just went belly up. They still had this dependency on this application. Well, guess what? There's no more patching, there's no more support. Like, what do you do in that scenario? I think roll the dice, right? At that point, like security by obscurity. I love it, right? Just don't tell anybody. Take it off of your inventory, just you know, leave it under the desk. Don't like, don't bring it up. That is definitely one way to address it. Yeah. No, I mean, look, there's there's a couple of interesting things people have done. And again, nothing crazy novel, but like some of the things that they've done have been like, all right, well, you know what? We're gonna surround it with additional controls. We're gonna compartmentalize the system because we can't patch it. We can't fit it. It's out of support. There's no more new patching that's coming out. Like this thing is just now not only vulnerable to certain things, but what's worse is over time those vulnerabilities have become commoditized. They're added to all of the different scanners, all the different exploit kits. Like they just are automatic, right? Attackers are just kidding you immediately and like automatically deploying these vulnerabilities. So you have to take this concept of like, all right, I have 130 a day I'm worried about, but I also have the million that's behind that. And now I have to deal with software that's actually added out of, you know, out of support. All right, I'm back on the scared bubble. This is this whole conversation has been an emotional roller coaster. It's like really scary. We're under control, kind of scary. Uh, there's a way out. Oh my God, I'm scared again. Like, I I'm not sure I can deal with many more of these episodes again. I guess the next card, huh?
SPEAKER_00I guess.
SPEAKER_01Oh, all right. Well, you have two cards left to choose from. You have A and you have B. Well, I can't choose C again. I mean, you could, but we'll probably just have to put the episode on repeat. It'll save us a bunch of time. That'll be good. Well, I guess I gotta go the other extreme, right? Let's do A. A. All the way to the left. All right. Let's go to A. Okay. So this actually comes from CrowdStrike's 2026 Global Threat Report. And what they've reported in that, uh, in that report they released publicly was that the average eat crime breakout in 2025 was down from 40, 48 minutes in 2020, uh, in 2024 to 29 minutes in 2025.
SPEAKER_00So can you restate that, please?
SPEAKER_01Yeah, I can. All right. We're I folks, I promise. We'll get better at this. It's our third episode. Like, let us work through this, all right? We can't hello. We can't. We also can't see because I got the I got the years wrong also. So I'm gonna restate this completely. Thank you for calling this out. Okay. Here's what we're talking about. This is CrowdStrike's global threat report. And what they're reporting on here is e-crime. And specifically, what they're reporting out is breakout time. So let's start with that. Breakout time is the time it takes from an attacker to gain access to the very first system and how long it takes them to break out to the next system. In 2025, the average breakout time was 48 minutes. So an attacker was able to gain a foothold on a very first system, laterally, right? And then the time it took them to move laterally from that first entry point was 48 minutes. In 2026, their report brought that down to 29 minutes. So sub 30 minutes, the ability to break out on average from the first system into the next system.
SPEAKER_00What does that feel like for you? It's interesting, right? I think there's a lot of things that kind of come to mind in the sense of quickness for sure, right? I mean, that's the first thing that comes to me is that the attackers are able to move laterally quicker. Um the secondary thing is kind of coming to mind is why, right? Yeah. What why are someone able to move quicker through our environment? And again, a couple of things come to mind. Again, what a novel here, right, is potentially more living off the land tools. Right. So as we know that detections are coming through, attackers know actually how to make amass themselves to go through good traffic. Um, right. And I think a lot of this also brings up to the fact that the breakout time isn't talking about. out the dwell time, right? How long is someone on the network? It would be a really awesome data point to understand this a little bit more. Right. The reason why I bring that up is because my assumption is that are we having better, more sophisticated attackers to say, get an understanding of the network first and sick. Learned. Don't try to go in there and get your objective immediately. And then the other element of that for me is that they're getting really good at trying to understand the network in a quiet area. They may not be hopping somewhere that is the highest level of admin credentials immediately. Sure. They may be trying to hop to different areas of the network, slowly working their way towards again, admin credentials or elevated privileges. And so again, just a couple of those things that are sparking to me from that perspective of, you know, why, what's the importance, um, how are they doing it? But then from the defensive perspective, right? That that's definitely scary in the sense that you do want to start to reduce how they are going in your network, right? If they're in, it's always about containment, right? How quickly can we stop them from moving? And this is basically saying it's not happened quick enough, right? Sure.
SPEAKER_01You break you actually bring up something I never thought about before, right? So like immediately when I read this card, the things that came to mind are this concept of, okay, clearly AI is playing into this. Clearly they're they're playing you know kind of those red team bots. Like, and we can talk a little bit about the difference between red teaming and blue teaming and like how AI agents are are changing those worlds and what they're doing. And I have, I have a personal opinion that red teaming and like the exploitation side of these bots is way further ahead than blue teaming because of the nuance that comes with defense. We can talk about that later. But you bring up something I never thought about before. Like so I never thought about this concept of living off the land and utilizing those tools in terms of speed, right? But I think it actually makes a tremendous amount of sense. So for those of you listening, those of you new in your career, we talk about living off the land, what that means is that means that the attackers are using built-in tools that are that are a part of the operating system. They're a part of the the actual network that exists. They didn't have to drop in new tooling they didn't have to download malware. They didn't have to utilize the tools that they built off of offline. They focused on like utilizing the things that were already on the system. And the reason why this attack is so effective and so useful is because they're hard to detect. These are built in, they're trusted, they're signed by Microsoft or whoever, whatever the operating system is so when they're utilized, it's not like we have we have a signature for them, we do, but they're used all over the world, right? So it's kind of buried and that's what Owen was alluding to. So like if I think about this, which is a new perspective for me from the perspective of speed, I think that makes a tremendous amount of sense. The tool is always consistent across the board, right? They've gotten good at looking for those specific tools, what to use. The commands are probably you know copied and pasted, right? If they're not automated, bringing it back to the AI agent stuff we were talking about a second ago. So I actually think that makes a ton of sense, right? Because like there is no stopping it. Like we have to now rely on behavioral analysis because the actual signatures of the software themselves don't matter. Everyone has them. They're approved they're used for day-to-day administration. I think that definitely part of this though is absolutely AI and like this concept of these unconstrained models, the agents that have been built that are basically being fed with every piece of information that any pen test has ever uncovered, any tactic built into things like Cali Linux, any any tooling that's been built over time, like all of these things are being produced and provided at machine speed. And that's what I think is starting to get this breakout time down do you think?
SPEAKER_00Yeah, no, agreed um my math's horrible right um but that's what 19 minutes difference? Yeah so so on average back in your SOC days, how long was a very capable tier one analyst able to dispose of an alert?
SPEAKER_01Wow, great question man. Like so this is so this is back in the day before we had like AI analysis tools, right? Which is which has sped things up amazingly so like if we're not if we're talking about true human look at alert, find the logs, triage, like triage alone would take anywhere from 15 to 25 minutes depending on complexity. And that's only the first look and that's only like tier one before we got into levels of escalation. And that's assuming the queue didn't have them hold those alerts for two to three hours.
SPEAKER_00No totally and so that's where my head is going on this perspective is like it's one thing to understand how quickly the attackers are moving. But that's exactly where I think on the best average back in the corporate days when I was about in the sock area, I think was 15 minutes. And that's someone that knew their shit excuse me. They knew where to go, what to look for, what signatures are bad, what are good. And so that's 15 minutes. We're saying though that this hot took about 19, right? Give or take. Yeah. On average I would assume that a normal human is about 20 to 30 especially a tier one junior level. Sure. Right? AI is helping along the way but again that's where the notion of if you have AI that's doing an end to end without human intervention, can you trust that how often is the testing being done, right? How likely are these to pick that up? Even if you have a human that's overlooking AI triage response, again, are they capable enough to see sift through that to be able to pivot? So in this example, we've got one hit, right? 19 minutes quicker, they're already in the next spot of your actual network. So is an analyst able to keep up with these speeds and identify as your certain aha right. So this just again compounds of definitely want AI automation to be able to know how to take proper action. But again going to practice that's extremely difficult because you don't usually want to block certain things on sensitive systems unless you fully know it on 100%.
SPEAKER_01And you know what's interesting is like again I'm also terrible in math but like if if if I'm thinking over this if we're going from 48 minutes and reducing by 19 minutes, like we're close to like 35 to 40% reduction in one year. I I I can't even imagine what the 2027 number is going to be. Right. Like we're we're gonna get into like sub 15 from in terms of breakout. And the thing is like folks the thing that's scary about this is that it's not necessarily just like oh that's the breakout that's the average right so there are plenty of organizations that have invested in cyber they've they've hardened their systems they've built the right tooling and those breakouts are going to be in the you know whatever hour range but think about all the other organizations where we've seen like we've seen the quickest breakout has been something like 54 seconds. Right. So like if we're if we're bringing this back down to averages like this doesn't mean you have, you know, whatever it is 29 minutes to get your act together. It really depends on your organization, depends on your controls, depends on the staffing you have uh assigned to it. Uh, you know, and like these are the things that really start to break out that nuance.
SPEAKER_00Yeah. And I'm not again I'm not a an AI um evangelist, but I think to your point, right, we've been seeing that over about the last one to three years are that the defenders are understanding that they have to invest in AI. So it's now becoming AI is fighting AI is defending AI. Right. It's AI against AI. Yeah it's by vs spy I'm dating myself but the old mad magazine spy versus spy right like and that's where it's again the attackers inherently are going to be ahead of the game because they're able to learn quicker. They're able to implement without having to have approvals, right? Compliance oversight, governance, none of that stuff. But we can't stop to to incorporate the AI capabilities again, as we talked about before defense and depth, right? Where are the other controls that we actually can manage to helpfully thwart against that, right? I think it was at Black Hat where someone was doing a presentation on the economy of the economics of the economics of malware.
SPEAKER_01Yeah. That was amazing.
SPEAKER_00And kind of shifting from what our big opportunity here is not to fight dollars with dollars, but to kind of rethink how we're implementing our controls. And I think what he said is redo the physics of it. Yeah. Right. So I started to think about how do we use tool sets appropriately to keep up with or go past how basically attackers are just leveraging money at the NMS AI tools and capabilities to do things quicker. Yeah. Right. Because we're not going to be able to keep with speed. So again moving this to a different area of thought right is sports for me. If you're bigger and stronger, I'm gonna be smaller and quicker. If you're smaller and quicker, I'm gonna be bigger and stronger. Right. Right. So it's those those notions of how do we stay creative to meet someone at that point of conflict rather than trying to say I'm gonna match you dollar for dollar.
SPEAKER_01That is an amazing perspective. And that's what this podcast is about. So look we're at 30 minutes on this is the fastest 30 minutes this week. I'll tell you right now, this conversation just flowed for me. Super amazing to take a beat and talk about these things. Really appreciate it. What are your last thoughts you want the audience to leave with on this one?
SPEAKER_00I'm just looking forward to to getting participants, building the community right love Paul. No I think we're both you know somewhat intelligent, fun people to talk with, but um we definitely need others, right?
SPEAKER_01We definitely want some different perspectives or we're gonna start saying the same thing over and over again. Agreed. And and look we definitely have a bunch of guests lined up super excited to circum some folks on on the uh on the show here. You know what I want to be audio to leave with on this one is for me, like a lot of the theme here is fear today. And I hate that. I hate that our industry that cybersecurity just drives this concept of fear all the time and it it's very frustrating. But like I think what we talked about today are exactly how you get past that fear, right? Like the numbers are scary, but you're in control of your network. You can pull the levers you need to in order to start to reduce these numbers, reduce your attack surface and make it harder for the attackers to do what they need to do. But that's on you, right? Like one of the things I love to tell clients when I'm talking them is remember you have home court advantage to bring this back to a sports analogy, right? You have control over all the tech. You can fix the things in order to make sure things like this don't happen. Or when they do happen, because that unfortunately is a reality in our space, you minimize the blast radius, you keep things nice and small and you make them easy to just kind of fix and move on from I think that's it, man. That's uh the first full episode in the books and uh it's been a pleasure. I can't wait to get it going again. Gaveled. Gavled. Also take care.