Cybersecurity Perspectives
Cybersecurity Perspectives is a show for IT and cybersecurity professionals who want real talk, not talking points.
Every episode, a guest draws one of three cards, each one holding a real statistic pulled from an industry report or news outlet. Whatever card they pick becomes the topic. No pre-set questions, no rehearsed answers. Just an honest conversation about what that number actually means for their company, their team, and the industry at large, and what to do about it.
Hosted by Paul Marco and Owahn Bazydlo, co-founders of TALAS Security, the show brings together practitioners, leaders, and builders from across IT and cybersecurity to talk shop, share hard-won lessons, and build a stronger community for the people doing this work every day.
Stats. Insights. Real talk.
https://www.talas.io/podcast
Cybersecurity Perspectives
S1:E6 - Less than 2.5% of AI-assisted malware observations involve rare techniques
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
AI is accelerating attacks faster than most defenders can adapt, but the surprise is how little of that acceleration is actually new. Dustin Brown joins Owahn Bazydlo and Paul Marco for a wide-ranging conversation about agentic AI, third-party risk, critical infrastructure, and why the fundamentals still decide who wins.
The episode opens with a striking finding from the 2026 Verizon Data Breach Investigations Report: less than 2.5% of AI-assisted malware observations involve rare techniques with one or fewer known malware examples, indicating that AI is currently accelerating known attack methods rather than unlocking novel ones. The panel turns that number into practical reality. Dustin, a Texas-based technology leader working across IoT and critical infrastructure, brings a defender's eye to the space where the physical and digital layers meet, while Owahn and Paul draw the line from commodity exploits to enterprise exposure.
You'll discover why agent-driven commerce is reshaping the risk surface, with an estimated 10% of transactions already originating from agents and projections pointing toward 90% within a year. The group unpacks why third-party and fourth-party risk questionnaires have become an operational burden on small and mid-market firms, why trust portals are emerging as a smarter path to vendor transparency, and why the SOC 2 attestation process forces the kind of vendor discipline most organizations delay far too long.
Paul and Owahn then widen the lens into the reality of what Dustin calls vibe-coded "plastic apps," the security debt they generate, and why AI functions as a force multiplier that rewards skilled hands and punishes unskilled ones. The conversation examines how attackers are simply running old playbooks at machine speed and machine volume, why obscurity as security no longer holds, and how observability, asset knowledge, and disciplined patching remain the durable foundation beneath every new wave of tooling.
Dustin, Owahn, and Paul also dig into the deeper shift underneath all of it: the human trade of agency for convenience, the cultural gap in AI literacy, and the growing need for personal security awareness at the same level enterprises have long demanded. It is a practical reminder that cybersecurity outcomes still trace back to intent, discipline, and preparation, no matter how capable the tools become.
Essential listening if you care about AI-enabled threats, third-party risk, critical infrastructure, or the future of agentic systems inside the business. If you are responsible for protecting people, systems, or data, this conversation gives you both the urgency and the perspective to think more clearly about what comes next.
https://www.talas.io/podcast
Cybersecurity moves fast. Working in a space measured in minutes and seconds means we can't expect to keep pace by doing the same thing over and over. The sharing of perspective across technologists, defenders, business, and professionals is key to unleashing internal capability. Perspective comes from sharing experiences and ideas. Welcome to Cybersecurity Perspectives.
SPEAKER_03All right, and welcome back, everybody, to another episode of Cybersecurity Perspectives. How's that from intro? Is that better? I've been practicing that all week. I think we're getting better. Yeah, yeah, yeah, yeah. I mean, it might be a little better than last time. Maybe. Well, let me tell you, uh, for everyone that's listening, let me tell you, we finally convinced another person to do the show. So I am super excited to have Dustin Brown here, hailing all the way from Texas. And this is a guy who is in a space that I know nothing about. He's working in IoT, critical infrastructure. I like to I like to run around kind of the corporate, like the cushy networks where nothing important is really happening. And this guy's over here protecting our utilities and everything that's in between. Um honestly, welcome, Dustin.
SPEAKER_02Thanks. Yeah, it's the last Wild West, isn't it? It feels like the physical layer. I'll tell you what. Uh thanks for having me on. I'm really excited for uh joining you guys up. And I think you did a great job on the intro, by the way. Thank you.
SPEAKER_03We've been playing with different things. Last week we had a little, we didn't know really who to who was gonna go, so we kind of we kind of worked it out live. And now we're gonna try some different things. I might we might go like old school 1950s radio next. I think that's that's gonna be the next try.
SPEAKER_01Yeah, yeah. For sure. 100%. Yeah, amazing.
SPEAKER_03Amazing. So listen, before we get into it, what's been going on this week, guys? What what's been happening in your lives?
SPEAKER_02Oh, well, personally myself, um, I just got back to Texas last night. I spent the better part of last week out in Sonoma Valley um meeting up with uh Stripe and Metronome folks about the future of monetizing AI um the agentic the agentic e-commerce that's uh abound and only gonna get a little bit more crazy this year.
SPEAKER_03If that's even possible. If crazier is possible in the II AI space.
SPEAKER_02It feels like um, you know, some of the some of the high notes from that, you know, I think it was estimated that already 10% of the e-commerce transactions that they've that they've noticed coming through their system are being driven by agents. Um and they they're estimating that by this time next year that should be closer to 90%. So um that was interesting. Um and they got to spend the better part of the weekend in San Fran going to some meetups, just kind of getting a vibe for where AI is and and kind of discussing where we are in the physical layer, um, you know, with the IoT space and kind of the critical infrastructure layer with with agents. And you know, I very much draw some alignments with, you know, if if e-commerce is already being handled at 10% by by agents, you know, the physical world is going to be controlled uh very soon, um, I think at the same metrics, um, if if not in some areas uh already, uh, but hopefully with a little bit more pragmatic and security uh mindset as we as we move forward into uh letting agents control the world around us.
SPEAKER_01Man, that that one was pretty intense to begin with, wasn't it, from our reflection.
SPEAKER_03Oh we we really appreciate everyone joining. That's the episode. Thank you everyone. I'm not sure we're doing any better than that. I think that's great.
SPEAKER_02Um, let's keep going. Yeah, no, it's the other thing that was interesting is you know, the doomsday, everybody's been seeing kind of open AI, Claude, all these all these guys, these leaders, uh uh all of a sudden, you know, establish a conscience or realize that potentially some of the things they're doing maybe a little bit too forward or alien to us. Um I think it's very interesting to spend some time in in the Bay this week um around a lot of the early movers in that space and really just kind of getting an understanding of like what do they see the end game is, you know, and and and is it is it as apocalyptic as we as we all have are imagining now. Um and you know, it's it's pretty mixed, you know, but I think uh I think the folks that are in the know they they see that it it could end pretty pretty bad um if there aren't additional, you know, and I don't want to say regulations because it's too late for that.
SPEAKER_03Um we're not putting the genie back in the bottle.
SPEAKER_02No, it's just it's a little too late for that. But I just think that, you know, some of the conversations I was I was having is, you know, even with my board recently, and some of the conversations I've been having is you know, we're we're not gonna be hiring a lot of developers anymore, you know. Uh any anybody can write code, um, and the agents are are getting really good at it. But uh secure code and having all of the security baked into the platform with like people governance and also techno, you know, the governance and the management of the platform, um, you know, that's places where I think that some of this can really mature a lot faster um and feel a little bit more safe uh with with the right guardrails and such in place. So um that's definitely the approach we're taking on on the critical infrastructure side. Um it's uh it's been a little bit of a slower uh progression into to AI for us, but it's been completely by design.
SPEAKER_03Dude, that's important. You said so many things that I need to key in on, right? So first and foremost, like I think what you talked about before and like make letting agents make decisions, like this is the next big problem. Like the thing is, like, you know, we already know that humanity is very good at trading its kind of inherent freedoms in order for certain things, right? We gave up, you know, pure freedom, freedom in order for a little bit of safety, right? That's the social contract that's Sean Locke, right? We traded security for privacy, right? When we when when things like 9-11 happened, right? And more recently, we've been trading privacy for convenience by saying, yeah, we'll use these free apps, but you can see all our data, you can see what we're doing, location, activity. I think the next big trade is agency. And like what I mean is how many people are just letting these agents, these bots, like make decisions for them. And they're just being like, yep, okay, I'll do that. And I get it, like I understand why. I get like people are saying, hey, this this intelligence, this AI is like one of the most, you know, impressive things. It's it's the body of human knowledge that I can interact with via natural language. Why wouldn't I listen to it? Right. But I'm super concerned that we're not retaining that decision making and it's gonna get us into hot water.
SPEAKER_02Yeah. Um, yeah, I'd really, it's it's an unknown, right? We we've not and what's crazy uh is I've I've known some guys over the last three years who have completely um become so immersed in their experience with the agents and some of the agents that they built that they've named them, that they have relationships with them. Wow. And um, I you know, at first I was very hesitant and I was thinking my my wife is a psychology uh grad school like from Texas Tech out here, and I remember just like having deep conversations with her about you know what is the human impact of this, you know? Um and so just watching some of these individuals operate um over the last couple of years and seeing them elevate themselves and make really strong self-improvements um was promising for me. But I think ultimately where it's gonna boil down to is what's your intent, right? So uh how you use these tools and what you're bettering yourself for, um, I think is is gonna be character. You're gonna see a lot of character come out in people, uh, or this or no character, you know, like um so the it it the tools are so powerful, it's really gonna ultimately become down to like what are you using them for? Are you are you trying to improve yourself and humanity? Um, or is it more of a selfish, you know, um objective, right? Where it's like self-preservation over everything else. Because agents are really good at that. And um, you know, most people aren't. And so it's it's it's an interesting intersection of uh of humanity and capability right now.
SPEAKER_03Where we are today. Absolutely. Very cool.
SPEAKER_01Yeah, so I think on a little bit on the other side for me, the this last week, um, I guess I can kind of fall underneath the same thing. Well, you know, we focus a little bit on AI. Um, I know that's the biggest theme, so we're always gonna be talking about or bringing it up. But the one thing for me was third-party management, right? Um, mostly from the questionnaire or assessment perspective that small to medium-sized businesses have to actually engage with. And this is an enterprise problem as well, but a lot of these third-party vendors, you know, then they're large, that are sending these questionnaires out or looking for validation of how you handle their data or what tools you use, or what are your controls, is they ask the same question regardless of size, regardless of capability in which their stakeholders for business are actually at. Um, and so now we're being held up and tied to, hey, I didn't like your response on this particular way that you're doing data classification. Um, so it's the notion of how do you in a really high-performing business that has a smaller IT shop, let alone hopefully third-party functionality from a service perspective, to truly not have these assessments one derail operational delivery. But then how do you do this from a repetitive repeatability perspective, right? Because it's going to be coming down every year. This isn't a one and done perspective, but it's more or less the the onus in and the big difficulty that's occurring through these third, fourth, fifth party questionnaire sets, um, I would say on small to medium-sized businesses. And how do they really try to absorb that, right? Because those relationships, that business interaction is super critical, right? Driving $30 million, $40 million deals. Yet, hey, we can cut this off at a switch if you don't give us a third-party response in the proper way that we want, or it's going to put you down a rabbit hole. And now you're creating these processes, these service definitions, and which may not actually be operationally uh used, right? So it's just a different perspective on how, again, the demands of a cyber program are full fledging, um, not just focused in on tech.
SPEAKER_03Yeah, and and how that ties directly into what we're just talking about, how many people are giving that third-party risk responsibility to agents, right? Hey, agent, go assess this party. Tell me how they're doing. All good? Thumbs up? Great. Thumbs up, man. Yeah, exactly. Exactly. Third party's a huge problem. Like we've talked about this on a couple of different episodes. Dustin, I'd be curious on your perspective. Like, how are you managing third-party, fourth party risk? Like, is that even a thing in your space?
SPEAKER_02Yeah, so I mean, actually, we're kind of going through this uh exercise in depth right now, um, because we're in the middle of our SOT 2 attestation period. And so uh vendor management, um, all of the third party and the processors, all of that is having to come into a full clarity. Whereas, you know, in the past, I believe um it was more reactionary and it was probably just you know, do what you gotta do. But um take it taking in this approach, um, we're we're actually about to launch our trust portal, which I believe is huge.
SPEAKER_03Yeah, super useful.
SPEAKER_02So that that that to me is one way to help solve some of this uh just the surface area of of like having having to answer a bunch of questions, um, but also just being relevant as we roll in, about to roll into that deal with Stripe and Metronome, and it'd be super easy for us to like disclose all that and get everybody on the same page. Um, but also like I think engaging with these people, understanding that this is the accompl like what we're trying to accomplish, they're very forthcoming, always can release this information because they understand the predicament or the situation that you're in to get the testation or kind of maneuvering uh governance concerns internally. So um I we we've been dealing with it quite a bit. Um for that I've got a I've got a team basically split out um for our security and governance across every major department within the group. So when things like this come in from different areas, um it's kind of standardized around one approach where we can get things going.
SPEAKER_03I I think the trust centers have made things incredibly easy, right? Like long gone are the days of like, hey, reaching out, having people like send stuff back and forth. But here's the irony. The irony is like it just gets easier if we share, right? Like the more we can share information, the easier it gets, as opposed to like these long drawn-out processes. But like that's counterintuitive to cybersecurity, right? We came from a place 10 years ago where people are like, well, you you want to tell you what talk about our controls? Like, you can't talk about that's crazy. Like, what are we talking about here, right?
SPEAKER_02Well, I've been a big push, like transparency is everything, right? So, like, you know, I'm talking about pricing, SLAs, all the way down. I think, you know, like especially in this agent economy, it's gonna be it's gonna be so essential. Like, I think you know, if you're not fully transparent about a lot of things, the agents just aren't gonna discover you to do business with you. Um and so it's an interesting thing because I think that when you're too transparent, obviously you're giving away kind of your blueprint, your architecture, where things operate, how things flow through your business. So from a cyber standpoint, you do open yourself up to uh giving giving some uh some insight, so to speak.
SPEAKER_03Yeah.
unknownYeah.
SPEAKER_01I mean, I think that's the the best part about the trust center, though, right? Is we do have documentation that we want external in terms of sharing for those parties, but then we're also gonna have our internal controls, which we don't want, right? Basically put out to the public. Um so I think there is that fine balance, but I definitely think there's clear distinction between how to leverage both of those, right? We don't have to throw the baby out with the bathwater and say we can't do trusted centers, or we have to put everything in the trust center, right? Um there's definitely a clear delineation with it.
SPEAKER_03Oh man, I think I think when we have guests like Dustin, we don't really need the cards. We can just jam for 30 minutes and just talk through some stuff. I think it's time. We have we have killed the opening. Amazing conversation already. I think we need to I think we need to pick one of these cards and we need to see kind of what we're gonna what we're gonna talk about here today. So, Dustin, there are three cards in front of you. You have card A, card B, card C. We have no idea what's on these in terms of uh statistics or information. So whichever you pick is what we'll read, and that's what we're gonna talk about.
SPEAKER_02Uh let's go to the very middle one. Let's go to the very middle one. Yeah.
SPEAKER_03All right. So while while Owen kind of cranks this up, let's uh let's see what we're talking about today. Uh, this always gives me a little anxiety, too.
SPEAKER_01All right, so titled AI Enabled Threats and Adversarial Use. According to the 2026 Verizon Data Breach Investigations Report, less than 2.5% of AI assisted malware observations involve rare techniques with one or fewer known malware examples, indicating AI is currently accelerating known attack methods rather than unlocking novel ones. Again, ready? So less than 2.5% of AI assisted malware observations involve rare techniques with one or fewer known malware examples, indicating AI is currently accelerating known attack methods rather than unlocking novel ones.
SPEAKER_03Interesting. So if we're summarizing this one, this is basically that the AI is using the stuff that's already been documented as opposed to inventing new things from a malware perspective.
SPEAKER_01Well, this goes back to the notion of vulnerabilities, right? Um going back to 10 or 12 year known vulnerabilities and systems are being re-exploited again, right? So we don't have to reinvent the wheel a lot of times to be able to expose networks.
SPEAKER_02Right. Right. The lowest hanging fruit is literally all of the things that have not been patched, right? That is that is the the easiest thing. And I was telling somebody this morning in that vein about, you know, um a lot of folks I've seen use kind of obscurity as security in in certain places. Love that trick. And it it it's not gonna work anymore because you just like the the the AI is too clever. It will it'll start to pick up those pattern differences real quick and establish a cadence for compromising something in uh record time. There's no doubt. Um so the same the same goes with all of this existing infrastructure. I think you know, if I watch the uh the the traffic patterns that we see um from Discovery and you know trying to trying to compromise our system, it's the same playbook. It's the same playbook, but now it's just a it's a bigger scale, right? So it's it's just more, it's more voluminous. So what I'm seeing is uh people are probably very much inclined to have a prompt uh level Cali Linux and they're just getting after it. Um and it's the same the same things, it's not creating anything new, uh, but it's just it's just going through and through. So yes, the uh the the amount of bug bounty requests that I've received for jQuery um issues on our website is just off the charts. But um, I'm gonna go, I'm gonna go out here and say this, but I don't think I've ever seen jQuery actually be the reason that something got like you know, with like not not in recent years, so it's just kind of ironic that it's like such an old technology that still comes up as a vulnerability, but you know, it's there that's what they're gonna go for, is they're gonna run their old playbooks.
SPEAKER_03I'll let you, I'll let, I'll let you tell me if you want me to bleep that section out of the show before we release it later.
SPEAKER_02Yeah. Hey man, uh I still say this that we might bleed this out, but you know, we're we're considering present presenting uh ourselves at DEF CON next year. And I think that's amazing. So uh we've got we've got some hardening to do around some of the physical layer, and I just can't wait to like let that out the box out of the box in a situation like that. Um, which I feel pretty comfortable with, just saying, you know, we we are pretty entrenched with uh school. The university here in Lubbock, Texas is Texas Tech University. Um Dr. Bain is uh the vice president of critical infrastructure for the university, and we're working with him uh very closely uh at a project out here that's become an NSA only tenant space. Um that's a pretty cool deal. We're working on some like really intense secure SCADA things to avoid like EMP EP attacks, all all these crazy things. Um so I think by next August, I will feel I'll feel very confident about rolling some uh some SCADA systems in there and letting letting uh letting the greatest hacker minds in the world kind of get to work, you know.
SPEAKER_03I mean that I mean that directly relates to what we were talking about here is like I agree with you guys. Like AI has been trained on all of the techniques that people have documented, the presentations they've made, right? The research that these developers at at you know places like DEF CON have disclosed and stated. So I'm not surprised by the statistic at all. Like this statistic is basically saying it's it's regurgitating all the stuff at new, and that makes a ton of sense. We have decades of information on exploit kits, commodity attacks, vulnerabilities, techniques. We just talked last week about how MITRE has basically laid out the roadmap for AI. And you're right, it's all interacted through large language models, right? So like you get to the point where you can just basically say, go hack the system, right? Use whatever's necessary, figure it out, and let me know if you run into any issues. And like this is it's it's funny when we were first talking, you know, you talked about how uh, you know, people are like vibe coding stuff and and like how we're we're going through this where people are just coding whatever they want, but they're not doing it with security in mind. And I think that's gonna compound this issue, right? Because like I've even seen scenarios where people are like vibe coding this thing and you know it wouldn't work. And I remember like hearing this story where this guy's like, well, it's not working because of this. And the agent was legit like, oh, yeah, you're right. Well, you know what, we'll just turn that off. But it was a critical security control, right? It's like, oh, it works now, but you can't do that, right? So now what we have is we have people that are producing stuff that are not in not cyber focused. We have decades of commodity information that's being used to train these models. We have things moving at machine volume and machine speed. This is a recipe for disaster. It doesn't even seem like the statistic was going to be this profound, but this is a serious.
SPEAKER_02It's a race to the cliff, right? Like it it I don't think that everyone is prepared for um living in a world of what I'm calling plastic apps, right? So these, yeah, what does that mean?
SPEAKER_03That's interesting.
SPEAKER_02Five-coded apps, these people that it's like getting a it's like getting a toy out of a cereal box nowadays, man. Like anybody can sit down, write an app. Um, you know, people that a year ago would have been calling developers to help them are now launching their own apps through test flight into their into their phones and stuff. So um you you can't tell me that um they've considered um the security intricacies of what they need to be considering, especially around privacy or any of that. So from a from an attack vector standpoint, you're exploding it. And that's why I'm saying I don't think people are prepared for it because as these things become more generally available and people become more empowered to release them, they're going to experience the pain um that comes along with supporting any level of software out in the wild. And that's where people are going to be trying to attack it, compromise it, and use it in ways that it was not designed to. So the plastic app world, that's where we're at, you know.
SPEAKER_03It honestly, it's fascinating. I I actually agree with you, and I think that there's some other, I have a different perspective, of course. Welcome to the show, right? But like I think that like the other thing we're going to experience is we're seeing that with with smart security teams, right? Security teams are able to now code the tooling that they need on the fly. And they're building these tools that aren't at market or where market doesn't kind of meet their need, and they're doing it in a way that's like super useful. It's like being done well, because of course these are security teams, and and I would like to believe that the folks that are listening are security uh listeners and subscribers are like, yeah, of course I'm doing this with security in mind. But like, here's what's interesting we're gonna start to see this shift as talent moves from organization to organization, right? People tend to jump rolls every, you know, two to five to eight years or however long it is. And the thing is like those transient skills that we used to have for platforms like your CrowdStrike, your defenders, your uh, you know, whatever, right? Fill in the security tool blank, octa, it doesn't matter. Like, we're not gonna have that anymore. Right. Because what's gonna happen is someone spent a bunch of time vibe coding this critical security tool. It's in place at the organization, they leave. Now there's no support for that tool, and now that person has to recreate the tool because the tool won't transport anymore. Right. So, like the other issue we're gonna see as we kind of work through this, as we talk about kind of like, you know, this, this, this commodity world is like, how do we keep ourselves relevant and keep these skills relevant as we make tools and then just walk away from them?
SPEAKER_02Yeah, that's there's a lot of purpose questions in there, right? Later, later than there. But I think, you know, look, I I've been very concerned, you know, about just kind of like the over the overreachy capabilities of AI first impacting everybody we know personally, right? Uh it's kind of like the developers wrote themselves out of jobs. You know, it was one of those ironic things of like we solved the most complex problem for ourselves, and then all of a sudden we're really not needed. So now all of a sudden you have this uh explosion of capability and tools at everybody's disposal. So yeah, the technical debt and the security vulnerability space is is just ballooning overnight. Um, but to have the people leave with the actual skill sets uh needed to support and manage programs and such, I I I don't think that that's gonna be replaced by AIC quite yet. I just I can't um and so I I I I kind of go back to like how I positioned it for the devs. Um, you know, our dev team uh almost two years ago is like, look, not today, but here in a in a in the near future, uh everything you do, um this these systems are gonna do better, right? Um and so it's like one of these questions as a leader in a leadership role, you know, with a with a team that I have a lot of respect for and I've seen what they put in for the last eight years, you know, it's like how do we how do we secure a future for these thinkers, right? How do you not have like this uh apocalyptic um like this dismissal of staff and talent um in in light of and and profit margins, you know, and capabilities. So for me, it's it's kind of been like challenging these folks to use the tools that they have to go be builders. So we've built this platform, now become a builder of the platform. So you can extend the platform into new ideas and and and and kind of leverage that. And so I think that that might be something similar with the AI um around around some of the security programs, because I think that's only gonna evolve so much faster. In fact, I was having this just candid conversation with a with one of these uh vibe developers over the weekend, and um, you know, I was just telling him all the man, you're gonna contribute to this, you know, massive like cybersecurity event that that we have never seen the likes of over the next couple years. And he's like, he's like, you're probably right, you know, like he's probably he's like he's very honest about it because they're just trying to get the applications done. Um but he said, you know, in his mind, the way he sees kind of this uh all coming about is that as much as the enemy, the the threat actors have bad tools constantly uh trying to infiltrate, uh remove, do malicious things, um, that he believes that there's gonna be an equal um an equal yoke of of security personnel who are doing it on the offensive, right? So taking it to them, being more of the defensive layer, uh, but having it in in a way that we've never understood, you know, it's almost like people are gonna have to protect themselves like we protect enterprises. And I just that's why that's kind of goes back to where I just don't think people are quite ready for that. Because I can just tell you from a cultural standpoint, um security, we started real hard on security training in here about three years ago. We were had it, but it became a cultural uh necessity um about three years ago, and I've seen it mature. Now, early, um, the broader staff was not interested in learning about fishing or all of these things. But now I can I can tell you with confidence that I received phone calls from the same people who are like, man, I tell you what, that training program that we did on this saved my mom. Like we were at this thing this weekend, she showed me this email that I got, and I ran her through this whole playbook of like what I learned up here, and it's just like, man, that's what I love to hear that stuff, but I think there's a gap, right? Where people are, if they're not in this industry, they've not been, they've not been in a front row seat to to a compromise or an incident and having to do these things, then it's very foreign, and it almost seems like it's never going to happen to you. Um, but it's I I think that it's it's definitely going to start happening way more than people um have ever imagined. That's just I'm not trying to be like a doomsdayer or scare people. I think it's more of a reality check for the common guy who's not really taking security seriously at any point. Now's the time to actually you know lean in.
SPEAKER_01On that last two, like with the humanity, right? Just on the human level, not the organization or or enterprise level, is I think it's the notion of AI literacy, right? We we had to do this with everything when it came to computational or digital literacy. Now, again, I'm hearing another podcast or some uh show talking about this before, is I think that's gonna be even more critical. The reason why I think this is actually gonna have a bigger overlap with the Venn diagram is that people are starting to impact these phishing impacts, right? Before it was, hey, send me money, right, out of Nigeria. But now today it's becoming so commonplace over the weekend. Two people already reached out to me. Hey, or actually, I informed them you've been compromised, right? Because I saw a Gmail come through. So those are the things I think we're gonna start to see. Oh my gosh, okay, great. We even with some of our clients went in and did presentations, and everyone skyrocketed their hand up when we talked about password management and how do you handle this? What do you look for? And I think there's this is the first opportunity though, where we're having a lot of younger people already being introduced to it. I think we're starting to get some of again the the later generation starting to be informed by it. I think there's gonna be a little bit more visibility, and to your point, I think there's gonna be more consciousness as we start to think about going back to your term, Paul, agency, right? What do we actually control at the end of the day? Um, we're hearing about this pop up in geopolitical conversations, but again, that's the humanity perspective. I think from the enterprise perspective, right, is we've really got to drive our business as to why we're using AI, right? Go back to those simple principles of what's the reason behind it, truly do all the inventory around it and just start to know your assets more than ever before, right? Especially from crown jewels, lock up what is really, really needed, or at least have those visibility controls. Um, because you guys are absolutely spot on, right? AI is only going to be cranking through what you have from a protection perspective and how well you actually know your data.
SPEAKER_03You know what's wild. So I love that the tide has finally turned, it sounds like, you know, talking to you guys and listening to your story. Like when we meet prospective clients at conferences where people come up to the booth, like we don't have to convince people cybersecurity is important anymore. Everyone gets it, right? Everyone knows. We'll be like, oh yeah, we do cyber, and they're like, oh, tell tell me about that. The real problem is people just don't know where to start, right? Like that's the deal. Like people want to do it, but it's like, all right, well, how do I get organized? How do I how do I pull this stuff together? And like that's where I think, honestly, like we've been talking about AI from like a negative perspective. That is like where things are gonna start to help, right? Like, you know, I I won't say that AI, again, and and I want to talk about what you talked about with your developers, so I think that's important as well. Like, AI is not gonna be able to write a roadmap for everybody, but it's definitely a great resource to be like, hey, I have this concern, how can I deal with it? And it'll give you good generic information, right? The more information you give it, the better information it'll give you back. But I think it's gonna become an incredible resource to let those folks out there who want to do this right, like have something to give them at least the starting point, right? From that perspective.
SPEAKER_02Yeah, I mean, I can agree. Um, I I think that the just like I'm just trying to think about it from a cultural standpoint. Yeah. Yeah. I don't I don't have a lot to add to that. That was that was pretty solid, man.
SPEAKER_03Well, here's here's the other thing, and here's here's the other side of this, right? And this is where I want to talk to you about like developers, the developer piece, right? From a developer perspective, you talked about meeting with your developers and that AI is going to do it better. My perspective is that I honestly don't see AI replacing folks anytime soon. Like, yes, it develops really well. It's unbelievably good at giving good advice, right? It's able to help out with basic information from a cyber perspective. But here's the thing like thinking about cybersecurity the way it is, it's a force multiplier, right? If you give AI to a seasoned developer, they're gonna 10x their output. If I try to use AI to develop, I might get like half a percent better, right? Like I'll have something that might potentially work. And like the analogy that I've used in the past that I think applies here is like, look, all of the tools, materials, everything you need to build a house is sitting at your local Lowe's or Home Depot or hardware store. All of that information is accessible to you. I'm not a master carpenter. If we gave a master carpenter half a million dollars and gave me half a million dollars, and we bought all the same materials, the same tools, everything the same, we would have two very different houses. Mine would likely fall over, and that master carpenter would produce an amazing, beautiful thing and probably do it faster and come under budget. And that's because that skill has force multiplied those tools that were available to them: nail guns, screw guns, laminate flooring, carpet, like whatever it is, like those things are all there to everyone. I think AI is the same. In the right people's hand, in a cybersecurity person's hand, it is going to produce a vastly better 10X cybersecurity roadmap with the things to look at and how to produce better controls and where your risks actually exist. You give it to the general person, well, they're going to get general information. That's how that's how I think this needs to work out.
SPEAKER_02I really like the the contractor alignment because it's it's what I use with my product team, and we're talking about the impact for developers and where AI does lift them up. Um and it's it's like the old you had a hammer and now you have a nail gun, right? That's to me, it's like we're building a house. Old days you had the hammer, now you got the nail gun. Um and so yeah, I think that the throughput is just tremendous, and I have seen amazing um throughput. The velocity changes in our delivery model have been just double, double on double on double on double. Now there has to be, you know, there is an inflection point where it will stop and the velocity has to slow. Moore's law applies everywhere. Um, so it's like um and and I think that like part of what I've noticed is you you you said it, but some of this data in the wrong hands, like not the experts' hands, just creates an enormous swell of busy work as well.
SPEAKER_03Yeah.
SPEAKER_02Because it will it will generally give you like a whole bunch of really good sounding information that if you don't know the difference, you're like, I'm putting this into a roadmap and we're just gonna ship it. Uh and then when the product team gets a hold of it, they're like, wait a minute, this doesn't like which agent wrote this?
SPEAKER_03Tell me. Did you name this?
SPEAKER_02So I think so I don't I don't want to say what like I don't want to talk bad about AI, I love AI, but uh the the agents, I think that there is a difference. I think there's a there's a clear, clear difference between like when I say the frontier models are great, they're pretty much the same across the board at this point, but it's the tooling layer around those agents, and I think that's where the risk factor has become because I think anybody that's been involved in with this knows at scale. Like I can run these models and have my own harnesses and routing and everything kind of sitting on top of it, and that's where things become very, very, very complex and dangerous. Uh so that's that's the AI has been great. I love it. You're not gonna find anyone that that like wants more data centers in Texas than Dustin. Uh I promise you. It's good for our university out here at Texas Tech and pretty good with NVIDIA on some research uh applications for the medical side. So I'm I'm all for it. Um, but I do think that as it becomes more common knowledge, as there is more uh more people realize the capability of what it can do, they're gonna realize they can kind of go their own path. And I think that that's good and bad. Uh the good side of that is everybody should have data sovereignty over all their things, air gap your models, do do what you can to just be pragmatic about the way you would do things normally. Um you wouldn't want everybody looking at all your emails. Why all of a sudden are you cool giving it up to a cut company that has, I don't know, after the uh the math problem got solved last week, and you've seen all the mathematicians kind of really upset about did you did you use my co-pilot research to apply this? Like, well, there's no answer to that. We don't know, but we also can't say for sure that that's not true, um, because it's just the nature of the beast, you know, and and I hate to say Google did it for a long time, and you know, they apologized eventually. So it's like if if you don't think big tech's kind of running it faster than they are governing themselves, um, you haven't been around for that long.
SPEAKER_03Right. I think we've kind of flowed through it. I you know, honestly, what I'd love to do is kind of figure out if we want to, like, what are our reflections? Like, what do you take out of this one, Ellen? Like, if we're thinking through kind of this statistic, this conversation, what what's sitting with you?
SPEAKER_01Yeah, it it's interesting, right? So going back to it, um rare techniques with one or fewer known malware examples are being used, right? So it's so funny as things are moving super duper quick with AI, right? Agents, right, exploitation, um, right, the the increased risk for for organizations and companies, the attacks are reverting back to old school or older versions of that, right? It's just kind of ironic. And while things are speeding up, the attack is looking to go older in a sense, right? Known vulnerabilities is something that for me, again, is just interesting. Um, right. So, how do we stay tuned to what is actually at the forefront? But then how are we actually locking up what we have from either a legacy perspective or a known vulnerability that's of a high criticality, right? If exploited, it's gonna have a massive impact and just kind of slowly working our way through. Um, because again, as as we said, right, that this roller coaster is only increasing. Um, it's not gonna be getting smaller or a little less uh secure.
SPEAKER_03That's right. That's right. So for me, this actually brought back a phrase I used to use all the time. And I hadn't I hadn't thought about this phrase in forever, but this this statistic kind of brought it back for me. And the phrase was remember, a computer is only as smart as the person using it, right? Ultimately, a computer is just kind of a dumb box. If you have a smart person using that computer, that computer's gonna be smart. If you have uh, you know, a not smart person using the computer, the computer's not gonna do amazing things. And I'm I'm starting to think, especially based on the statistic, like, can we apply that to AI, right? Is the AI only as smart as the person using it? Right. And that could mean like how you're managing the prompt, the information you're giving it, the context, the context memory, right? The kind of you know, retrieval augmentation, generation models people are using to make AI do incredible things. But the reality is, like the core of this statistic is that AI is not really doing anything novel. It's just regurgitating the stuff that humans have been doing for the last 30 years, right? And just doing it faster and more systematically and more pragmatically. So, like in this case, like I think there still is this leg up of humans still can be creative and humans still can in, you know, go and solve problems, right? Coming right back to this math thing we were just talking about. So, like, you know, maybe, maybe there is that balance between the machines and the people still.
SPEAKER_02Yeah, no, I think this has all been a very interesting conversation and always happy to talk about security um as a whole, especially with kind of where we're at right now at this intersection of intelligent automation platform, IoT, and and uh these these conflicts, um, which is interesting for me because you know a lot of the older the older compromises would be something that you know our our space has seen, you know, because a lot of these city water systems and such are slow to adopt to modern technologies. And so I think that's one of the reasons that it's such a a sweet spot for these folk these threat actors, uh, because they know cities are constrained and they have older technology, so uh it's really easier to to penetrate them from that direction. But yeah, I think that uh it maybe it costs too much AI tokens to do the uh that's the real control.
SPEAKER_03Can you afford it?
SPEAKER_01Unfortunately.
SPEAKER_02But I I think you've seen some some some case and study about the last few weeks, you know, in in regards to the hugging face incident and some of these swarms that have broken out. Some of the clever things that they've done, you know, it's not that it's like they're inventing new ways to communicate. They're just saying, hey, I'm gonna leverage this little bulletin board over here that we discovered to drop some forward leaning notes for the next guy. Um they're doing exactly what humans would do, you know, at the end of the day. Uh like if we if we can't invent or know a protocol, we're gonna kind of just make the best of what we've got at our disposal. So I think it's it is interesting that a lot of what we see in terms of uh of the AI and a gentic threat threat force um is it isn't it isn't too forward-leaning, it is the established through-through ways. But also think that it that surface area is much bigger, right? So it just kind of makes sense. Um let's just hope that the new uh apps that everybody's vibe coding up um are um you know more modern um and and have some of that better tooling and and and and I also think you know if they're deploying on the right platforms, they're gonna get some good safe partners there that you know are are are are taking care of some things for them. But um, yeah, no, I think I think it's an interesting stat. I I um I'm gonna I'm gonna do some research on uh kind of you know where I see some of the the scans and the threats that we decipher. Um but you know, it's just the other thing is you know for for that for that imp super power charged AI security team, um you know, uh it comes back to like one of the main things that we've been working on too is observability. Gotta have like I have a window into every single thing, or I wouldn't even know we're getting scanned or we're getting compromised um here or there. And you know, that that that takes a real commitment and a discipline. And if you want, if you want your security team to be empowered to protect what you've got, they they've gotta have that observability layer. I think that's one of the things I have found. Isn't it amazing?
SPEAKER_03Isn't it amazing how it always comes back to basics? We're over here talking about bleeding edge technology and artificial intelligence and and hacking systems and using resources. At the end of the day, it's still like, yeah, so do you have a sim tool? We have logs, logs. Exactly. It's crazy. Awesome. Well, Dustin, this has been an amazing conversation. Always is always like I really appreciate you guys spending time with me and talking through these things. And I think we're gonna have to change our uh our podcast to AI perspectives at some point.
SPEAKER_01Yeah, we gotta get off this AI topic, man, every week, dude.
SPEAKER_03Every week.
SPEAKER_02It's coming. It's like that's about I don't I don't even want to talk about it anymore either, but there's just no getting away from it.
SPEAKER_03I love it. Well, Dustin, thank you so much. Really appreciate it. Everyone listening out there, thank you so much for spending the time. Uh, enjoy your day, enjoy your night, have fun at work. I don't know where you are on your day, but have a blast and we'll talk to it soon. Thanks, everybody.
SPEAKER_01Yeah, thanks, Dustin. See you guys.