Chen Burshan on AI-Powered Threat Detection and Cloud Security at Skyhawk Security | AWS re:Invent 2025
Skyhawk Security CEO Chen Burshan highlights the company’s AI-driven cloud security platform, emphasizing advanced threat detection, automated response, and reduced alert fatigue. He explains how organizations can stay ahead of evolving adversaries by leveraging intelligent automation and modern cloud-native defenses.
Transcript
Hey, everyone. Welcome back here to Techstrong tv. Uh, you know, we're continuing our coverage of in interviewing folks here at, uh, AWS reinvent from our suite up in the wind.
Um, it's been a, an interesting couple days, obviously, a lot, a lot of news, a lot of information, a lot about AI and agent ai. If you haven't had a chance to catch, you know, a lot of our coverage, uh, sponsored by our friends at suse, by the way, we've also had a great, some great conversations with SUSE and a WSI recommend. But let me introduce you to my next guest.
His name is Kim Bohan. Yes. Uh, Kim is the, uh, CEO of a company called Skyhawk Security.
Security. And if I'm not mistaken, it's Skyhawk Security. Skyhawk Security, Correct.
Is the website. So, Kim, welcome back. We, well, welcome back.
The last time I saw you weren't sitting across from me, you are on Zoom, but now we're here in person in Las Vegas. Um, Very excited to be here, and thank You for Thank you. My pleasure.
But look, not everyone watching this saw you last week. Yeah. So I'm afraid we gotta do a little bit of ground keeping here, give people an idea of kinda your journey and what Skyhawk does.
Yeah. So first of all, IO obviously recommend everyone to see our, uh, previous recording Absolutely. More in depth coverage.
Kayak is a, a cloud security company. Uh, our roots are in cloud threat detection and response. In the past years, we added the AI based threat team, uh, and transformed the platform into an autonomous property platform.
Basically, we have a, a red team in AI that fights the cloud threat detection engine and creates a, uh, basically a purple team automated, autonomous purple team on customers environment. And I'm inviting you to talk with us, uh, further to learn more. Absolutely.
And you know, it was interesting. I actually, we, I was mentioning with SUSE earlier, we did a, a panel and we were talking about AI and, and what autonomy it brings in software development. And, and one of the examples came up, sort of like an AI red team, right?
Where, where, look, the code might be generated by one LLM, but we're going to use an AI red team by a different LLM or a different, you know, model to check the code before. And I said, at what point does the human go into this loop? Right?
At what point is if, if the code's generated and the testing of that code is generated and the deploying is generated? So, you know, in my case, I see generative AI as a force multiplier, not, it's not eliminating humans. Mm-hmm.
Uh, in our experience, uh, I was able to build, um, uh, an AI based threat team with extremely efficiently with a very small team. We have, uh, companies that were building, uh, you know, breach and attack simulation with tens of people in r and d. And over years, we were able to do with a relatively small team, what would otherwise, before generative AI take, probably tens, right?
So it's a four multiplier. Uh, even more importantly, in our case, it was, uh, uh, a design, uh, a fundamental design consideration because we thought that adversaries are gonna change, right? They are going to use generative AI in order to build A test.
They are, And you know, we started that claim three years ago, and people were a little bit hesitant. Now it's obvious because we see it in the wild open. AI talks about how, uh, chat GPT was used, uh, uh, and traffic were, uh, uh, talking about how cloud was, uh, just used by adversary to build attack.
So now it's reality, it's obvious, uh, it's a force multiplier for adversaries, and therefore we as the defenders have to use it in order to help our customers protect mm-hmm. Uh, against what they're going to encounter in real life. Uh, so it's not zero human in the loop.
Uh, there is, you know, still a research team, there's still development team. We, we do have, uh, some human envelope, but, uh, the pace in which we're able to, uh, build basically attacks their to customers environments just amazing. It's unparalleled.
Uh, No, this is, I mean, look, I had friends who started like, uh, like for instance, cobalt, you, I'm sure you know, cobolt, you know, crowdsource penetration testing, right? Because before that, the limiting factor was how many pen testers can you have, right? Right.
And now, you know, with crowdsource, I could have literally hundreds, but even that's not enough in today's world where, where we're talking scale. Right? And that, you know what I, again, something that I spoke about on a bunch of the talks over the last couple days is the scale and then the scale, the scale that you see at an AWS or, or Google or Microsoft, any of that.
They don't call 'em hyperscale. It's for nothing. Yeah.
The scale is phenomenal. Yeah. And, and it's, it's the scale and it's also the velocity, you know, that we see the time from initial access still impacted, shortened from months to weeks to now less than an hour, right?
Yeah. It's, it's, it used to be that you would have adversaries in your environment for days or weeks before they would make their lateral movement. And, and the negative impact now from initial access to negative impact less than an hour, it's crazy.
The industry statistics. Yeah. And It's crazy.
And, and it's going down from there too. I, I imagine, Kim, when we had you on last week, it was right around the embargo lifting on this announcement, right? That you guys made.
Again, people may not be familiar if they are great, but let's go over it again. Let's go over the announcement. And now that you're here and you've had a chance to kind of have it, get some legs uhhuh with people, let's hear what you're hearing.
Yeah. So we basically announced adding a genki, uh, into our platform to help with security validation to understand that statement. There's some background that, uh, I need to repeat.
Uh, as I mentioned, we are providing a purple team platform. Basically, we have the detectors that are continuously being fought by an AI based threat team, uh, generative AI based, that builds customer specific attacks against our defense engine. And, but by that, we were able to show customers the true weaponized risks, uh, and how our system would detect that, uh, incident when it happens, uh, and how the, uh, uh, alerts how the CDR portion of the system will look like.
That was well received by customers, and they basically said, it's amazing, but we also have other, uh, security controls in our environment. And apart from seeing how sky o will, uh, react to that incident when it happens, we also wanna make sure that the rest of the security controls we have in the environment will properly behave, uh, to do that. That's where a genki, the new addition we just announced comes in.
Instead of just providing security control, validation of the customer specific risks and our detectors, we're now learning with Agent T ai, uh, framework, basically learning everything that the customer have in the environment. There are sim solutions there, eed, uh, basically we're learning everything that they have. And we, uh, show them how their, uh, ecosystem of security will behave when a weaponized risk will materialize.
That helps them do a few things. First of all, it prepares the sock. Uh, so it creates an automation, uh, of basically verifying that you have all the right detectors.
You can almost do a continuous tabletop exercise so that the SOC knows exactly when they see that sequence of events fired, that it's a true positive that was pre verified. They already know how to respond to that. And again, we're now doing that ecosystem wide, uh, on the customer's environment and integration with Splunk, with CrowdStrike, uh, that we were doing, uh, in order to provide customers, uh, full coverage.
Love it. You've been here a couple days now. What, what's the feedback been?
What are, what are you hearing? What are you Seeing? So, first of all, uh, customers are, uh, really, really excited.
Uh, even my own customers, uh, not just here, existing work, right? Existing customers are extremely excited about what we announced. It came from customers feedback.
So that's, uh, obvious we always thing, right? Listen to customers. They teach us, uh, more than, uh, anyone else.
Uh, but, you know, the traffic at the booth was amazing. The reactions were, uh, good. Uh, I feel that it touches true pains of customers.
You know, they get a lot of noise, a lot of alert fatigue. They don't know what to do with it. You know, people stand by the booth and, and they see the metricses that we placed out there, uh, that customers reported to us.
And they say, okay, I have that pain. I, I want to, uh, uh, learn more and, and resolve the same thing. It's real world.
It's a real world pain that they have. Like, they have real, literally, people told us, you know, hundreds of thousands of, uh, alerts that they need to deal with, whether it's on the risk side, on the vulnerability scanning, uh, as well as, uh, on the runtime side, you know, right. Left of the boom and right of the boom.
And we basically help with all of that. Uh, I must say that if you look on the announcements that were made this week by AWS and others, different places of the stack, but generally the same messages of, uh, AI agents that are, you know, doing analysis, each one of their on their own layer, uh, talking about noise reduction, about the ability to use AI agents in order to provide security. So I think you've seen different places of the stock, uh, exactly the same messages that are being, uh, conveyed to customers, which means there is a, a pain that the industry experience, again, in, in coding, in cloud infrastructure, in vulnerability management.
We see it all over. Uh, I think that there is a, um, a tsunami of, uh, yeah, solution. The solutions from that family that, uh, we're gonna see.
And I'm happy that we were there three years as innovators and think About it. Well, it's always nice to be, you know, early in, in, in that, yeah. In the movement.
Um, this will be over tomorrow. What, what's next for you at Skyhawk? So we're, first of all, we're going to continue to listen to our customers.
They tell us, uh, you know, the best, uh, where we should add next. Uh, I think that what we have right now is really innovative and probably two or three years forward of where most of the market is. Uh, our approach at Sky Oak was to create two major innovation every year, uh, that we announce, uh, and we'll continue to do it, you know, with the iGen, uh, simulation and verification.
I think we, we mentioned it, uh, in our previous conversation. One of the things that we can do is also become a recommendation engine on what, what else to add in order to close gaps. So, you know, these are areas we can expand to.
Uh, but, you know, the core essence remains being a purple team platform, solving the pains of noise reduction, getting the sock prepared to, uh, respond to events, showing customers their true weaponized risks rather than, you know, laundry list of vulnerabilities. They have nothing to do with the, the core values remain, and we will innovate, uh, around them more and more and more. Absolutely.
Excellent. Excellent. Hey, I want to thank you for popping up here.
Thank you for inviting Me. Um, again, it's Skyhawk security. Skyhawk Security.
Check it out. Um, I, I think you said you were gonna be at RSA or We usually do every year. Yeah, Maybe.
We'll, we'll, well, we'll be doing this on Broadcast Alley there, so hopefully we'll see you then. Looking, Looking For it up. A pleasure.
Pleasure. Thank you very much. Skyhawk Security.
Check him out here at, uh, AWS reinvent. We're gonna take a break. We, we have more coming, uh, today, and of course, a full day tomorrow.
So stay tuned. You're watching Tech Drunk TV.