Innovations in Cybersecurity with Christy Wyatt | Black Hat 2025
Christy Wyatt, president and CEO of Absolute Security, shares her journey in the tech industry at Black Hat. She discusses the company’s unique cybersecurity technology that creates resilient endpoints with self-healing capabilities. Wyatt highlights the importance of intelligent devices in responding to threats and the role of AI in cybersecurity. She reflects on the dynamic nature of the event and emphasizes proactive measures for future security.
Transcript
Hey everyone. We're here again on the floor of uh, black Hat. You know, it's funny, it's a very interesting show floor.
You walk in and you know, it's so loud. There's so many bells and lights and whistles and, but we found a little bit of a quiet area. We actually didn't truth be told, we kicked a guy out who was doing a demo here from Absolute Security.
We Nudged in gently. Alright, Christy Wyatt, absolute security. Here's my guest on, uh, text Drunk tv.
Truth be told, she nudged him Gently, Gently, gently, we'll say gently. Christy, first of all, thanks for coming on. Text Drunk TV with me today.
Secondly, here's our audience. Tell them the Christy Wyatt story. Well, first of all, thanks for having me.
Um, I'm the president and CEO of absolute. I've been with the company for about seven years, uh, software developer way, way back in the day. I've spent many years in Silicon Valley.
So, uh, Palm, for those who remember Palm Pilots, uh, Motorola, apple, uh, Javas Soft back in the day I was at Citigroup for a period of time. Really insider threat company called DT EI had a company called Good Technology. Um, so done lots of, lots of different things and now we're here with absolute Very cool.
Um, you know, assume our audience doesn't know absolute, how would you just give us the absolute story then? I like to say Absolute is the coolest cybersecurity company nobody's ever heard of. We have a very tiny piece of technology that's embedded in the bios and has been for the last 15 years of almost every PC on the planet really.
And so what that really gives you is kind of an unbreakable connection to that device once it's activated. And so the way we use that is, is a whole host of different ways, but always with a focus on creating endpoint resilience. That's really a category we've sort of created and have been evangelizing for about seven years now.
So we can use this to track and manage devices from the firmware. We can use this to, uh, monitor the health of your overall security posture, heal applications if they stop working. So make sure that your security apps are always working.
Um, we do something called rehydration, which means if, if the OS or the devices become overcome or non-responsive BSOD or ransomware, uh, again, we wake up before the operating system so we can remediate things that may be happening in the device and kind of put you back together all remotely, all without user intervention. And then We did this so many, We have a big zero trust product as well in our ss e product called Secure Access. So we'll do a lot of different things.
And it's all in the bio. It's not on the, is it in the silicon? Silicon?
So it's usually in the un flushable part of the firmware. Um, we do have products across operating systems on endpoints, but we're in the un flushable part of the firmware, mostly on Microsoft products. Our Mac OS and Chromebook products operate slightly differently 'cause their architecture's a little bit different.
Got it. Yeah. You know, it's funny, I was walking around, people you meet at Black Hat around know my friend Alan Friedman.
I don't know if you know Alan. He's from a, he just left csaw. Okay.
But Alan is the father of SBOs software, biller materials. His new thing is called hbos. Yeah.
Hardware bill Materials. I would imagine this is something absolute security would be perfect for. So, so we've been doing this for a long time because we are embedded in the firmware and we have amazing partners like, you know, Dell, Lenovo, hp, Microsoft.
I mean, there's 28 different, uh, hardware providers that we've been working very deeply with over, over several decades. Um, some of our customers actually activate their, the, this, uh, capability in the bios at manufacturing, which means they can actually track the device from the time it takes its first breath, virtual breath first, hello, uh, yeah. Uh, all the way to the time it reaches your hands.
And it also gives you the ability to see a lot of telemetry about what's going on in the device from within the bios that a lot of other platforms wouldn't be able to see. It sounds it's an amazing tool, an amazing tool. Now I'm gonna imagine you sell directly to PC and Mac and you know, Chromebook manufacturers?
No, no, no. This is a, this is a commonly held, uh, so, so our great hardware ecosystem, our great resellers of our products, uh, but we sell direct to enterprise as well. In fact, we have over, you know, 18,000 customers, everything from small business all the way up through global enterprise and federal customers.
So there's a lot of different ways you can buy from your MSP, from any practically any reseller, from any PC manufacturer. Um, and you can activate it on any device you have. So, so you don't have to activate it at the time you purchase the product.
You can, you can activate us across all of your existing asset, no matter how old. 'cause we've been doing this a long time, But it's built into every bio, not every Yes. But it's built into all of these bios.
Yeah. And it's, should we, could we use the word dormant until it's turned? Right?
Right, right. So we don't, we don't see these devices until somebody has, uh, installed, uh, an absolute activated product and it will activate that capability in the firmware. And then from that point, you know, that device is very aware, self-aware, and, and very aware that it is kind of connected to your enterprise.
So you can, what we, when we talk about self-healing, right, we really talk about rooted in the hardware self-healing. So we're not just trying to save ourselves like a lot of anything that's running at the, uh, OS and application level is, is really kind of preserve themself. They really can't heal themself.
If you're dead, you're dead, right? I think the difference between us is, is we're in the hardware. So, so to us, self-healing means I can rip out the hard drive, put in a new hard drive, and the very first thing that device will do is it will wake up and say, wait a minute, something's missing, and we'll get stood back up.
We extend that concept of self-healing to our entire ecosystem of partners. So whether it's CrowdStrike or Tanium or literally any, uh, security or many enterprise applications, we'll make sure that they're always there and always running. We actually, uh, have a research report we've been putting out for about six, seven years now, called our resilience index.
And in that we actually show across millions of devices the actual resilience score for most applications. While organizations may think, Hey, I've installed encryption, I've in installed my XDR across a hundred percent of my install base, it's probably only active and running on maybe 70, maybe 80% if they're doing a good job. Um, things happen all the time, right?
And it's, it's not just about patching and and vulnerability management. It's, it could be the user tampering, it could be just a a, an upgrade got installed. There's a whole host of reasons why endpoints go dark, Uh, blue Or blue.
And you, you really don't have time to send an alert to a human being and have them come. This is really why we believe that the, the, the last point of resilience has to be on the device. The device has to be intelligent and self-aware.
And, you know, we, we've seen such a, uh, an emphasis on resilience lately, right? We, we can't prevent everything true, no matter how hard we check. Resilience is the key.
And it's funny, this is not necessarily new. It's been there. Yeah.
But it was, it's kinda like Dorothy clicky her heels. It was there the whole time, you know, It was there the whole time. Well, to be fair, I think the company has been doing this for a long time, but the use cases, uh, historically have really been around visibility and control.
So it's ironic that in this age where we're talking about some pretty sophisticated threats, one of the biggest things that people really struggle with is, where's my stuff? Right? Oh, there's a, a big os refresh coming in front of a lot of us.
People don't know where their assets are. They don't know what state they're in. They don't know how to get to them.
I think that, um, that's long time been our focus is making sure you always have that hard connection. You know, where it is. You can remotely manage it and remediate it.
It was really about seven years ago, and it was because I had come from another endpoint agent technology company, and too often something bad would happen and we'd say, oh, let's go check the logs. And, and surprise surprise, that device stopped calling in, uh, a couple of weeks ago and nobody really noticed. Yes, it threw an alert.
Yes, somebody tried to fix it, but people are busy, right? We, we don't have enough people to go fix all of these things. And so the light bulb just sort of went off that, that you have this capability to, to heal things from within.
Now this was pre COVID, pre-work from home, pre VSOD event, pre ai. But, uh, but I think that it's even more relevant today if we think about the speed at which breaches and attacks are going to happen. Our, our last line of defense is at the edge.
It's where the fingers touch the keyboard. I, I agree with you a hundred per se. You mentioned ai, you mentioned, so, so in my mind, post COVID things changed.
The, the world changed. AI has been harbinger of a huge change. Yeah.
Um, how is that playing into the absolute vision? There's, there's a bunch of different ways aside from, you know, we'll sort of start with, there was this myth. We all sort of convinced ourselves for like a decade that any data that was of any value to us all lived in the cloud.
And that the endpoint devices were just sort of non-intelligent transactional things. Like To the dumb terminal Disposable, right? If you talk to someone and said, I could restore your endpoint device, they'd go, eh, who cares?
All my data's in the cloud. I think that for first of all, that was never true, right? People were creating all sorts of unique data and insights on the device itself.
Second of all, you know, in the age of AI where you have a lot of new content being created and context being created, your digital twin, your digital footprint, fingerprint, and the point of compromise is probably on that endpoint. You can't afford for the intelligence to be sitting in the cloud. You can't wait for your next instruction.
You know, the attack is gonna happen in five, seven seconds or less. You, you need to find a way. And, and I think there's a lot of really great innovation going on across the cybersecurity ecosystem about how to move more of that intelligence into agentic tools, down to the endpoint to the edge.
We're the thing that makes it stick. Not aside from the way that we use our own data and, and, and are applying AI within our own products. I think the more AI enabled tools you deploy at the end point, the more critical it is that you have that undeletable connection.
Here's the thing, we're gonna get some of it wrong. People are gonna trial, and they're experiment. They're gonna push out new things, things will go go wrong and they'll go wrong quickly.
And so if you don't have that, that digital heartbeat, that connection to that device, I call this participating in your own rescue. Like when you call me and you say, Hey, you're in the bios and everything just went blue, or everything just went black, or we're just, we have a ransomware. You know, the, my question is gonna be, did you, did you activate us?
Like did, did you, did you turn on the lifeline? If the beacon's on right, there's probably something we can do. That's a, that's a great way of saying it.
So, you know, it, it's funny. So everyone out here watching this actually already has absolute installed, probably it may not be activated, trip Beacon may not be on. So that begs the question, what can they, other than going through channel partners that you mentioned, yeah.
Is there anything they could do to turn the beacon on? So first of all, uh, there's a whole host of different ways you can come see us here at blackhead. com, right?
There's, there's, uh, opportunities there. Literally any PC manufacturer, most channel partners, there's, there's no shortage of both applications that have the ability to, because there's a variety of different ways to turn it on to activate it. Um, so there's a whole host, there's no lack of voice.
com and you'll, you'll all things will be revealed. Excellent. Last question.
What do you think of Black Hat so far? Uh, I, I mean, aside from, it's chaotic as it always, it always is. It's, it's, it's, it's chaotic, but I think, um, things are happening so quickly, right?
And I think the top of mind for everybody here is just the rate of change, right? I think it's, we're all very excited about ai. I think somebody in the, in the CISO summit yesterday said the words fascinating and terrifying in the same sentence.
Which, which I thought was profoundly true. I think that as things unfold, um, there's tremendous opportunity. I also think there's tremendous risk and we're all sort of painfully aware of it.
I have huge respect for all of the constituents that are participating here. 'cause I think everybody's working their hardest to figure out how we all kind of band together and respond to, you know, uh, digital workers and, you know, tainted data in your, it's it's Short Territory. It's, it's craziness, you know?
Right. You've been around, I've been around. I've seen the advent of cloud.
I, I, I remember when cell phones became a thing. I remember when the internet became a thing and we all had these, sometimes they were probably rose colored glasses, visions of how great everything will be, but getting my experience anyway, getting from here to there Yeah. Is always bumps in that road that we don't anticipate or we didn't see coming.
And there will be here too, as you say. I, I think, I think people are cautiously optimistic. How does that sound?
I more terrifying. And, You know, I don't know. I, I I think it's inevitable.
And so, uh, you know, I like to say that there's not a lot of benefit in having what I call the Muppet debate. I dunno if you remember the Muppets, the two guys on the balcony, like, it's gonna take all the jobs, it's gonna be fine. I, I think the answer is, it's, it's, it's here and it's happening.
It's happening with your employees. It's happening with your customers. And so we're, you know, there's a tremendous opportunity to kind of participate and sit down and figure out what is the best way to apply this, to accelerate our businesses, um, but also to help mitigate the risk.
And so there's a lot to talk about there. I agree with you. A lesson I've learned in 30 years of security.
The market doesn't wait for security. Security has to catch the market. Right.
And I think that's what we're seeing here as well. Absolutely. Anyway, best of luck.
You, it is Thank you. com. com.
Check it out. We're here at Black Hat. We'll have more.
Stay tuned.