Israel Mazin, Memcyco | Black Hat USA 2023
Website spoofing and brand impersonation are becoming an issue for organizations – and for their customers. We’ll discuss these attacks and their damage, which is both financial and reputational. In particular, and due to new regulation, companies should put more emphasis on protecting their customers and not only their employees – a cybersecurity area which hasn’t gotten a lot of attention until now. An important element of focus is a Window of Exposure, between when a fake site is up and until it is taken down, during which companies and their customers are exposed – and which existing solutions do not protect.
Transcript
This is Textron tv. Hi, this is Shera Rubinoff Broadcasting live here at Black Hat with Techron. I'm here with Israel Meine from CECO Israel.
It's a pleasure to be with you here today, and I'm so happy I was able to catch you between meetings at Black Hat and able to get some of your time. It's just, you're running an incredible company. So please introduce yourself to our audience, tell them who you are, and a little bit about your background.
Thank you for having me here, Sheila. It's a pleasure to be here with you. Uh, yes.
I have about 30 years experience in building startups, uh, to a very successful, uh, software companies, especially in, uh, the cyber. Uh, and, um, some of my companies were, were public in the nasdaq. We had also significant exits, uh, also my management team, uh, working with me almost in the co-founders the last 25, 30 years.
So we are, have a, a lot of experience in building these type of companies and, uh, we are using it now when we founded, uh, Mexico about two years ago. Uh, with all the experience that we have and also new, uh, entrepreneurs that working with us, that coming from the Israeli intelligence in, uh, development. So we develop and build very strong team to run this company.
Well, thank you. You certainly have an impressive background and I love the fact that you took your management company with you and everybody came together and continued to move along. And the successes of different companies, you know, as strong team always yields a great results.
So, you know, kudos to you and your management team of continued success. So, Israel, please tell us a little bit about mems cco, how it, how the brainchild about it came about, and, uh, where MEMS CCO stands in the ecosystem of cybersecurity world. Great.
Yeah, thank you. So actually we founded it two years ago. We, uh, also already raised the seed round of 10 million, a few $10 million a few months ago from two top VCs, capital ventures and venture guides.
And, uh, what we are actually doing in Mexico, we provide full protection from, uh, um, website, uh, spoofing and brand ranking, uh, actually to our, to the customer and also to the customer of our customers. And this is where we are unique from other, uh, uh, companies in this space. Uh, from the moment that the, uh, website, the fake website, uh, is alive until it, uh, it is, is taken down, uh, these windows or window of exposure, it's the most risky.
Uh, because this, all the attacks in happening there and what we develop, it's a completely unique solution that protecting this window of exposure. Most of the companies today in this space, they are more doing more threat intelligence and uh, uh, take down, we are doing it also, but it's just 10% of the, our solution, what the real, uh, differentiation that we have that actually we protect in this window of exposure. When the site these fake sites are alive, we can, we know exactly who are the attackers, we know who are the user, the gold scams and everything in real time.
So this is, uh, the uniqueness of our solution. Also, it's, uh, very easy to install and implement. It's a SaaS based solution.
So the customer that installing us, they can see the value almost immediately in very short time. Like we started to sell the product the beginning of this year. We have already customers from many sectors like banking, uh, like, uh, retails, logistic educations, uh, charities and more.
So it's go all over, you know, all over everybody. Almost every company is suffering from these scams. Today.
Actually, we are, we changing the paradigm of, uh, fighting against this type of, uh, of scams. Very interesting. You know, the talks in the cybersecurity world, you have to be proactive as well as reactive.
And both of them are equally as important. And one of the elements that I find tremendously powerful that ceco iss doing obviously a lot of things, is that they are looking at the proactive. You're looking at the proactive piece as a very important tool.
And when somebody has to be proactive and their cybersecurity, uh, stance, they have to have different ways that people could know. And as you're saying, the sites, we need to know that we're on the correct site. And one of the things that I see that you do is you take the onus off the user.
When the user comes. They know that they are on a protected site without doing extra steps. And one of the human factors pieces when dealing with people and being proactive, when you give extra steps to users or you make them do something in order to be protected, everybody's moving at warp speed.
People are doing multiple things at once. And when people are doing that to do the extra steps, no one's interested in doing either, they'll go around it, they'll break it, they're circumvent it, and then, then to the day they may or may not do those extra steps to be protected. So one of the pieces that you're doing that I think is tremendous is that you're not having the user think about if they are protected or do anything.
They will know and they for sure will know based on how your solution works without doing extra steps. So a few of the things that I believe that you're doing in order to strengthen, you know, the space around cybersecurity, you're telling organizations, look, you know, your, your, your insurance can go down and your cyber insurance because you don't have that human factors piece of a human being, the weakest link in the chain. 'cause you're taking that off.
You're saying, okay, we know we're protected, we don't have to do that. The training factor, yes, everybody needs to be trained and you have to do it in a way that's good for the organization and good for the people within, and the consumers on the other side they need to know. But that training piece of letting them know and how do they do things they know.
So can you talk to that aspect a little bit and explain to our audience a little bit more around that key piece of knowing that you're protected without the extra steps and why that's so important? Yes, of course. First, you know, today there are a lot of budget cuts, as you know, in all the organizations, less in cyber, but still the CISOs today, they, uh, need to decide where to, uh, put the budget Sure.
And we can help them to reduce, uh, uh, the, the budget cost and also insurance cost, as you mentioned before, actually our solution give a few, uh, feature that are very important, as you mentioned before. One, we are detecting and protecting in real time the organiz the organization and the users. Yes.
By, uh, giving alerting red alerts when they are entering, uh, to a, to a fake sites, the users. So immediately we stop them from entering to these sites and also report, uh, uh, to the organization that there was a, a scam. Yes.
And which user tried to go scam by the hackers. But we also provide, as you mentioned before, that the user will know that they are on the, the genuine site. We provide a very unique watermark that, uh, actually to every user it's different.
One, it's animation and a code or a, or a photo that he knows. And every time that the user enter to this site, he will see this watermark. And he knows that it's, it's for 200% on the general, the right, correct side if he doesn't see this water mark.
So it's in, in a fake side. So this give to the user, to the user the confidence that they're accessing to the, to the, to the genuine side. The problem today that because there's so many fake sites, and it's so easy to do it today with this, you know, AI and all of this, uh, kits, uh, uh, as a servicer to do spoofing as a service.
So, uh, users are afraid to access to these websites. Even they get the mail or message or advertisement, they're not accessing. So it's reduced revenue to these, uh, potential customers.
And it's affect all these reputation. And also when the, we are the customers using our solutions. So the CISOs has less, it's, they can reduce the budget, as you mentioned before training, but they need to do less training and awareness because we are protecting, we are there.
So they don't, they, they, the user doesn't need to sink because, and what to do because we protecting them. And this is the most important in our solution, that we protect the user and we protect the organization in this windows of exposure that this fake site are, are alive. And, uh, attacking them also, in addition to this, what we are doing, you know, we give a lot of, uh, story information about their attacks.
So we reduce also the soc people that investing time and, um, all the to find where is the scams, what, how it's happened. A lot of investigation hours or days. They don't need it anymore.
Yeah. Because we give them this information in real time to the soc to the, we we integrated to the scene like, or Splunk or others. So they don't need now even to do any investigation.
We give them all of this information. I can tell you that some of the customers that we are working, they all we know, we felt that we were blind before. And now we feel that we know, we didn't know even that all of this happening.
It took us hours or days to know it. So we can now shift the, the system and the SOC can shift their budget to other activities when they're using our product. And it's critical because today they need, they have limited budgets, so they need to find more budget to other solutions.
Correct. You touched on a very important thing, and that's one of the things that CISOs are scrambling. It's their budgets and they're going to the boards explaining they need more budgets, but there's only a certain amount of money to go around in the companies in order to yield protection.
And when the CISOs are trying to figure out budgets, when they're looking at solutions, if there's extra involved, whether there be training, whether it be people and personnel, they probably put that to the side. You know, we look at solutions like a good to have a need to have and a must have good to have is everything need to have is, you know, we'll get it as soon as I've budget for it. And a must have is this is critical.
This is something that's needed now. 'cause one either reputation's involved, money's involved, different things are involved that that could curtail either business as as usual or slow down production and have companies scrambling just to get up to speed. So you really hit on an important point that I know that CISOs are dealing with on a daily basis.
So thank you for really explaining that. And if you could also describe to our audience a little bit about the proactive approach and reactive, you're talking about realtime warnings and the realtime warnings are critical because something that you see minute one minute 30 can be completely different story. Can you talk about that real time versus a little bit of lag of time?
Yes. Yeah. So all the solution that today in the market before we came without solution, what they did is threat intelligence and take down Yeah.
And, uh, this is reactive as you said, because first, not always, you can do the take down. Not always it's possible. Secondly, not, you always find all these, uh, sites, the fake sites.
What we are doing is completely different approach that actually when, uh, our product is, uh, implemented and installed in these organizations. So when, uh, the this fake site, this hacker send your fake sites and you try to access to these fake sites, immediately we alert on it to the user and to the organization. So they don't need to search for it.
They don't need to find it because we are there when it's happen. Yeah. You know, it's like you have a house and you have, you have like alarm and lock and the, the locker when you enter the, and if there are no lock you can enter.
Yes. So it's what if you discover that there is stiff round, but you stop it from entering to your house? This is exactly what we are doing.
We stop them when they'll try to attack your, the users. Sometimes hundreds of users, sometimes hundreds of thousands of users or millions. We, we are there to catch it in real time.
And this is the big difference from reactive and proactive. We are proactive because this is what really protect the users. Mm-hmm.
And also the organization and also in, in addition to this, we give them all the information. So where they know who attack them, when they attack them and more, most important, who are the user that got scam? Yes.
Because then they can do it, they can do some action for it. You know, That's excellent. So once you give them that information, they can take it further, whether that specific user might need a little more training specifically, so you don't have to go across the whole organization.
Maybe that one user might be a negligent insider threat, which doesn't mean they're trying to take down the organization or do something wrong, but they just don't know, they don't realize they fall prey to attacks. So really honing in on it. Exactly.
Yeah. It saves the budget and it saves the organization and really educates the organization as a whole so they can be better, stronger, faster, and do what they need to do, whether being operations and security and hand in hand. So if you could tell our audience, when you look out at the audience and you wanna really educate them and say, you know, this is a very important product for you.
We talked about being proactive. We talk about being reactive. We talk about real time, we talk about taking away the onus on the user.
We are lowering the CISOs budgets. So literally sounds like this is the solution to have. So if other organizations are using other solutions, how does it stand out?
When you talk about, you know, taking bonus off the user in all the different areas, what could be your five points? If you could just make it easy, informative information that people could say, okay, check mark, check mark, check mark, check mark all the way down. And they say, this is just a surefire win.
What can you say to that in a very concise way for our audience to understand? Yeah. Okay.
So first, uh, the most important that we protect this window of exposure when the site alive until if at all, it taken it taken, it is taken down. Yes. Uh, we are, we don't need to search.
We are, we know this is the big difference from us to other we know because we are there in real time. Yes. So most important, as you said, the a few points that are important, one that we give you, uh, we protect, we give you all the visibility in real time that as, as the customer said, we were blind before, now we are not blind anymore.
You start see what's happening in your system. You know, who are the user that works camp, you know, who are the hackers from where it's coming, what is the fake website so you can start acting. We also give protection because we know the authorized user of the authorized devices of every user.
So if hacker succeed to take some credential, he cannot enter because we stop it because we know, we know that he's not authorized. We have very unique so, uh, capabilities of device d n a device fingerprinting. So these are the another point that we are protecting.
Second, the third one that we have also this, uh, unique watermark because we, when we discussed with customers, they said, you know, yeah, we are protecting them now with your solution. But how the customer will know that we care for them because there are a lot of regulation today that they need to show that they are protecting the customer. They're liable, you know, in the uk the regulation now that they need to protect the customers in other, other European countries, it'll come later to the US and Australia and others.
Yeah. So it become more and more liable to their customers and compensate them. And also then it's expose the systems and other to more personal liabilities.
Our product protect them from this because they doubt not it to, to doubt or guess they know. And this is the, I think the big difference from us to searching and take down. We are doing today, you know, detect, protect, and take down, but the protection is the 90% of what really important in what we are doing and what important not us.
So I, you know, what customer told us, you know, when I have your solution, I'm going to sleep well at night. I think this is the most important, you know, sentence. They can go to sleep well at night.
The seesaws, the floor, the sock, because we give them the right protection. We don't guess, we don't search, we know. Excellent.
And a lot of organizations, they look at technologies and solutions about how does it, what does it take to implement this solution? How long does it take? What, uh, do we need some training to implement?
What does it cost us to implement the solution? How many people need to be involved in it? Can you talk a little bit about implementing the solution and the ease of use?
It is, Yes. This is very important. When we develop it, we said we must have something that it's very easy to use agentless, that the end user, uh, don't need to install anything, register anywhere.
So it's very easy to install its agentless solution. It's take 10 minutes, even large organization to install it and then to implement it. They almost see immediately because we do every single automatically it's SaaS, uh, model.
So after they install it, it's like a fuel line of codes and that's it to install in the organization. That's it. A few minutes installation.
And after it we start collect the data and start showing the data and protecting. So they see the value immediately. They don't need any training almost because everything is automatically everything.
You know, some of, uh, the customer that we installed will show, they said, I don't believe that we can see this value immediately so fast. So this was something very critical for us when we developed the product, because this is part of our experience that, you know, all of this long implementation in the past, you know, on-prem, that's it, it's not relevant anymore. Uh, customers today, they have so many solution.
They want to have something that they install and that's it. And this is where what, what we focused to have to solve a real pain, that it'll be proactive and the installation implementation will be very easy, immediately can see William. So it's very easy.
You don't need almost any training. We show them the demo we showed, I don't think that we have any unsuccessful p o c after we do A P O C, they see immediately the value and moving to procurement. So it's very easy installation and implementation.
Almost no training. So one other question around this, this area that people worry about, man in the middle attacks to spoof. Is there any way a man in the middle attack could occur in order for them to spoof a real site, even to maybe grab whatever they think that the user's supposed to see?
How do you protect the user from man in the middle attacks? It's exactly what we're protecting. Because many in the middle, it's exactly because they can then bypass the multifactor authentication and other authentications.
Yes. When they install our product, we catch it immediately. When they access, they cannot even go to the next step.
Right? Because when they access to the, to the site, uh, that installed us to the fake site, we alerted immediately and we stop it. So they cannot men then men in the middle, it's exactly strong solution for men in the middle, maybe the only solution because it'll not help you in the men in the middle when you search and take down in this window of exposure.
This window of exposure can be days sometimes. And then they do this man in the middle, and then they catch a lot of the credential of the users. Uh, and even worse, the employees, you know, and then they can do one somewhere and all over.
So this is exactly the good solution for the man in the middle that you are mentioning. Excellent. And any other cybersecurity points you wanna leave our audience with that you might wanna just give some extra pointers to them and, uh, just speak from your, your great vast experience around the cybersecurity world.
Yeah. I think that today there are, you know, many, uh, the very critical to have like, uh, all these, uh, advanced solution like us and others, uh, in even in other, uh, uh, you know, cybersecurity, uh, protections and areas. Uh, I think that, uh, ransomware start all from phishing, uh, you know, and taking credential or from vulnerabilities.
You, we see ransomware all over. So they need type of solution like us to protect ransomware, but also the vulnerability to protect because this is the, the main way to do ransomware. And we hear it almost everywhere, you know, in, in hospitals in the other organization that they actually succeed to penetrate and encrypt the data.
And I think that I very important today when you have, you know, and also the AI today or using ai, it's much easier to do all of these scams, fake sites, ware all over. It's much easier. So I think that customer need to increase the cyber.
I think today it's when it's more risky. So I think organization need to increase the cyber security. Even they cut budget.
They seem need to give more budget to cyber security because it's more risky today. It's easier to, to do to, to, to attack even hacker that are not professionals today with, uh, this AI and, uh, all these kids can do. Uh, you know, that's true.
Uh, can I, yeah. So I think that if we look on all these cybers, I think there are a lot of threats today from sometimes from more professional even, uh, sometimes, uh, states or, you know, countries. But 70% coming also from that are not professionals.
Sure. And you need to protect against them also. So I believe that your organization need to increase their cybersecurity budget and not reduce it, even their reduced budget, but also focus on what really can protect them and also their users because this, the user is actually what give them the to to live and the, the revenue and uh, to protect their brands.
Sure. So Israel, I know you have some exciting news that you wanna share with our audience, some announcement, and I'd love to give you the stage. Can you please share with us the news that's coming at manix out?
Yeah. So as, uh, I mentioned when we start in sco, we want to develop suite of products on the digital trust that protect the organization, the, the employees, and also their customers. Uh, so we are going to, this is the first time that I'm talking here and announced this.
We have a new product that we are going to protect the STEM way that we are protecting the websites to protect the login page of single sign on like my, like Microsoft or Okta or others. Today. It's, uh, it's a really entering to and doing through this login page, many scams that doing this ransomware as I mentioned before.
So we are going to release a new product in the next few weeks that will protect the log page of these, uh, uh, SSOs, uh, and uh, against this type of, uh, account takeover. We have all of this technology, including the watermark and the protection and detection in real time to, to these login pages. Uh, we talk with tens of customers that who are looking to looking forward to have this because it's happened to them.
What we saw in the survey that we did with them, that between 15 to 30% when they are doing the simulation, fall to these scams and give the recommendation in this, uh, s o login page. So we are coming with really unique solution to protect this login page of these SSO form that it'll help against ransomware and data leak and everything. Well, congratulations on that.
It sounds like a very much needed technology and I'm sure it'll do really, really well. So I encourage our audience to take a look at what Meego is doing. Israel, a pleasure to speak with you as always, and I'm so glad we had a chance to speak here at Black Hat and I look forward to speaking to you again soon.
Thank you, Sheila. It's really a pleasure to be with you here as always too. Thank you so much.
Thank you.





