AI, Ransomware, and Cyber Resilience: Insights from Absolute Security’s John Herrema
John Herrema from Absolute Security explores how AI is advancing the Absolute Resilience platform, the growing threat of ransomware, and the evolving role of cybersecurity professionals. The discussion emphasizes the need for AI guardrails and strategies to strengthen organizational resilience.
Transcript
Welcome to another edition of Textron tv. I'm John Swartz Textron Group, senior content writer in Silicon Valley. And with me today is John Herma, chief Product Officer at Absolute Security, where he's responsible for leading the company's product, organization and driving the strategic direction of the evolving portfolio to extend cyber resilience capabilities to global enterprises.
John has spent more than two decades focused on enterprise mobility and security. John, welcome to the, uh, segment today. John, thank you for having me.
I really appreciate it. Sure. Uh, sure, my pleasure.
Hey, I understand you're here to discuss how absolute security, which is a, a valid leader in enterprise resilience, has announced some new advancements in AI that's been added to the absolute resilience platform. Can you tell me a little bit about what those are and, um, maybe where you're gonna be announcing or elucidating more about these announcements? Well, hopefully we'll skip the hallucination part, but yeah, we're really excited.
So in our, uh, secure endpoint at 10 Edition, um, we've introduced kind of our first foray into, um, uh, artificial intelligence in terms of having, uh, an AI assistant embedded into the product, um, to help our administrators more easily, um, generate insights, reporting, understand their risk and, and, and compliance posture, and just do that in a much more rapid, natural, simple way. Um, that doesn't involve, you know, having to do complex queries, complex report generation. You can just have an interaction with that assistant, um, and it will reveal the insights to you, um, based on the questions you're asking it, and then allow you to turn those into customized dashboards, trending and reporting so that there's something that you're looking to track over time.
Um, it will automatically do that for you. Is, is, are you gonna be talking more about this at Black Hat and under what type of context? Yeah, for sure.
So we're, uh, we're gonna be at Black Hat and, uh, I'd be remiss if I didn't say Booth 46 0 5, so definitely come see us there. And so we're gonna be demonstrating, um, that, that product as well as our, our full, uh, full portfolio and some other, uh, interesting capabilities that we've, uh, launched recently. For example, our rehydrate capability, um, our AI threat insights, um, capability, uh, as part of our secure access portfolio.
So we're, uh, really excited to be showing off everything we do, uh, as absolute, You know, one thing that I wanted to ask you about and kind of just kind of stepping back in the cybersecurity realm, for example, are you seeing, uh, especially among enterprise adoption, is there more of a, of a cognizant, uh, acknowledgements of having guardrails or the necessity of guardrails, especially now recently as AI starts to take off and drives demand? No, absolutely. So I think it's, it's this classic tension where folks absolutely wanna embrace the technology, use it for all the, the wonderful, uh, things it can do for us, um, but are taking, you know, measured approaches and making sure that they have policy in place, um, in terms of what can be used, what types of tools can be used in what modes.
So that's really important. Uh, I would say is, is making sure that you start with that, uh, policy side of things so it's clear, uh, you know, that it can be used, but then also how it should be used, uh, but then also being able to couple that with tools, um, that make sure that those policies are being enforced. So within our own portfolio and others are doing similar things, um, we have the ability, for example, to see, uh, whether there are local models running on the endpoint and which types of local models and, you know, the ability to apply controls if you didn't want to, particular models running locally.
And then with our secure access product, we can actually also monitor the flow of traffic from that, uh, endpoint and that user interaction out into any cloud-based models as well. So you can kind of have that full visibility into terms of what is going on either on the endpoint itself or in conjunction with a cloud-based, uh, large language model. And make sure that you have the visibility to ensure that, uh, your policies are actually being complied with, um, and then as needed to remediate, um, and control that where something might be being used in a way that is not consistent with policy.
You know, it's interesting, there's this been this classic narrative, and I know it's been discussed at blackhead or RSA, any number of conferences where security was always kind of thought of as like this evolutionary technology that slowly developed. But given what's going on with AI and its revolutionary nature, it seems to me increasingly that cybersecurity is becoming more of a, uh, a priority. It's not the last thing considered, or one of, one of the, among the last things considered, it's, it's raised in terms of, uh, its importance, especially as AI is, is kind of seeping its way through all these organizations.
Is that kind of an you see a change in that narrative happening at all? Well, as you say, it's been evolution. It's really interesting.
We just came back from our company kickoff in our own as, uh, uh, CIO Harold, uh, Revis actually gave a really great talk about, you know, how has the role evolved over the years. And I think what's interesting there is that it's, it definitely evolved, but it's someplace that has still evolving. So I think depending on the type of company where you might be in the world, um, what we think of this as a role today, uh, for example, north America, if you're working at a financial services institution, it might look a little bit different than it does in some other industries, some other, um, locale, but certainly, um, it's moving and, and a lot of places is now, you know, board level visibility.
Um, and there's, there's accountability all the way up to the board, um, for that risk management and cybersecurity posture management, um, aspect of that role. So it has certainly evolved, um, from really being almost kind of an IT EO function many, many years ago, or an adjunct to IT, to really its own board level, um, visibility in many organizations and certainly our own. Yeah, they knew that.
There's a, uh, some couple of research reports that came out, including one from the Futurum group this week that indicate that, uh, CIOs, almost all of them, all of them actually, there were 203 they talked to, and all of them talked about this kind of transitionary period in terms of IT experience in the use of AI absolutely necessary, uh, a critical part of what they're doing, uh, especially, uh, given the number of data breaches and, and ransomware incidences that we keep hearing about. So it's definitely become in, again, even adding in the, uh, growth of a AI agents, it's become an absolute necessity. Um, hey, that's gonna, that brings me to my next question.
What threats are causing the biggest problems for organizations today in cybersecurity? Well, I think this is the, the, the place in the conversation where I get to use the, it's probably the two words that are used most often these days, so certainly ransomware, um, the increasing sophistication of those, those attacks, the notion of ransomware as a service where these ransomware organizations are operating as businesses and, and offering best in class services to their, their customer groups, so to speak. It's a bit frightening when you think about how well organized that's, uh, that's becoming.
Um, and then coupling that with ai, uh, both on the, you know, for good and for bad side of things, because, you know, for example, with ai, uh, on the bad side of things, we have the opportunity to craft much more sophisticated phishing attacks and so on, um, uh, have them adapt in novel ways to, in, in, in, in tune and improve their behavior. But on the flip side, when we're using it for, for good, um, I think one of the big stressors on A-A-C-I-O or a CI IO organization is just staffing and having enough people to keep up with, um, all of the patching, configuration management, all the things that need to be happen, make sure you have what we call shields up in the first place. Um, and so being able to leverage AI and agentic AI to not just identify where you have those weak spots, but then to actually automatically be able to apply, you know, configuration, patching other forms of automation.
So at least that part of the job, um, is simplified, operating more at scale, um, is, is a wonderful opportunity. I think the other great opportunity for good for AI is that, you know, when you can use AI to model, you know, how data is flowing throughout the organization and being able to, uh, identify cases where, for example, a legitimate process may have been hijacked and is now starting to operate in unusual ways and, and move data, for example, low and slow exfiltration things that are very hard to catch, you know, at the macro level, uh, AI can certainly be a tool, um, to kind of root out those sort of instances of anomalous behavior and again, at that very, very nuanced level, um, because increasingly attackers are trying to, you know, impersonate and sit on top of otherwise legitimate processes and people and identities, um, so they can execute that live off the land. And that low and slow data exfiltration, um, type of model, Just, just as the proliferation of AI agents from so many different vendors, does that actually help or hinder, um, security efforts within companies.
I wonder what the impact you think will be, I know it's early in the game, but I'm wondering where you think that's going. Yeah, well, I think it's, look, it's always when something new comes around, um, there's gonna be many, many, many vendors and options to choose from. But I think when we see any of these sort of, you know, hype curves and things, things, you know, you go through that you inflated expectations and maybe that disillusionment, then you start to come out as things sort of start to normalize.
So I think we will see that, um, that similar type of pattern. I think what we're gonna see in this case, however, is a very compressed, uh, pattern because the nature of them tools themselves will probably allow that, that cycle to, to progress more quickly. So, um, there's always a bit of, uh, norming and storming involved, but, uh, I think we'll, we'll, we'll get through that.
So, So I wanna ask you about, uh, absolute security and how, how specifically from your, your product viewpoint, how it's helping organizations in the modern threat environments. Yeah, so I I, yeah, I'll preface that by saying one of the big shifts that we're seeing overall is this, this notion of, you know, certainly I have to continue to focus on protection and detection, but we're seeing a general shift where a lot of folks are recognizing that, look, you, you have to do your absolute best in, in those areas. And I'll, I'll talk a little bit about that, but increasingly a focus towards, okay, but what if I do have the bad day?
And maybe not even what if, but when I have the bad day, uh, how am I actually gonna be able to recover, recover rapidly and to full production and productivity for, you know, all of my users? So I think there is kind of an understanding there that if you're not, you know, assuming that you're gonna have the bad day and preparing for that, that when that day comes, it's gonna be worse than it, than it otherwise would be. And so at absolute, um, we kinda look at that, that resilience journey, uh, across sort of four, four steps and, and there's different capabilities we have in our portfolio to address that.
The first one I call just get the hygiene right. And so, uh, one of the really interesting things, and a bit alarming is that, uh, you know, depending on whose statistics you look at, maybe 40% or more, um, of successful ransomware attacks were traceable back to, uh, a vulnerability that was actually already known and could have been, could have been patched. So one of the things that, um, we, we focus on there, um, with our, our patching and vulnerability remediation capabilities backed up by our, our firmware, uh, persistence is that you, you just have to make sure those processes are running, running in an automated way, running rapidly and running to completion so you can get that basic hygiene right and take care of all the vulnerabilities that you already knew about and, and should have been fixing.
Um, so that's the first step you have to get the hygiene right. Uh, the next part is you have to make sure that the tools you're using for things like endpoint protection, um, and XDR actually deployed, um, fully updated and operational at all times. And we call that kind of shields up, get the hygiene right and make sure that your shields are up and stay up.
And so we have a capability called application resilience, um, that we can use to monitor and make sure that all the different security management controls that you need to be deployed on that endpoint are always deployed, operational, running, and fully updated. And so that kind of protects you against things that you, you, you don't yet know about. The third step in that is that if you, if you have the hygiene right, you have your shields up, now you're ready to start interacting with the world and, and moving data in and outta your organization.
And so, um, at that point, applying zero trust principles and doing that universally, um, a lot of times folks, when they think about Zero trust, they think about it as something that, well, I'm gonna apply that maybe when the user's remote and trying to connect, you know, into the organization. But, uh, we're seeing that organizations that are more mature on that site are, are looking at, at zero trust is something that need, need to be doing every user, every device, um, all the time, regardless of whether you're remote on premises, whether you're accessing internal resources or accessing externally. And one of the key parts of that is that a lot of times folks end up compromising between the policy they wanna apply and doing universal Z 10 A because the impact on user is too great.
So one of the great things are secure access solution, which supports universal Z 10 A also, um, optimizes the experience for user just from a connectivity, uh, perspective. Because if you have bad user experience when you're trying to apply your security policies and controls, you're creating this kind of, you know, tension between the two. So if you can get that part right, um, then you're really doing everything you, you, you possibly can on that sort of preventative side of things.
And then the last step is, uh, number four, you can still have the bad day. So you have to have a set of tools in your kit that are allow you to recover, uh, and bring yourself back to a fully operational and productive state, even if, uh, all of your attempts to prevent, um, you know, your best level attempts, uh, don't succeed. And I think that's the part where again, we're starting to see more focus, um, on that with folks understanding that being ready for that day is as critical as those first parts.
Well, it's, this is, uh, very, very interesting stuff, John. I know that you will be at black half of these announcements and you're also gonna be releasing a cyber resilience risk index for 2025. Um, I appreciate your time.
Thank you for being on, uh, Textron tv. Um, we wish you the, the best of luck and we look forward to the news that's coming out that has come out and, and what you care to share with us at blackout. Thanks, Sean, really appreciate it.
We hope to see folks there and, uh, appreciate the time today.