Amit Sheps on Managing Expanding Attack Surfaces in the Age of AI
CyCognito’s head of product marketing, Amit Sheps, discusses the growing challenges cybersecurity teams face as artificial intelligence accelerates the expansion of enterprise attack surfaces. He explains why visibility, continuous assessment, and proactive risk management are becoming essential in an AI-driven threat landscape.
Transcript
Hey guys, thanks for the throw. We're here with Amit Sheps, who's head of product marketing for Psych Kognito, and we're having a little chat about well attack surface management 'cause things are getting a little bit outta control. Emett, welcome to the show.
Yeah, I think getting out of control is, is the right context for, uh, for attack surface management. Um, and I think before we'll start, regardless of attack surface management, I think what we can see is that security teams are still being the same, on the same size. Whether being become smaller or staying in the same size budget are becoming much tighter and the risk is being bigger.
And I want, I would like to say attack surface is here for the rescue. But, um, I think we can see definitely a lean on from organization towards attack surface management towards attack, external attack surface management, um, as a mean to reduce the noise, to make that vulnerability management something which is more cohesive and something they can work with. And instead of chasing vulnerabilities, actually addressing a risk, it seems like we're dealing with two sets of challenges and one we're kind of aware of in that the number of platforms that we use and the number of things that we need to secure has increased as we've become more distributed with our applications.
And there's more stuff running at the network edge than ever. And at the same time now there's this AI component where we're starting to see agents that are essentially a new type of end user that also needs to be secured. And so the number of, shall we say, uh, people, whether they're AI agents or actual humans that need to be defended is also exponentially increasing.
So from your perspective, it seems like if I'm the cybersecurity person, the game is a little rigged right now and not in my favor. So how do you see this all playing out and, you know, is there some way to think about managing all this? Um, let's start with the first question and then I'll move to, to the ai, the elephant in the womb.
So yes, organization become, became much more complex, uh, whether it's, um, many tools, as you said, to secure many things, many domains, many technologies, um, whether it's the size of the organization, if in the past we had, you know, a small office with a data state data center, somewhere in here now we have organizations spread across the, the globe and security teams first struggle with visibility, with actually trying to get everything together, uh, whether it's see what mines and actually try to get somehow a unified picture of all the tools that I'm using. So I think the first step that we are seeing is integrations, whether integrating your inventory system to your ticketing system, to your EASM, to to the exposure systems to create some kind of holistic view. So in the end of the day, you will be able actually to connect the dots not running after, you know, whether it's vulnerability or, um, patch in your IT or something which happens somewhere you can actually connect, integrate all of your systems.
And now I think you are much in control, which also says, um, sometimes when dealing with, um, incidents or vulnerabilities. So this is for the first, for the complexity. Now let's talk about the elephant.
Um, so AI brings, um, let's say two dimensions to cyber security, as, as I like to play with that. Um, one is ai, what AI is doing for the practitioners. And the second one is how to secure ai.
So both sides of the equations now in terms of securing ai, your tax surface is being now expanded. So you have, I'll say, new toys you need to play with, but you need to secure them. And I think, uh, you and I in this business long enough to hear, uh, Cisco complaints about the cloud and marketing team spends a new application, uh, for their new, uh, um, for the new campaign.
And the security cannot control the velocity of the cloud. And I think we are going to see it here as well. Um, whether you expose an NCP or uh, an agent, as you said, you need the tools to identify it.
Security must keep up with the pace of ai. This is on one hand, so you need the tool. You need to again, have that AI mindset on your attack surface on the underway round, uh, which is the good stuff is the what AI can do for you.
And now, um, I'll call it you have a new assistant, Neil, which can actually help you and take a lot of your work. Um, same has happens for instance in r and d today, or with developers that we see, uh, ai, I don't wanna say replacing, um, developers, but taking some of the, um, tasks of the, so to say, senior, uh, developers and make their life much easier. So you can see, and we can see products today that can investigate, um, incidents.
So there are some kind of a junior analyst that sit near you and do and collect the data and make the, so to say initial, uh, trash, uh, and actually give the the analyst initial, uh, findings of the incident or whatever he's investigating. AI can actually process data at scale. So if, if, let's say two years, I know, I mean it's not that long, but you need it actually to take ev all that data, all that logs all this information and process it.
Now, AI will do it very fast for you. And of course it's being, it's, it's being done in your language. So I think in one way AI made a little complications, the securities and the other way around.
It's also helped them a lot to deal with these complications. And with the rest of the complexity, I think there's a a, a third element to this is, is the bad guys are using AI as well. And so it seems like they are discovering and creating exploits for vulnerabilities faster than ever and then launching them at higher levels of scale.
And if that's the case, then, um, you know, is this whole thing moving to something that is, uh, attack and respond is now in real time and it, it is occurring faster than humans can keep track of it. So is the whole nature of the game changing? I agree.
And I think, um, if you look at the hacking methods, I mean, I I, to be honest, I did a small course. I'm not retaining to be of ethical hacking. So just to understand what is go, what was going over them.
And I think the methods of hacking are now once, once they are being replaced by an agent or, or, um, ai as you said, it actually made every, makes everything more challenging. However, that means that you need to maintain your attack surface much tighter. So you need to identify risks much sooner and then you will be able to prevent these attacks because again, in order to initiate ai, uh, and attack AI is the orchestration tools is the means to the end.
At the end of the day, if you will maintain your attack surface, identify, um, identify where you are exposed, where are the exploitable issues, um, then you can prevent, I don't wanna say 100% of these attacks, but you can prevent many of the attacks by being aware to that attack your view and then prevent it from happening. So what's your best advice then the security teams as we kinda look at all this stuff? 'cause it could be, frankly, it's a little overwhelming.
And how do they wrap their heads around all this? Because, you know, there's a tendency where, you know, if you think too hard about it, maybe you just wanna run home and scream, but what am I supposed to do? In one of the webinars that I made in the past, someone um, brought me, um, a question, how do I prioritize vulnerabilities where everything is critical?
So it is, it is a situation. Um, but I think, and this is where you start off exposure, attack, surface management, um, so external, so taking that attack your view, I think most, I don't, I wanna say most or some, or we see a situation where security teams are currently handling vulnerabilities because of, I don't know, historical reasons because this is the way that they're working. And we see also a change in the market where security teams, our customers are taking the attacker review in order to prioritize, in order to understand, um, the essence of these vulnerabilities.
So it's being done in two ways. First, uh, how they are reachable from the outside. Can I, can I see that vulnerability as an attacker outside of demonization?
And second, we are also validating the risk. So we are doing it safely, um, without any risk to the business. So now I have validated risk and I know that it can reach, it's reachable outside of the organization.
And now I think we are on the discussion of from my hundred 100% vulnerabilities, I can actually prioritize based on the risk and not based on the number of vulnerabilities. So this actually changed the equation and it's changed the way that security teams operates. We see that security teams starts to breathe now when they can actually deal or handle the risk rather than, you know, vulnerabilities.
So it it, it's, it's a different story. Um, um, as we kinda look at all of this stuff, how do I as the security person have this conversation with the business because um, you know, a lot of times business people are thinking, well, you know, we just spent a boatload of money on security and now you're back telling me we need to spend more because why? And they're kind of like, you know, saying, why should we increase the percentage of money spent on security?
And they're a little dubious 'cause they don't see these threads per se until, well, it hits 'em in the head with an attack. But, um, is that what I gotta wait for or is some sort of catastrophic event before I can get this business people to wrap their heads around this? Or is there a way to talk to them?
There is always a way to talk with them always. And um, it's funny that you're saying saying that because I think security is always mean. There is always that dance between security and business implication, business case I and all that stuff.
Um, you cannot come to a person and say, we are exposed or something and expect that he will invest money. However, um, one of the triggers, uh, for security, for security projects is of course compliance. Um, and we can see, I don't wanna say shift, but we can see requirements, um, appearing in, for instance, at least two in Europe that actually requires for external monitoring.
So they want to understand if you, uh, if you have, um, assets which are exposed to the internet, are your vulnerabilities are, um, reachable from the outside. And I think once you have in the compliance discussion, it's a pure business discussion. So you need to comply with in order to do business.
Um, so this is 1, 1 1 use case. Um, the other use case I think is to show, To move to risk efficient to, I mean you need to discuss in business metrics you need to understand to show the business impact. Um, and in some case what we are doing is we are bringing the business implication of, of issues or findings, I wanna say vulnerabilities because sometimes it's an three bucket exposed to the, to exposed to the internet.
So it's, it's not a vulnerability, but it's definitely something you need to, to deal with now. But in many cases, you want to show the business implication. You wanna show, okay, if this server, this application will be hit, will be breached, then what it'll do to our business, that means that one hour our customers will not get any service.
Think this is something that management and business people can understand and in some cases translate it into money. Um, and once you are translating cyber risk into business risk, then I think it meets, um, otherwise you are right, it's a different languages. Mm-hmm.
Um, um, to your point, are we also therefore moving towards, um, some sort of ability to continuously monitor those environments and activity and we need to, uh, have that level of visibility And so, and, and how do we gain that? And um, 'cause I think, um, people have been talking about this theoretically for a long time and very few have accomplished it. So is it getting any easier to, um, continuously monitor an IT environment with an eye towards preventing something bad from happening?
Is it getting easier? No. Um, I think, um, complexity is there and, and I think um, the attacker always like the attackers always like the bigger organization because it's more prestigious is because, you know, uh, it'll get to the news faster.
Um, what we can see and what we in psycho is doing is actually trying to imitate the attacker or take the attacker point of view when we are doing the discovery, the, how to say external, it's not inventory, it's actually discovery and actually showing where you are, where you are exposed. And there are two levels. So one is understanding the organizational structure.
We are actually mapping the business organization and from that point, you, you are going to the technical aspects of physical assets in terms of web apps or IP addresses. So it's not, we are, I mean this is the outside in approach. So basically looking at the organization the same as the attacker would do.
So that provides the visibility, um, that, that match the attacker. So, um, you can actually be certain or be sure that you are actually playing, um, with the right tools against the attacking. Now once you have that, you can, uh, understand all the elements, all the, I don't wanna say chain of events, but uh, you can understand the vulnerability that he sees, you can understand where he can breach, what he can do, and then you can map it into attack path analysis, uh, and all that stuff.
And I think this is where we're leaning back into the inside systems in where we're integrating and combining all this data, as I said before. So you have that full visibility from the outside connected with the internal systems. Hmm.
I think people kinda are starting to understand that and you gotta think like your enemy essentially. But one of the things that I do hear from folks is they go down this path is they wind up collecting a massive amount of data and then they don't know what to do with all that data and they can't afford to store it all and they can't figure out what data to keep and what to toss. 'cause there's just, you know, everything is instrumented and it gets overwhelming.
So how do I kind of think about security on a certain level has always been a data management problem, but how do I manage the data? I think one of the ask question that we've been asked as well is if I will bring sonito and exposure system external exposure, uh, would it increase the noise? So am I bringing yet another solution that will make yet another noise?
And the answer is no, um, is no because of two things. Um, we're not replacing the complementing. So in the end of the day, I wouldn't say that I can give you the internal inventory as, as any other, uh, player in this market.
But what I can do is that I can provide my insights to the internal, for instance, we're integrating with harness with axons. And what we do provide is, for instance, that holistic view. So you, you will have that visibility of all the assets of all the external assets and once you are connected it with armies for instance, you can actually create an end-to-end attack paths so you can know which of your crown jewels is so to say threatened by attack path, which is can be exper can be initiated from the outside.
And I think this is where the noise is actually, um, being diminished. So now instead of 1000 findings, you can focus on that 10, 15 findings that actually show you this attack path. All right, well folks, you heard it here.
Hey, if you can't see what it is you're supposed to defend, I think you're at a serious disadvantage in the first place. So, um, maybe the first step is just understanding what that environment is and then figuring out, well, if you were gonna attack it, how would you do it? 'cause the bad guys are probably doing that as already as we speak or as one wag one said to me, if you can imagine it, somebody's trying it.
Hey Amit, thanks for being on the show. Thank you very much for having me. All right, and back to you guys in the studio.