Cobalt’s 2024 State of Pentesting Report with Caroline Wong
Caroline Wong, CSO of Cobalt, shares the results of Cobalt’s 2024 State of Pentesting Report. Caroline also shares trends to be mindful of and how new technologies such as AI are impacting the market.
Transcript
This is Techstrong tv. Hey everyone, welcome to Techstrong tv. If you're watching this, the day this came out, it's Monday of RSA week.
So you would expect to have a security heavy, uh, agenda, and you won't be disappointed if you are in the cybersecurity world. You probably know this woman right here who is my guest. She's, she's a good friend of mine and, but also someone who I, I just am so damn proud to say she's my friend, actually.
She does, she does good work for the community. She does good work for, for, I mean, many different communities, not just the cyber community, but for women, for people who have had, uh, uh, not addiction, but, you know, well, addiction and, and dependency issues for children. She's a big dog lover on top of everything else.
What more can you, you know, better than shooting dogs, as we've seen lately in the press, but, um, anyway, there, there's just not enough good things to say about my friend Carolyn Wong. Carolyn, welcome to Text Drunk tv. How are you?
I am doing great. I'm so happy to be here with you, Alan. I'm, I'm happy to have you here.
So, Carolyn, by the time people see this on Monday, you are already going to be in San, well, you're, you're on the West Coast anyway, but you'll be at RSA conference by the time they're watching this. If you're at RSA conference, run over to MO North. We have a great DevSecOps AI event going on with some amazing speakers around ai.
But Carolyn, we're here to talk about the annual state of pen testing report that Cobalt has been doing for how many years now? This is the sixth annual, So I was gonna say sixth through seven. I'm so excited.
Mm-Hmm. Um, before we get into this year's results, let's kinda lay the groundwork. What is the state of PAN testing report?
Why do you guys do it and why should people care? Cobalt delivers the highest volume of extremely high quality manual pen testing in the world, and we have this treasure trove of data and we wanna share it. And so for the past six years, every year we take a look at all of the manual pen tests that were conducted the year before, all of the security vulnerability findings, and we publish that in a report because we want folks in the industry to understand what are the data-driven trends that are occurring.
And in 2024, we've got, we're looking at more than 39,000 security vulnerabilities found by cobalt pen testers last year. Wow. Crazy.
And, and it's not just last year. Now you've got six years of a body of knowledge here. So you, you know, you could start doing yearly trans annual trends and see how things have evolved and changed and what kind of news.
Yeah. I love those kind of memes where you see graphs that, that go out over time and how things change and grow. Yeah.
You're getting into that kind of territory now. Um, but before we get into those big trends, let's, let's focus into this year's trends and, 'cause it's been a crazy year, right. And many, I think, I think in hindsight, when history looks back at this, this'll be the, the dawn of the AI age, right?
AI is just stuck the oxygen out of every room in the house. Yeah. We've also seen a crazy year for tech where you've got tech layoffs that we haven't, we haven't seen tech layoffs in a long time.
I, and I'm in this industry 30 years. com bubble burst in 2000 to 2001, 2008 and nine, the great recession. It really wasn't terrible for tech as offer as much as other people.
But this year was not, I mean, let's face it, we, we've seen, we've seen things like, you know, valuations going down, VCs getting hung out to dry, and they in turn hung out their portfolio companies to dry crazy, crazy times. So this had to have an effect. No, Absolutely.
And in fact, these days, the state of Pentest report actually comes from two data sets. One of them, of course, is the nearly rather, the more than 4,000 manual pen test engagements that Cobalt conducted throughout 2023. We also bring survey data from more than 900 cybersecurity professionals in the United States and in the United Kingdom.
And so we've got sort of this technical security data and we combine that with the survey results. And in fact, perhaps it's no surprise, security professionals are disheartened, you know, the, the budget cuts and the layoffs are affecting security professionals in really big ways. You know, folks are, folks are concerned that they're not going to be able to handle the security for AI as fast as it's coming.
We've been doing pen tests on AI systems, and we actually are validating the OAS top 10 for LLMs for large, Large language language language modules, large language language modules. I'm so used to saying LLMs. Uh, And we find that actually it's, it's exactly what we're finding when we're pen testing AI tools, we're finding prompt injection, we're observing denial of service attacks, we're observing sensitive data exposure.
Um, and, and security folks are really, are really feeling this, you know, we, we see it in the data as well, you know, from the beginning, cobalt has been not only about finding security vulnerabilities, we're really about helping our customers to fix this stuff. Right? 39,000 vulnerabilities if they're just out there, that's not, that's not great, you know?
Yeah. But once those get fixed, that's when the quality of the code increases. That's when it gets actually more secure, and the fix rate is down nearly 30% because we keep track of which items get fixed and which items just sort of sit there and folks don't have the person power to be able to fix these security vulnerabilities that are being found.
Absolutely. So two things about what you talked about here, I wanna focus in on one. One is the, let's call it economic macroeconomic conditions.
Yeah. So as a result of that, a trend that I'm starting to pick up on here, tech Strong, because, you know, we, we talk to a lot of people. We don't, we're not a security vendor.
We're a media. Is that where there's this narrative that's been forming that, hey, enterprises are growing weary of spending a ton of money on security and all these new tools that have come down the pike over the last few years without they, they don't see a payoff. They, they're not seeing security measurably getting better, even though I think it has.
And you may think, and those of us in the industry think, you know, that it's a lot harder to get hack now than it used to be. Right? Um, but from a, you know, from a big business point of view, they're saying, Hey, every year security comes to us with, with an ever bigger budget.
We keep buying new tools and we don't know whether they're being used not being used, but we're still getting breached. We're still getting hacked. Something's gotta give here.
We, it's tight budgets. I can't be spending that kind of money. Yeah.
And I, you know, from a security point of, from a security person's point of view or pro's point of view, I mean, that's not music to our ears. You know, that's scary stuff. Like, you know, we, we are doing better.
We are doing better. Um, but we, but the, the bad guys are no dummies either. And they're doing better and they're harnessing AI and they're harnessing these latest tools.
You know, I, you know, I, I just have my little teleprompter here saying 57% of the respondents in this year's report that the, their department has cut back, uh, on, on tools, you know, for, for security and 16 or 16 or 18%, more likely the average, right? So it, it is real. We're seeing a cut back on security budget, security tool.
Budget, yeah. Tool. I mean, that may play well for, for Cobalt because with your crowdsource model, it's actually maybe a little more cost effective for companies.
But from the wider point of view, yeah, it, it, it is, it is tough. There's, there's a return to fundamentals. Okay?
There Is, there is, there is a trend of folks getting back to basics, really basic security, understand what your attack landscape is, find security vulnerabilities, fixed security vulnerabilities. There's all sorts of other fancy stuff that folks are saying, you know what, that's a nice to have and we can't afford to do nice to have right now. So we're gonna focus on must have.
And pen testing is a must have. We saw a 30% increase in the number of pen testing engagements of folks are doing between 2022 and 2023. And there's really a coming back to basics, because every dollar spent on security is a dollar that doesn't get spent on a sales head, a marketing head, an engineer a product.
And so there's always a trade off involved. One of the recommendations in this year's state of pen test report is intentional resource allocation. When you have to do more with less, you've gotta be really thoughtful about where you're putting each and every single dollar.
I agree, no doubt about it. I want to turn down APIs 'cause you may or not APIs, ais, 'cause you mentioned that Caroline, in my mind, three important things. Aboutis, I'm gonna say 'em and then you can run with it.
Number one, to me, the two security issues for us around AI are this AI poisoning, or ai, you know, malware. And when you are using AI to write code and that code, you know, because these LLMs, these LLMs are based on everything on the end. They're large, hence the L and LLLM, right?
They're large language modules. They're taking kind of indiscriminately a lot of information. And then being trained that gets into the training so that these ais can work.
So, you know, there's that old saying, bad, bad in is bad out. And, and so when you're asking them to write code or check code or give you information, it's only as good as the information it was trained on. And, and so we've gotta be careful of the hallucination, the poisoning, the injection of malware that could come in via prompts or just, just the fact that they're based on this cesspool of data, right?
Yep. That can lead Carolyn. The, the thing of, uh, worry about APIs is from a, like a privacy kind of point of view, is how do I make sure that my data doesn't make its way into the LLM that these ais are using?
And that may be proprietary or damaging, you know, sensitive data, number one. Number two, look here at Tech Trunk, we publish a lot of content. Content.
I pay a lot of money for that content. It's our, it's our lifeline. It's our bread and butter.
It is how we earn a living here. If you are going to use my content to make your content, I need, I should be compensated for that. I should be able to decide what content I want to contribute to the common good of an LLM and what content I don't.
And I think that's gonna be a huge security play over the next couple of years as we figure out that, no, you can't just rape everything on the in rake everything in off the internet and use it for other people to make content. Definitely. You know, to your first point, bad data in bad data out folks are coming to Cobalt and saying, please, pen test our AI tools.
We've seen an explosion as one would expect in these types of requests. And the top security vulnerability that we're finding in AI tools is prompt injection, either jailbreak or indirect. And this is simply people with bad intentions being able to poison the data and change the outcome.
You know, I think about, uh, you know, I've got young children, as you know Mm-Hmm. And I say to them, Hey, if you wanna know something, why don't you search for it online? But the answer you get is not the truth.
You need to understand that the answer you get is not the truth. And we as technologists, we know that AI doesn't tell the truth. AI tells us something based on the data.
And if that data can be poisoned, then the outputs can be poisoned as well. Second thing, privacy. How many developers today are taking how much code bases and putting them into public LLMs to say, write this code for me.
How many folks are looking to write content, you know, and putting private data in there. At cobol, what we're doing is we have a private instance of chat GBT that our teams are using internally so that folks can use the power of ai, but we're not leaking data all over the place. Right.
There's an additional one that I wanna share with you, Alan, which is AI enables bad actors to do better social engineering. So many of today's breaches start out with social engineering, a bad person saying to, you know, someone who doesn't know any better, give me some information. And if they're able to use AI to get the language and the tone and the nuance right, in order to better impersonate a trusted person, that's just gonna make social engineering a little bit harder to detect.
Yeah. I mean, again, from our, from our research assisted working with us here, uh, according to survey data from the report, right? 84% of cyber, uh, professionals say that the growing prevalence of AI driven attacks is changing how their team approaches threat detection.
It, it, it is a way of, of looking at it. I should have had three points about ai. I mean two.
Yeah. And they're two AI kind of security threats. Let me turn it on its head though.
We gotta use AI to beat ai. That's right. Right?
We, we need to, and when I say we, I mean the, the cybersecurity industry. We need to harness AI for good harness AI to combat these threats. Harness AI to automate more, do more, be smarter, be better in security.
And, um, I'm wondering that like how's Cobalt saying, Hey, how can we use AI in Airmark? It's the next level of automation. So, okay, what Cobalt does is manual pen testing.
We leverage really great pen testers and they look for the security vulnerabilities, and then they write a report. And I'll, I'll ask you just for fun, Alan, if you're a pen tester and you spend some of your time hacking and you spend some of your time writing a client facing report, which of those two activities do you prefer? I like hacking coders.
Code hackers. Hack writer's write. That's right.
That's right. And so we are able to use our private LLM in order to help these folks write reports. Great.
They can put inputs And then, and then the report comes out and it's that much easier and it simply allows them to spend more time both on what they enjoy doing as well as what's gonna be the true value add for having that specific technical security resource. Yeah. So I, I think this is the future of, of not just AI for security, but AI in general, which is specialized.
LLM, some people call them SLM, small language modules, right? That are much more focused, much more narrowly focused on, in this case, you know, uh, pen testing reporting and pen testing, right? Or what, whatever your, you know, your focus is rather than trying to, you know, boil the ocean of the internet in one of these, you know, LLMs that are out there, though, I do think you need that large, and I, I don't hold myself out to be an AI expert, but I do think you need that large language module to sort of get that basic training of your AI done.
But that, that should, the best way I've heard it described to me, Carol, it is that should be your long-term memory that you go into. If you don't have something in your short term memory, your short term memory should be that SLM or that specialized LLM that you're using for your ex area of expertise, for your, you know, where you're going with this for your body of knowledge. And I, you know, I think we're at that awkward teenager stage right now where some companies like Cobalt are going in that direction already.
They're making great progress. Others, others are just starting to embrace I ai I mean, it's only been, what, a year and a half maybe. And Remember when people were so scared about the cloud?
Yes, absolutely. When everything, When everything is run in a private data center, you know, and, and folks, you know, at that point in time culturally could not imagine giving over control to a third party to host my technology infrastructure. You know, and now we're on the other side of that.
We're at the very beginning of it with ai. And one of the very interesting things about AI is the immense amount of storage that it requires. And this is why there's actually a security vulnerability, a very serious one.
It's the number two security vulnerability that we find in AI tools, denial of service, because these are so storage and resource heavy that if you can take someone's down and make it not work for their intended users, that's a, that's a big security as well as an availability problem. Agreed. I, I agreed.
Carolyn, we, we got off on a couple of tangents there. We used up our time. But let's talk a little bit more about the report, not, not necessarily findings.
'cause you're gonna be at RSA Tuesday. Come see me and let's, let's talk more at RSA about it on Broadcast Alley. People can watch it streamed live and it'll be on text drunk tv.
But for people watching now who wanna get this report and so forth, can we clue 'em in there? Limb in, absolutely. Go To Cobalt io.
Cobalt io hit resources and you're gonna see state of pen testing 2024 right there, 26 pages of rich data. Uh, and we're so pleased to be able to share it with the world. Absolutely.
As always. And are the other five years available there as well? Or they're Out there?
They're out there. So you just, you know, search for Cobalt State append testing 2023, cobalt State Append Testing 2022, you know, and all of that data is out and available because it's really important to us to be transparent with the data that we have in order to help the industry. Got it.
Carol, you help the industry being who you are. Thank you. Um, I will see you Tuesday.
I'll see you then. Moscon at, uh, broadcast Alley. Carolyn Wong, cobalt State of Pentest report 2024 is out.
io for it. We'll continue this conversation at RSA later this week. You're watching this on Monday.
It'll be on tomorrow live as well. Uh, until then though, Carolyn, thanks so much. This is Alan Shimel, you Techstrong tv.
Thank you.