Navigating Cybersecurity Challenges with AI Insights with Deep Instinct’s Carl Froggett
Transcript
Hey everyone. Welcome back here to Tech Drunk tv. I wanna introduce you to Carl Frog.
Carl is the CIO for a company called Deep Instinct. Hey, Carl, welcome to Tech Drunk tv. It's great to have you on.
Hey, Alan, good to see you, and thank you for having me. Pleasure. Look forward to Pleasure.
Our little chat today. My Absolutely. So, Carl, I, I mentioned you're the CIO at Deep Instinct, but you know, there are, there are different flavors of CIOs if, just like there are CTOs, right?
Some are very engineering it, well, they're all IT focused, but some are more outbound, outward facing, inward facing, really serving at the executive level and filtering down. Some are filtering up, some are doing both. What kind, how do you consider your role as the CIO and, and maybe, you know, how has your personal journey kind of shaped that?
That's an interesting question. Uh, Alan, so I'm probably one who does a little bit of both, uh, filtering down, making sure that the, uh, the teams understand what I need them to do at Deep Instinct. Uh, I also run customer support, uh, at Deep Instinct.
So it helps having that technical background, although, uh, profess the, the, my time is more on that upward executive and communication, which is a really important part of, uh, of leadership. And that's because of my background coming from financial, uh, background in Citi and, and providing their security solutions for the 27 years that I was there prior to joining Deep Instinct, you have no choice but to be, uh, technical, but to get buy-in, you have to communicate, you have to put, you have to talk to the business. Ultimately, I'm serving the business here at Deep Instinct, just like I was at Citi.
So the role of the CIO is, is is both generally, Alan. Absolutely. Absolutely.
You know, I had, uh, had the pleasure of knowing at one time the Citi, actually, it was probably Citibank or Citigroup then had three global CIOs. I don't know if it was like that when you were there. I would imagine I Was three, Well, there were three Globals back then.
One of them was a gentleman named Peter Fisher. I don't know if you ever knew Peter during your time. I know Peter.
Yep. Yep. I mean, I, I had the pleasure of meeting and dealing with Peter from a, a company I had co-founded.
And, um, what a gentleman. I mean, he had smart, I, I learned a lot from Peter. Uh, a lot of respect for what he did over at City.
What, what, I mean, the whole city operation was Yep. Yeah. I met Peter, um, quite a, quite a few times.
I was quite young at the time, I'll say 27 years. It, it was definitely, uh, the late nineties, early two thousands. Uh, we, we were building, I I, you know, him in the early two thousands.
Yeah. We were building, uh, Canary Wharf, um, uh, the city group centric at Canary Wharf, which was the Europe became the European headquarters. And, uh, Peter and Rich Brunick was another one.
Sure. Uh, that came with Peter and yeah. Had to present the whole, uh, cybersecurity element.
It was called Security at the time, not cyber. That's, uh, something. Yeah.
We called, we, we called it InfoSec, right? Yeah, Yeah, yeah. So I, I remember, you know, uh, presenting to, uh, Peter and, and Rich and, and getting grilled and coming out with a pat on the back and relatively unscathed.
So, yeah. But good for you. It's those kind of interactions, um, really, you know, at the time you, you're almost just pleased to get out alive.
Um, but those experiences are, are what I've managed to bring into deep instinct, uh, you know, today because dealing with such titans and, and certainly there's many others, um, in such a high pressure environment, like one of the world's largest banks, um, you know, it, it's, it's an experience that, that Pew get to have. And so I'm really grateful for, for my whole time, though. Absolutely.
We'll talk more about that as we go on, but Deep Instinct. Talk to me, or actually don't even talk to me, talk to them. A lot of folks out here are not familiar with Deep Instinct.
What, uh, how would you describe it? Sure. So I joined Deep Instinct three years ago, and we prevent known and unknown threats, and we do that leveraging a advanced AI called Deep Learning.
Hence, hence the name, which is the learning, uh, that the chat GPTs and LMS of the world are built on. Uh, the company was founded several years ago, and, uh, lane Bess, uh, he was the CEO of Palo Alto Networks when they were startup. I know, I know Lane too.
And then, and then he went to Zscaler, that little company. Yes, he did. And he has a huge boat down here in Miami.
He Does Alan. Yeah. And, um, and, uh, yeah.
So yeah, he's our CEO and I've known Lane since the Palo Alto days. Oh, I didn't realize. Okay.
Yeah, yeah, yeah. So, uh, he was one reason. But, you know, we, uh, at, at Citi, uh, what we were seeing was threats were evading the more machine learning and signature legacy based approaches.
'cause that's what the threat actors do. And so we ended up evaluating and purchasing deep instinct and, and putting it in our applications and in the storage to prevent, and here's the thing, to prevent against threats that have not yet been invented. And that's a huge claim, but it stands up, which is why we have financials and other big customers today.
But our core is deep learning. That's what we bring to the table, and we're the only cybersecurity company that that does that. So that's what we do and that's what makes us fascinating.
The classic story of the customer who loved the product so much, he went to work for them. Exactly. Yeah.
Yeah. Yeah. Not raise a blade.
Great story crop. No, No. Not raise a blade.
Good for you. No, sir. Um, so, alright, just real quickly, deep instincts website.
Yeah. com. It's right there.
Okay. And, uh, the audience, you, I'm on LinkedIn. You can hit me up if you, uh, have any questions or any follow ups that you need through today.
Fantastic. Carl, I wanna turn to our topic of discussion today, which is SecOps teams and burning, and burning and burnout, even with AI and everything, agent ai. And supposedly, you know, it's gonna make our jobs easier.
It's gonna make us 10 x more effective. It's gonna do a lot of the tedious work. We're gonna have nirvana and heaven on Earth and cue the angels playing the trumpets, right?
Yep. But yet, we're still suffering from burnout. Now, Carl, you and I are of an age, right?
Um, Is it the gray hair, Allen? Is that what gave in the Way? Well, at least you have hair.
It's all good. Um, you know, but we're of an age where we didn't really talk about burnout in the late nineties and the early two thousands. You know, I, and there are some people who say, is burnout real or is this part of the participation trophy generation?
But you know, I, I've had the chance to interview, and I forget her name. She's a profess PhD professor, probably one of the most foremost authorities on burnout in the world. Both her and her husband actually, and I'm drawing a blank, I apologize.
She, I, she's always used to talk at Gene Kim's DevOps Enterprise Summit. Mm-hmm. Um, but anyway, I remember, you know, her telling me and teaching me that burnout is now recognized by the World Health Council or the World Health Organization, the WHO.
Yep. As a, as a bonafide diagnosis. As, as a real, it's real.
It's not just people's, you know, saying, oh, we're being overworked or whatever. Burnout is real. And it's lethal.
It's lethal. It affects, affects your mental health and your physical wellbeing. Um, but I, you know, why, why in this age of AI and automation, our second cyber cyber warriors, we'll call them, right?
Let's make 'em feel good. Why are our security operations teams suffering more than ever from burnout? I think, I think it's a nuanced, uh, kind of question.
Uh, so we, we did the voice of the, uh, SecOps, uh, which is available from the website, uh, go and download it. And, and that is, uh, responses from the front line. So this, this is something that we, we publish, but the, the results are from those warriors that you talk about are on the front line, Alan.
And it's, it's literally an interpretation. It's non-marketing. Uh, my background, I have a good in, uh, high integrity for making sure that the deep instinct, you know, produces, uh, quality research like this.
And I think the burnout's got a few things having run security operations, right? So I not only did the engineering and the architecture, but I also was, uh, ultimately accountable, uh, for security operations. And the context, I feel that, that the response of burnout, which was 69%, it was a, you know, two thirds, more than two thirds said that, uh, it had, uh, introduction of AI created burnout.
So why is that? I think there's a couple of nuances. One is there's been this mad rush, right?
So the bad actors have been leveraging, uh, you know, LLMs and Daft AI as Gartner called it, to, to create more sophisticated threats on a scale that we've never seen before. And we'll get to that. So, so what that means is that there's more going on, right?
And you can look at pretty much any statistic of phishing, ransomware, ransomware fines, right? We're spending all this money, Alan, and yet the bad guys are still winning, right? That's what the statistics show and the breaches show.
So if you put yourself as a, as a warrior in, in, in SecOps, you now have these new ais, but really they're not, they're not addressing the problem. So security operations are, are inundated with a vast amount of telemetry data because it's detect and respond, right? And that volume just keeps going up.
And so, get this, Alan, you are paying for, for whoever's product to send you all that data so that you can respond as a security operations person. But there's a couple of things there. More data doesn't necessarily make it better.
And there's a lot of false positives. So you end up, you end up spending a lot of time chasing down and ultimately finding that something was a false positive. So you, you didn't actually do anything in chasing that event.
So you feel very disheartened, right? But the vendors who are sending you all this telemetry are now selling you an AI to help you sift through and figure the telemetry out. They're not addressing the root cause of the problem, right?
If they fix their products with a more advanced ai, like deep learning, they would be able to prevent the threat from overwhelming the SOC in the first place. But, um, you know, uh, AI's everywhere as, as you know, Alan. So they've implemented an AI to try and help security operations per se, but it's not having the effect.
And what we do is we actually prevent the noise and the threat in the first place. That's the fundamental difference about what we do. We now have a prevention first approach, not a detect and respond approach.
And ultimately security operations is very stressful. Uh, like any operations role, but security operations is constant, is 20, you know, those bad actors don't go to sleep. Some of the other operation roles, you have stability and you have calmness, uh, and until something breaks, but security operations is, is constant.
There's always something to do. And I feel that the burnout is a, a multitude of chasing false positives, not getting anywhere, implementation of all these random AKIs that are not addressing the root cause of the problem, which is to stop the threats in the first place, right? And then your, the security operation, they've also gotta learn and use all these new tools, right?
As well as do their day job. So I think there's a whole bunch of factors that ultimately just lead to a, a lot of overwhelming stress and a, and a significant dip in job satisfaction. 'cause they're not actually preventing the threat from happening.
They're responding to it all the time. And that ultimately, you know, just leads to a very demoralizing situation for an individual, which is why they feel burnout. So I, I think that's two other things to the equation we need to add, Carl.
Number one, you know, almost by design, right? Our SecOps teams are playing from behind. You know, whether you're a football soccer fan or a American football or a baseball or basketball hockey, when you are playing from behind, you're down a goal coming into the third period or the second half, or you know, you're down three runs, you only got two at bats, left it.
That pressure builds it's constant and, and security, it seems, you know, as I say by design almost, we, we are one step behind. It's this cat and mouse game where we're the cat, right? We're waiting, see a hundred percent, You know what clever way the mouse is going to come at us.
Now, secondly, yes, we have these wonderful ais to use, and whether they're the right AI or the wrong ai, I don't think we have enough experience with the ais to really know which is good, bad, or indifferent. We're still learning. I think it's an emerging kind of, uh, uh, emerging sort of, uh, expertise to pick the right ai.
But we don't have a monopoly on ai on the good guy side. Those bad guys, look, they're clever sobs, right? And, and they, yeah, they're using AI too, and they're making our life miserable with these ais, right?
Phishing is so much better than it used to be, used to be able to spot most phishing attempts because, you know, English is a second language and all of that. Yep. Today's fishings are beautiful, right?
The the whole, I mean, they're using AI throughout the whole battlefield, if you will. And, and make no mistake, I, I think that that's another reason, Carl, is that the battlefield, if you will, the, the attack, uh, Surface, The attack surface is, is expanding every single day. There's, you know, there's a new, a new vector, a new thing we're worrying about.
It's not, I mean, it's, it, it's not fun sometimes being a, a SecOps guy, right? Right. And I, it's, um, it's not, it, it's not fun.
Um, uh, but you get the satisfaction when you know that you did something more Than stop thing, right? Then You something. And that's another issue in security, right?
When nothing happens, you did your job, at least to the outside world, right? You know, inside, man, Well, I'm sending you any operational role if the phone doesn't ring, like it's a good day in the office, right? I'm I'm Good day.
Exactly. Exactly. Yeah.
Just to, uh, yeah, I, I think you're right on the, uh, on the ai, now the bad guys have advantages then the big advantage they have is that they generally don't follow any laws, any rules or any regulations. So, no, they, um, uh, the University of Indiana did a good study, uh, in 2023, I think, of, uh, the 15,000 or so at dark AI is what Gartner coined LLMs, um, that have no morality and guardrails, right? So you can ask them to do whatever they need to do, and they, they'll do it.
That's where the bad guys operated more than three years ago. So this is the explosion of AI from a bad actor perspective, because they just literally stopped almost overnight using their old methods because they don't care. They're leveraging their most current technology, which was lms, um, yeah, ultimately to, to make their objective.
And most objective is to make money through extortion or whatever. Nation state, obviously. And activists have, uh, different motivations, but they kind of use the same, the same techniques.
So they, they al they always have that first mover advantage. Now, what we haven't had as cyber professionals, uh, honestly, I, I probably deployed machine learning, I don't know, 15 plus years ago. Um, and it was great at the time, uh, but most things ERO erode after 15 years.
And, and, you know, cyber's constant waves and, and the dark ai, the LLMs have just really empowered the bad actors. And if we think about the kill chain, so it, phishing, you mentioned phishing when chat GPT came out, phishing spiked over 1300%. Why?
'cause they're trying it, right? And yeah, like I say, they're very fast to do it. But that's, that's delivery, that's exploitation.
They're now using ai, uh, um, advanced AI to make zero day threats, zero day attacks. So what used to take experts, uh, you know, in, in and take 'em days and weeks, is now, uh, done through an ai. And the way I like to describe it is, you no longer need expertise.
You no longer need to go and recruit a whole bunch of bad actors who are good at coding or good at finding vulnerabilities. You just need intent. And you tell the ai, the bad ai, the dark ai, what you want to do, and it will create you those super realistic, uh, phishing emails.
Those deep fake audios, deep fake videos. It will, uh, Google just recently announced that they've used AI defined zero day vulnerabilities that we normally take a long time to find years in some cases, right? And so, if you think about the steps a bad actor needs to do, the only one that I can't point to an article or research or statistics is reconnaissance.
And that's where they're gathering information. And why can't point to something because it, they, you know, they don't need to tell you that they're doing reconnaissance, but almost certainly they are. So they're, they're not only weaponizing the whole kill chain using dark ai, they're automating it end to end.
So you are gonna get, well, we already see you're gonna get zero day threats, zero day vulnerabilities, zero day attacks, zero Day attacks Out of velocity and a volume. 'cause this is, this is cheap for them and they're gonna over work. They're already overwhelming.
The things that stood as well for the last 15 or so years are already starting to crumble. So we need to pivot, um, and, and use this more, you know, fight AI with AI as a tagline we use here at Deep Instinct. That's why we have deep learning, the most advanced AI that you can get today.
And we're the only cybersecurity company that does it. But it has some unique characteristics that it can predictively, prevent zero day attacks without any updates, without any new training. So some of our biggest customers, ministry of Defense and shipping companies, um, yeah, they're actually offline, rather, they're not connected to the internet.
So we don't have the limitations that machine learning has when it comes to preventing threats, um, including the unknown. And it's the unknown that is totally shifting the landscape right now. Absolutely.
Carl, I wish we had an an hour to sit and talk about this. 'cause I, I, I feel like we barely scratched the surface. I'd love, I'd love to understand more about what makes Deep Instinct better.
What what gives us a little bit of peace of mind and takes the knife away before I cut my wrist because of this dark AI stuff. Right. Maybe we'll have to have you back on and continue that discussion.
Uh, That'd be awesome. Alan, This recent, uh, data about 69% of security professionals Yeah. Contributing to burnout.
Is that a study you guys have published that we can point to on the website? A hundred percent. It's on the, it is on the website.
It's called Voice of the SecOps, and it is downloadable, uh, to anybody who, uh, uh, signs up. Fantastic. In the meantime, we will continue this discussion.
Um, I'm not sure if it'll be in person or on here, but we will do our best. I think we have A-A-U-R-L if I could read it. Um, no, I can't read it from here.
We'll, but we'll take this URL and we'll put it into the notes of, of this interview, Carl. Yeah. Paid, paid for the, uh, the sec op report.
URL. See, and I actually live in Boca Raton, Alan, so I'll see you in Miami as well. So I live, I live in Highland Beach.
Okay. So I'll see you before Miami, but we'll, we'll make, I'll, we'll talk. Thanks for being on Text Drunk tv.
We're gonna take a break. We'll be right back.