Navigating the AI Security Landscape with Mindgard’s Leaders
Transcript
Hey everyone. Welcome back here to another Techstrong TV interview. I've got some big news on a company called Mind Guard that we're gonna discuss right now.
Let me introduce you to my two guests. First of all, I want to introduce you to Dr. Peter Garrigan.
Uh, Dr. Garrigan is the, well, he's I guess current CEO and CTO at Minding Guard, but about to assume a new position, a really exciting position. And I want to introduce you to the incoming CEO of Minding Guard.
And that's James Breer. Gentlemen, welcome to Textron tv. It's great to have you on here.
Thank you. Yeah, thank you very much. Thank you.
James. If it's okay, I'm gonna start with you, right? It, 'cause you're kind of coming in, you know, pinch hitting here.
We're calling up a new batter into the box. Um, give us, you know, your impression here, incoming CEO of minding guard. Why?
Sure. Well, again, thank you for having me. Um, you know, my background, I've been lucky enough to work in startups for the last 25 years and have been, I think, successful identifying new emerging markets and technologies.
And through that, my last role as CEO of which was a security automation company. It was very familiar. It was very clear to me that obviously very obvious for most people that automation's gonna be, have a, a huge impact in, in the world.
And so I was a part of that and we had a lot of good success as I was, uh, working at Swim Lane. It became, again, very apparent to me that the impact AI is gonna have on security. And, uh, I was introduced to Peter and very quickly realized what he had built and the company's building was gonna be very unique in its approach in dealing with securing ai.
And I said, I need to be a part of that. It was that simple. Absolutely.
Absolutely. Um, James, if it's okay, I'm gonna, I want to focus in on Peter A. Little bit here.
Please, Peter. You know what, let's, let's first talk about your background. Obviously your PhD.
Obviously I'm not, I'm assuming on the technical side of things, but, you know, I hate to assume share with our audience a little. Sure. So I have a PhD.
Um, I am also a chair professor in computer science at Lancaster University in the uk at Lancaster as well, of the leading universities in Europe, in cybersecurity. Yes. So I'd be doing this role for about eight or nine years, I would say.
I had a great opportunity to work with lots of big tech companies as well. So I kind of blend both the academic rigor of looking at security of systems and ai, but also working very closely with some of the big tech companies to solve problems they have. And if you wouldn't mind, and I'll, I'll throw it to either of you who would like, give us a little bit of the history of mind guard.
I'll hand that to Peter. Thanks. So I run one of the largest research labs in the world for system security.
And about 11 years ago now, I am thinking ai, almost specifically deep neural networks. They're pretty interesting, but I'm not sure of current security tools and techniques actually work against it because it actually unravel a deep neur network, which underpins all modern ai. It is very, very black box and very, very random.
These things aren't good for security. Spend the next years of my scientist and engineers at University Lab trying to unravel some of the secrets and find a, it was really, really hard. And a b actually doing this quickly was really problematic.
And come to 20 2017, a very famous paper came out called Attention's All You Need, and this was the architecture that underpins all modern language models and agents realized that we need to make a company in this space, but the tech we have built, because if we don't do this, I, I'm seriously worried people deploying AI at scale back in 2017 cause a huge set of problems. Fal, today we hear lots of stories about air being deployed and things going wrong. So I took half my scientists from a lab, went to London, raised capital and position us, um, you know, became the founder C and CT of Ingal at the time, actually thousand 22.
I Love it. It's a great, great journey. You know, Peter, I, I've, uh, I've been in startups myself for 30 plus years.
Done three or four, five venture backed ones. Be, you know, tech Strong was not a venture backed, it was actually my blog is how it started. But I've been in security also for 25 plus years.
Right. We didn't call it cyber, we called it InfoSec. And um, so I'm, I'm, I'm familiar with the, the whole journey.
It is a rare individual who's willing to kinda maybe set aside their ego and say, you know what, I'm probably not the best person for the job of CEO if we're gonna take this where we want to take it. Um, my talents lie elsewhere. But, but generally coming to that conclusion is a journey, right?
It's not something you wake up in the middle of the night and say, Eureka, right, I'm doing this. It's, it's a, it's a realization journey. Tell us, if you wouldn't mind, tell us a little bit about your realization journey to this point.
Sure. So when you're trained to be a scientist, you get better at identifying biases and flaws and thinking. So that's kind of one element.
The second one is even from the company started, I remember saying to my first staff and my investors, I am the CEO and CE two and a professor. I have three roles here. Eventually those roles become decoupled.
It makes perfect sense to do so as the company scales. So the question was when and not if and bank defense way two, yes, I had the vision and drive to pushing forward and that's still the case. But as the company's now bigger and we know we have traction of customers, we have a more people more, more, more sales.
Everything about this, I could do it, but it's also my specialty. What I really care about is building positive change, social good research, vision, execution on research technology. But people would look to me in terms of, Hey, you have the vision executes.
Now the company is bigger solutions, more mature, and the customer are aware, it makes sense to get people who are special as of what they do. So as we're now growing to the next stage, getting someone who's been there before, someone who's grown the companies to become, you know, the rocket ship makes perfect sense. And I'm sure Jim will talk about this, which is, this is seen as a great partnership, which is I can bring the vision, the can, the, you know, the, the experience in MySpace and the drive to make things better with Jim's experience to also make things better for customers.
But more importantly, he's seen the things in pipeline sales, GTM and even things like, you know, um, people, people and resources, these things. This is Jim expertise in terms of group building, great companies. My expertise is at the heart of building great technology and great research to solve these problems.
Love it. Jim, let me come to you. A lot of times these kinds of, uh, you know, uh, executive board level kind of things are, are accompanied by uh, a money raise.
Was there a money raise or additional capital raise with you coming on board? Not yet. I think we are currently had completed a, a seed round financing a little less than a year ago.
I think it's our plan to start to entertain, uh, a round financing here in the next six to 12 months. Good. Um, Peter, I I just one more question for you and then I want to really jump into mind guard.
You are shifting to the role of Chief Science Officer. Talk to us a little bit about what that mission is. What, what do you see that as your, you know, what, what's your, what's your job as Chief Science Officer?
So my job in the company, so as founder, is to make a company successful. Sure. So it's not a case of I'm still talking to customers, I'm still doing marketing.
All that thing doesn't go away. You know, alter founder, always a founder. But my core remit now, it's very common in AI startups that the chief science officer is, you know, one of the, the key focus points of the solution.
'cause a lot of the space stuff in AI is not solved from a reasonable technical background. So I'm moving into a role to really focus on two or three things. One is that my strength is looking for a vision for the future and making a reality as a scientist, I can bring that type of skillset and my background and ability into the company and keep driving forward the solution.
So have a very differentiated and a great product. The second one is what makes our company a little bit different is there is a very large AI lab at the University of Lancaster, which operates, there is a partnership that we have with them, which will be, um, talked about, I'm sure soon in order to actually, you know, train the next generation of AI security researchers. I'll be faking my time with them as well.
So there's a whole untapped market of research in this space that needs time. So our, my job is gonna be ensuring that my guard's pushing the future of AI security. And we do this by actually having, getting at the heart of the problem of AI that we talk about is really the science behind it and how do you take that science and build it in analogy.
So a lot of my job is to focus on that, but of course I'll still be doing everything else in the company as well. But that's gonna be my core focus and obviously Joe Jen will be coming in then to, Um, excellent. Thanks.
Thank you Peter. Thank you. James, let me turn back to you now.
Talk to me about minding guard's mission going forward. Yeah, Sure. I mean, so again, I think what we're trying to build is the leading AI security company in the world.
Full stop. I mean, that's our objective and it's really trying to help enterprises, I would say, kinda secure their models, uh, their agents systems. 'cause it's going to be ubiquitous here very shortly across the entire life cycle.
That is our mission. Yep. So I I would say it's already ubiquitous, right?
Yeah. 90% of developers are using ai, uh, 30% of Google and Microsoft say 30% of their codes AI generated. Uh, and, and that's just in the, in the software delivery space.
Right? Right, Right. Jim, when I look at AI and security though, there, there's two, there's almost like two separate missions here.
One is I'm leveraging AI to provide better security, right? Yeah. Two is, I am actually, there's three missions.
Two is I am defending against bad guys, let's call them Yeah. Bad, bad people who are using ai Yeah. To, to from, you know, malware and, and and for bad things.
Yeah. And then number three, knowing that every organization is building a, a, a new AI infrastructure, a new AI stack, if we could call it that. Right?
Right. How Do I protect the AI stack from AI and conventional threats? Yeah.
Right. Whether I use AI or not. Yeah.
Talk to me about the three of them. I'll tee that, that's a very good question. I'll let Peter answer it.
But I think first and foremost, as you brought up right now, the, we're at a stage in the, in the market where you, if you saw kind of AppSec and how that grew. Yep. And now you look at today there is, I, as I am, I'm expecting a massive tsunami of challenges with securing ai.
Meaning you don't see a ton of breaches announced yet, but they're coming. And if you fall track kind of AppSec in its history, we're at the very bottom. And you also brought up kind of defense, well first and foremost, most importantly is can, can companies get assurance and comfort and confidence that they have the right defense?
And it starts with kind of an offensive strategy. And I think what we're trying to do is take kind of what Peter's built with the, the kind of the, the uh, academic rigor of AI research and we're combining it with offensive skills. So we're building the best kind of AI hacking infrastructure in the world.
We brought in probably some of the best. And we're gonna train the models so that we can help give confidence to, to enterprises when we go kind of on a red teaming and using AI to red team to test and validate, you know, through attacks that their, their infrastructure's protected. Now we will also be doing protection is what you kind of got, we're talking to there.
But it starts with getting kind of visibility and then attack and then we'll defend. And I dunno, Peter, if you want to add to that, I Think there's two things. AI's been around for decades.
It's not new technology, non new concept. People are talking about Alan and agents as the ne this generation. And it's got huge adoption, as you mentioned, Alan.
You know, it's, it's pervasive, it's ubiquitous. It's come very quickly to market. So this introduce a new attack surface.
'cause the AI is still software, but conceptually, but how you do things like attacking and defense is actually quite different because there's no code. It's a bunch of mathematics probability in AI models. It's very, very difficult.
Yes. And what we're looking at is co enterprise companies have three problems in ai. First one is the visibility of risk.
Where is my ai? What is it doing? If it can't find it, I don't know what it's doing, how enough I'm gonna defend it.
So that's Always question one. Exactly. Number two, how do I assess my risk and how do I measure reliably in ai?
That's very, very difficult from a skills perspective. But also just fundamentally it's a random black box. How do you actually have some validity on my assessments that I do compliance, but also make sure I secure.
The third one is if I can find it and I can test it, I can assess it, how do I defend it? And again, the solutions are moving very quickly. So these are the three problems that we see day in, day out, essentially companies deploying and building ai.
And we'll talk about my, I'm sure shortly, but minding guard's built to look at those three products. Excellent. Thank you Peter.
Jim gonna come back to you. So is minding guard more of a red team sort of service provider or is there actually building product around this? Yeah, no, this is a product company.
I'd say we're gonna take advantage of our heritage, which is a lot around red teaming. But again, we're gonna expand on that because red teaming is just one element. One of the things we haven't talked about is kind of the psychometric impact or behavioral impact AI has and how people can manipulate AI psychologically.
That's another element that hasn't really been thought through deeply in the market. And I think we're gonna approach that as well. So yeah, heritage is, is red teaming, but we're looking at it much broader.
Yeah, I mean certainly, uh, if you wanna call it AI poisoning, inducing hallucination, we call it a hallucination. But if it was induced, well still a hallucination if someone induced it purposely, right? Yeah.
Poisoned the, the llm. That's right. Um, and, and that is the kind of, you know, Peter, to your point, that is the kind of attack surface we're talking about, right?
Um, you, you, you have LLMs and it's not just LLMs. The, the future is a lot of companies will be creating their own small language modules and their own rags and their own vector. That's right.
Basis. You know, that that will supplement, let's say a large frontier model running behind it or something like that. Um, are you utilizing AI to fight the, to fight the ai, to defend the ai?
And if so, how? Peter, do you wanna take that one? Uh, the answer, like all things, it depends on the context.
The answer is yes, but AI is a tool, like all tools use it where it's fit for purpose. So in minding guard, there are instances yes, that if you are attacking AI or trying to assess its risks, you can use ai. But that's, there are other techniques that exist as well.
There are rule based systems is also AI decision making, even just having coding and doing, doing some technical stuff. So yes, you can use AI to augment things, make it automated, but there are also other techniques as well, I should leverage. It comes out to my original point, which is the AI is still software, therefore a lot of those concepts apply.
But as Jen mentioned with this, the problem with AI is that it's not human by the way, even though it tricks people a lot, it's still software, but it's being trained on human language and human information. So as human-like characteristics in terms of people interact with it. And because the modern AI and l LMS and agents using natural language, I can ask the same question a thousand different ways.
And that makes it very, very difficult in security. So the, the example I give people is we're about manipulation. If I called up a call center, could I find the right words and tone to make them upset or angry to do something I don't want to do?
Yes, probably in infinite universe I could do is the same as ai. You've seen loads of Ks of people basically gaslighting AI to make or do things it wasn't built to do. And that's the, and this is not a new concept for humans, but with the power of ai but also the ability for it to un to understand natural language, it makes entirely new attack surface that you exploit if you're an attacker.
Excellent. Guys, just a little housekeeping. A couple things I wanted to make sure we mention was you recently, recently also announced the addition of, uh, rich Smith, who I, I think I know Rich, um, rich Smith to the team as well as Aaron Portnoy.
Two pretty well known, uh, offensive security folks, US headquarters moved over to Boston. Great town. My my son's up there, he just passed the bar, he just got results.
He passed the bar exam there now. So if you need a lawyer up in Boston Gym, alright, reach out to me. You, um, so good, good stuff there.
What's the website guys? The URLI mean? Yep.
Um, it's mind guard without the u ai. ai, correct? That's correct.
Yep. Wanna make sure we get that out there. So guys, first of all, I wish you, both of you a lot of luck in your new positions.
Peter, it sounds like you are a duck in water, right? Getting into this chief scientist role, and I'm sure you're gonna en enjoy that a lot more than looking over the, the spreadsheets and the sales numbers and managing all of that good stuff that goes into being a CEO that I I know all too well, unfortunately. Um, Jim, I'm, I'm glad to see you back in the game.
You know, my, uh, swim Lane was a great company. We, we worked with Swim Lane here at Techstrong over, you know, either Security Boulevard or DevOps one, one of the seven sites we wrote. But, um, I'm sure you'll do great things here.
I'm looking forward to hearing more from both of you very soon. Great. Thank you.
All righty. Pleasure meeting you. Thanks Ellen.
Pleasure meeting both of you. James Breer, Dr. Peter Garrigan, mind guard.
It's M-I-N-D-G-A ai. Check it out. We're gonna take a break here on Text Trunk tv.
We'll be back in a little bit.