Safeguarding Data in Generative AI with Harmonic Security’s Alastair Paterson
Alastair Paterson, CEO and co-founder of Harmonic Security, delves into how Harmonic Security helps companies to adopt generative AI without risking the security and privacy of their data. Their pre-built data protection LLMs detect sensitive data of all forms – no labeling, complex rules, or training on your data required.
Transcript
This is Textron tv. Hey everyone. We're back here on Textron tv.
You know, we haven't spoken enough about Gene AI today, so I thought we'd do another interview that we'll have, uh, some relevance there. I wanna introduce you to Alistair Peterson. Alistair is the CEO and Co-founder for Harmonic Security.
Alistair, welcome to Techstrong tv. How are you, Alan? I'm doing great.
It's a pleasure to be here. My pleasure to have you on Alistair. Um, well, let's talk about you a little bit.
You know, I, you're the CEO and Co-founder Euro Harmonic, but you know, what have you, what have you done before that? What, what's your, you know, what's your life arc about? Yeah, no, plenty to talk about, but, uh, the first thing's, probably the accent you can tell is, uh, strangely not from the US here, but yeah, originally from the uk.
Uh, I, you know, I grew up there, spent a bunch of time in the cybersecurity industry there before setting up my own business for the first time, which was Digital Shadows, which was one of the leaders in the threat intelligence space. I remember Digital Shadows Well, didn't, didn't Jen Gio, my, my friend Jen worked there for a while. Absolutely.
Yeah, that's right. Yeah, we had some, a small world Through the company and, uh, it is a small world in, in security. Everybody knows everyone, uh, for sure.
And, and so that one, yeah, I mean, it started around the kitchen table in London in 2011, just two of us. And we, you know, we had to bootstrap for quite a long, a long way before I could, uh, come and raise the, the big bucks in Silicon Valley and move my life out here in 2015. So I've been living in San Francisco for the last nine years now.
Wow. So, yeah, good chunk of time. We, we scaled digital shadows massively, you know, over 500 customers ultimately at the time of acquisition by ReliaQuest, which is a KKR company out of Stampa that you've, you're sure you would've come across.
Absolutely. Yeah. And so I did a, did a great year there of, of transitioning the business, and then Harmonic Security started just in August of last year.
So we're very new. Excellent. So give us the harmonic story now.
Yeah. I mean, you mentioned Gen ai and I, you know, if people are not sick of hearing about it, uh, I'd, I'd love to talk just a little more about that, because I think it's a phenomenal technology. I mean, I, I mentioned we were, you know, we acquired at, at Digital Shadows back in July of 22 and chat GPT came out in November of 22 and really changed the world.
And, you know, I I, I was one of the, the sort of early adopters that just really thought the technology's potential was, was enormous and was talking to all the smart people. And I, I could in Silicon Valley and elsewhere about it, but I was also, you know, something to think through the security concerns, but also opportunities with this gen AI wave because I think it's a bit of both. And, and when you think about gen AI adoption in the enterprise, that, that was where I first went with this.
There's a lot of people that are still just dipping their toe and they're a little, little worried about going more into this revolution. And, and the number one concern they have is about their sensitive data. It's a data privacy issue because in order to use these models, you know, you have to put in a certain amount of sensitive corporate data into them.
And, and it's one thing if you have that controlled in your, your boundary, but of course, there's this plethora of new AI apps outside the, the boundary, of course, these third party apps that, that of course your employees want to start using and speeding up their jobs and, and getting these efficiency gains. But the risks are, are really that some of these models are going to train on the data that's put into them. Some of them are, are really early startups that are not well secured and, you know, are not going to hold the data compliantly if you, you've got customer data that's going into models held in geographies that that should not go, for example.
So challenges, like how do you, how do you maximize this AI wave without the data privacy issues? And, and the, the, the sort of fundamental issue here is that the existing data protection technology wasn't really working anyway. So going back to digital shadows, my my last journey, we were looking at information that had already leaked out of companies and we were finding, you know, billions of sensitive records a week of payroll, HR, data sensitive IP that was getting out in the open, usually accidentally.
And so this je I wave is, is shining in a new light on this data protection space, uh, again, and, and the existing measures are just lacking because they rely on regex matching on social security numbers or credit cards, you know, kind of pattern matching these structured data types or, or it's all about labeling and categorizing all your data, which is a real challenge for most organizations to do. So that's the challenge that we see today is, is the backdrop to Harmonic. Excellent.
Yeah. So coming on a harmonic, I guess is, is probably the, the, the next, uh, key thing. So, so I think the, yeah, seeing this challenge is, there's a few things we're trying to do.
We, we really try to reimagine how do you do data protection in, in the gen AI era, right? And, and initially thinking about data going into gen AI apps and models, but actually we're looking at the broader piece of like all data protection. And, and so we've, we've really from the ground up, thought about about this problem.
And so the best way to imagine it is, is to think about what, if you personally had enough time to look at all the information that was leaving your business, right? You would make a pretty good decision about this is sensitive, this is not sensitive, because, you know, you've got that human judgment, you know, what, you know, something that looks like IP is and where it should and shouldn't go, and, and the existing technology can't do that, but we're building that equivalent at Harmonic. So we are, we're building our own suite of data protection, LLM, so the pre-trained models that make human-like decisions about what is and isn't sensitive that's leaving, uh, any business.
So yeah, there's a lot more we could dig into in, in, in that of course. Yeah. No, I, I'd like to, if you don't worried.
So look, one of the things I think we're, I think most people who are playing with ai, using AI beginning to understand is that to really get the value from it to really make it work for you. So it's not just a, a parlor trick if you will. Um, you need these LL you need custom LLMs, you need s SLMs, maybe you need multiple LLMs, you need better training of LLMs, you need better underlying data in your LLM if you really wanna maximize the value you're getting out of your ai right out of your Gen ai.
Yeah. And so to me, that's where the action is, right? Can, should companies be creating their own LLMs?
Should companies be licensing s SLMs? Should companies just be training, doing their own training of larger other people? LLMs?
Are they gonna be sort of, not data free, but um, free data LLMs that no one's gonna come back to you at some point and put their arm on you and say, Hey, you used my data in your LLM and now you know, you owe me. Um, these are all things that I think are going to be popping in here. Um, at, at the end of the day, I think we may look back at this period and say, well, it was a little bit like the Wild West, right?
Everything we would just using everything, right? Yeah. We trained it on the entire internet.
Yeah. You know, warts and all and everything in between. And, uh, what, uh, what were we thinking?
Right? Of course, we got the poisoning and the biases and, and we had the ip, uh, in refrigerants that we did. I think we'll get smarter, better, more secure about it going forward, or at least I hope.
Yeah, I hope. Well, you and I have been around long enough to see, uh, waves like this before, and every time a new technology like this comes along, huge benefits, but it, but it takes a while to figure out where they, It takes a while to catch up, no doubt about that. Um, let, let's talk a little.
So harmonic security, fairly new, generally available, still kind of, you know, money raise. What, what do you, what do you think? Yeah, no, we're, we're on a, we're on a real charge.
I mean, I, I had the, uh, the fortune this time round, so with digital shadows, we were bootstrapping for several years before. Yeah, No, it's always hard. The first one's the hardest.
Always. Totally. Yeah.
This time around, I, I was able to, uh, yeah, to raise the money extremely quickly. I, you know, went back to people that had invested in digital shadows. I was very fortunate to get, uh, you know, 10, 11 and Storm Ventures involved right at the start here.
So I, um, yeah, we, before we'd even founded the company, they, they were ready to, to back us. So I founded the company on the Friday. We got a term sheet on the Saturday, and, uh, we signed it on the Wednesday and, and got rolling.
So yeah, it's, it's given us the ability to execute incredibly quickly here. So amazingly, despite only founding in August, we were live on our first enterprise site in January of this year, so that's great months. Um, we're now live on on many, and, and we, we are heading for a GA imminently.
So we'll be announcing that shortly and, and certainly second half of this year, it'll be a commercially available product. And, and just going back to what you were saying about the World West, I think it was, it's a really interesting point. I, I think the first thing that we do when, when you spin up Harmonic is we give you kinda like an X-ray of the business to show you what AI apps are in use across the enterprise, right?
Who's using what, um, which teams are using which tools and which ones are gonna cause you a business risk of some sort, because they are, they're training on the data that, that you, your sensitive ips going in and, you know, being else's model or, or maybe it's hosting your data somewhere that you wouldn't want that, that customer information to go, for example. Mm-Hmm. So that's, that's like first bit of functionality we've got.
And then the more intelligent piece is what we've been building with these, our own data protection LLMs that are then giving you that, that really accurate visibility into the sensitive data that's going out. We can go way beyond that prior generation that was just trying to match on social security numbers and so on. And you can actually describe to us in plain English whatever it is that you want us to look out for.
And, and then our models understand that. Just like you would just, like, I would, so, you know, if that's, um, if it's customer data fine, but it could be some specific type of IP or investment information, or m and a details or code or whatever it might be. If you can describe it in plain English, we can actually spot it with, uh, harmonic.
Do you think DLP may finally work? Well, exactly. Getting My friends out there, don't shoot me.
Uh, yeah. But, but it, you know, it's so, it's been hard. It's DLPs a, you know, digital loss or link prevention has been something that's been around a long time, but, you know, put a little gen AI over it and, uh, I mean, it could actually be much, much, much more effective.
Right. Because it's like, it's like working with a scalpel rather than a shotgun. Exactly.
Yeah. And that shotgun at the moment is just being tuned to look at a few, you know, regulatory tick boxes around PII It's not actually stopping the stuff you care about. No, It's, it's a shotgun, right.
It, it spreads a, a pellet blast, you know, in a radius. Yeah. This is much more laser.
Um, are you guys gonna be at RSA? Yeah, for sure. We are one of the 10 Innovation sandbox, uh, companies.
Oh, you Didn't tell us that. So we, you know, you're about, you've gotta be the sixth or seventh one I think we're doing, you know, and it's interesting for those, and at this point, I think my audience is tired of me repeating the story, but the RSA Innovation Sandbox has been around about, I think it's 18 years now, or 19 years. Yeah.
The Celia Marnier, uh, RSA runs the innovation program. And when you look not just at the companies that are won, but at the body of the 10 finalists every year, it's a who's who of, of security companies. And like I always say, and it's not cliche, just making the finalist for this thing is a win.
Right. And, and so congratulations to you, uh, innovation Sandbox, of course, takes place Monday, May 6th. That's Right.
Uh, it's all day. And if you have it, I think even just an expo pass, you could come up to the Innovation Sandbox and check it out. You'll be presenting, I assume.
Absolutely. At some point Monday I've got three min Yeah. They give, they give you all three minutes and then the judges will, you know, announce their decisions.
It's exciting. It's exciting. And, and congratulations to you and the team for doing that.
I mean, to think about a company started in August, making Sandbox that spring. Yeah, yeah. It Accomplished me.
We're, we're really pleased at, I've gotta say, it's partly because I've got around 20 of my former colleagues from Digital Shadows on board, so we've just locked in place and executed and, uh, we, yeah. No, it's just getting the band back together, right? That's right.
Yeah. That's, That's very cool. Yeah.
Will, it's a sandbox. And if, if anyone wants to come and see us there, we, we'd love to see you. Absolutely.
Um, Monday, May 6th. Congratulations, Alison. That's, that's a, uh, that's a good accomplishment.
Be proud. Good stuff. Anyway, we are about outta time.
Did we mention the website Harmonic Security? It's a very easy to find company name. I love it.
Love good stuff. Yeah, we hearing from you, You should check it there out. You can check it out there.
Do check them out at the, uh, sandbox event on Monday. Quick Reminder Monday, we're also doing our DevSecOps AI event at RSA in the Moscone Center. We have some great speakers lined up.
There're also on the topic of security and AI actually, um, some great keynote and speakers from most of the leading AI companies. Um, but for now, I think we're gonna take a break here on Text Drug tv. We'll be back soon with our next guest.