Securing AI Agents Everywhere with Zenity’s Michael Bargury
With Zenity, businesses can optimize efficiencies, automate processes and maximize human capital by leveraging AI Agents to get more done, securely. Zenity customers can also enable business users/citizen developers to securely build agents and automations on their own without needing extensive coding backgrounds or developer training, as well as govern the use of AI Agents for day-to-day work.
Transcript
Hey everyone. Welcome back here to Techstrong tv. I've got a, a first time guest here.
He is the CTO and co-founder of a company called Zen Entity. His name is Michael Barky. Michael, welcome to Tech Drunk tv.
It's great to have you on. Thank you so much. A thank you for inviting me.
Ah, it's our pleasure. So, Michael, do we were talking of course before we started. You were recently in the RSA, like we were, uh, was this your first RSA, you've been to RSAA lot?
Uh, I've been to, I've been to RSAA lot and I can tell you this year was something special for us. Like, you know, I a so much noise, so many announcements being made, but we are today really at the pinnacle of, of the problem that needs to be solved. So I had amazing, amazing conversation LA last week.
Good for you. Good for you. All right.
So tell us what brought you to RSA all these years? Give us a sense of your journey, Michael. So I started, uh, as a kid in gaming.
So like very, very, very small age. We would play with our friends and I would play, like I I would play competitively. And then at some point we figured out that people were basically dosing each other to get the other team to lag.
So you win by the fact that the other team is unable to play. And that's how I got into that. That's the first time I got an experience a deep, like a you got, you got the feeling inside that this is an important thing.
And later I have this typical like 8,200 story, uh, uh, served, served there for, uh, for a few years. Stayed there for two extra years, and then after that I st I kind of took a step back. I went to study math and, uh, computer science and started working for Microsoft.
And I made my way into the city of office, uh, for Azure security. And then I really got to see the problems that are hurting, uh, the enterprise today. So it's like all of a sudden it became practical from when I was a child and I kind of, I got, I got why this is like, I got the urge to do something about it.
But then being at Microsoft, seeing how product gets made, gets made from the very early days, seeing what the enterprise needs. I, I got like, I went full cycle and, and was prepared to do my own thing. Uh, and that's, that's what got me like to, to, to following a company.
You know, it's a, it's a so where I sit, right? I, I get to tick to a lot of people like you and everybody's story is unique, but you see patterns and you know, and as a parent, right, I have two sons and you see these patterns and they, and they, they kind of play out, right? It's that, it's that curiosity, it's that passion.
Yeah. That Shines through. I strongly agree.
Like just, just that experience as a, as a young kid, when you don't understand anything but you, you just want to get the specifics. So you, you play a game, you really want to be good at that game. You do whatever is needed, right?
So it before, so where it started with like, a lot of people got into security through hacking, cracking software, right? And many of those people are now living in the industry. So it's kind of just, you need That spot.
I've been in security. Yeah, I've been in security 30 years. Yeah.
When I first got into security, first of all, we didn't call it cybersecurity, it was called security or info security. There was no classes in school that you took. Most of my friends, they were either network people, right?
And then they started doing security on the network, or they were kind of the kind of people that would like to break things and then build it back better to make it harder to break next time. And that was, that was the core of, now, now kids go to school, they have cybersecurity majors, they go into the 8,200, you know, unit for four years or whatever, and the VCs are waiting outside, start a company. But, um, but it wasn't always like that, right?
I, and that I think is an important thing people need to remember. Uh, so talk to me a little bit about how did Zen come about then? So Zen was a very special thing.
Look, I, I've known, I wanna, I wanted to start my own company since forever. This is a typical Israeli fund thing. Uh, you know, you want to start a company.
You still, to be honest, when I, when I had this, I knew it before. I knew what it means. And, and by the time I knew all what it means, I also understood that you, that the person that you need to convince when you go and start a company is first of all yourself.
You know, a lot of, a lot of times when you start, you immediately think about VCs, you immediately think about customers. But first you need to convince yourself that you are gonna spend the next 10 years of your life building something because that's what it takes to be the big thing. So your opportunity cost is major.
It's like the biggest years of your career you're gonna spend on this thing. So the first question is, who are you gonna spend it with? And that's the first thing I covered.
Uh, and, and I, I spent, uh, a year looking for, for the right partner. And then I, I recollected with Ben. Ben and I are very strong, uh, uh, like very good friends.
When we connected, the first thing we did together was, uh, talk about values before, an idea before, like what are the, is the problem we wanna solve? What kind of company do we want to create, the kind of company we wanna work for? So that's when we started and the next pace was, okay, we wanna build something big.
What is the biggest problem? We know what is the biggest gap that we can see? It's gonna be a problem that's interesting and deep enough.
So in five years we'll still be excited. In seven years we'll be more excited. It cannot be something small.
It has to be major. It has to be something that we don't know how to crack. And the biggest problem we could think about at the time we saw at the time was citizen development.
So at, at my, my time as at Microsoft at the CCTO office, uh, I was, I was seeing all of the edge cases where customers were, were helping and we didn't have the right answer. And, and we saw there, there were many different things, but one of the crucial things that I saw is just how big citizen development was, both at Microsoft and also with our biggest customers. That notion, the notion of no code of everybody can build application has been like in digital, uh, in the digital world sense forever.
Like Excel was a major advancement in that field. Writing changed careers, it's changed entire, entire professions. But what I saw with no code, with this drag and drop interfaces, that they are actually making a huge impact.
Again, people in the business have really been able to move the business forward without waiting for it. And I saw this blow up and I saw how different, we need to think about it from a security perspective because you have a thousand more applications being created and everybody's a developer and there's no CICD and like all of the tools, processes, knowledge that we're used to, they just don't apply. And at the Covid, it's about enablement.
It's about letting everyone do more. That is, and I love the fact that we can build a security company that's focused on enablement, not blocking, non catching the bad guy on enabling people to do more. And so that's where we started.
We started with Citizen Development, we started with no Code, and then two years later or two and a half years later, we find ourself in a situation where now everything is no code. We are all vibe coding now. And that idea of no codes became like the main thing that's happening right now with ai.
Yeah, I mean, the vibe coding has just, you know, taken off. And, and it's funny, right? You say you build a company, I, and I, I've started, as I said, four or five companies of co-founded Venture backed.
And you do it, it, you put your, you put your, you know, your blood, sweat and tears, your kish is my grandmother would say to her, right? And, but you need to pick something. But what you pick, there's no one has a crystal ball.
So when you started with low-code, no-code, for instance, hey, low-code, no code's a up, you know, it's a huge thing. Who knew that AI was going to just upend this and really allow us to do no code, right? Allow everyone to become a citizen developer.
Um, but now I feel like we're, we're, you know, I don't think people realize the security issues around this low code, no code revolution. And now of course the AI coding, vibe, coding kind of, I dunno if you want to call it a revolution, evolution, whatever, but Michael lay out sort of what, what's the, where, what could go wrong, right? Where's the risk here?
So when we started with Citizen Development, we had to do a lot, a lot of work to help people understand what's the risk? Because you do under, like people do understand the inherent risk. We are letting people across the business build, be creative, do more, and there is a, there is an inherent risk of losing control.
And, and in that level of intuition, it's clear, it's been clear to everyone. But we had to make that specific practical, what does the security program look need to look like? So we, we started the os local, local top 10.
We released, uh, uh, research across the years and on Blackhead and, and, and, and i a and whatever. And, and now with ai, I think it's even, it's even bigger. We all have an inherent, like humans.
We have an inherent cautiousness, an inherent fear about ai. And that is something that's rooted in our culture. And so I think right now people understand both the magnitude of change that AI agents can have in the enterprise.
Like they can change our lives in the way that we work. But it's not like that, it's not a, it's not magic. It's gonna require a lot of engineering work.
It's gonna require a lot of ingenuity. If you really want to capture that, you cannot just let like 10 people in your org build stuff. You need to enable everyone to think about how they apply AI to their, uh, to their job, to their function.
And when you do that, well, you have, you have now let everybody build these agents. And these agents are different. They change themselves.
They decide at runtime, what are they going to be today? Like one time you ask the agent to do something and it decides to be one thing, and then you decide, and you then you ask another thing and decides to be another thing. Who knows how, how can you tell that this agent is going to only do what you asked it to do?
So you say you build an agent as a customer success agent. Should that agent be able to write code, should that agent be able to send information outside of the org? Well, it, it, it does like it, it has all of the capability to do that.
How do you know that your agent is going to stay within the boundaries that you want it to stay? And so what part of what we've been able to do, part of what we've been investing in is showing the risk, what could go wrong. And uh, that started at Black Hats about, uh, six months ago where I showed that the, the biggest agent out there, the amount, the one that has the most security, like Microsoft copilot, it was the, at the time, the largest, uh, enterprise agent that is built by like company that's like Microsoft.
They, they have all of the budget, the smartest people ever. They, they can build a secure thing. And I showed that just by sending an email to you, I can take, I can hijack yo copilot and now yo copilot with your identity operates on my behalf.
I change its goals and now I, I change the goal to be, hey, uh, find every piece of data Alan has access to and send it out to me. Or, Hey, please get Alan to, uh, go to my phishing website or to share its mfa, his MFA codes. And so that's what we showed six months ago.
And what I showed at LS a last week is that not only that this problem still occurs, it's a fundamental thing. It's not just for Microsoft copilot. We show that on chat, GPT, we show that the Gemini, we show that it can be, that it can happen not just through email, but through teams messages, slack messages, calendar, invite sharing documents.
It's not a problem that we are going to fix. It's a problem that we need to manage. And that's a very different thing.
Resilience, defense in depth. Like this is a, this is, uh, we have learned this lesson already. Part of what I, I'm trying, I, I've tried to convey, uh, at my talk at, at our sale last week is that we are, as a security industry right now, look at what we're doing.
We are looking at these LLMs and we say, if only we could make sure that no painted data go to the LLM, we'll put a firewall, we'd put a bunch of guard rails. The problem with that is that you are rebuilding the perimeter that didn't work the first time, right? It's not, it's not gonna be the solution here.
These LLMs, they have been trained on the internet, and the internet already has a bunch of bad stuff like the, the, the LLMs the models are, are tainted from the get go. You are not gonna protect them just by uh, putting a wrapper around it. We need to assume breach, we need to assume that the next prompt injection is going to occur and cus and, and the attackers are gonna find it.
And we need to still be resilient. We need to apply defense in depth. Agreed.
Agreed. You know, and I listening to you, I can't help but think, are all these agents double agents or potential double agents? It's scary.
So I mean, defense in depth is something we've all been preaching insecurity for many, many years. Frankly, I don't know if it falls on deaf ears or people are just tired of hearing us say it. But Michael, how's it get better for us?
What, you know, is there light at the end of this tunnel? Yeah, that's a very good question. So absolutely, AI is incredible.
Um, and the fact that we cannot fix prompt injection, that is not a fixable problem, doesn't mean that we cannot manage it. I'll give you an example. Malware on the Windows ecosystem is another unsolvable problem.
You are not gonna fix malware. Nobody can fix malware. Instead, we manage it, we do defensive depth, we look at behavior.
We try to catch it many different times when you first download the thing and then when it's, and then when the process runs, and then when it tries to encrypt the file or send it outwards. You see what I mean? We have multiple points where we try to target malware.
This is a problem that we are managing. We are not trying to fix. We need to apply, we need to do the same, apply the same mentality to agents.
So instead of saying, Hey, my agent is okay and I'm just gonna filter out everything that goes to the agent, no. Instead we need to think about those agents. As you said, they could be double agents, humans can be double agents too.
What do we do with humans? We have afi CY programs where we look at humans, especially under circumstances where they might be more suspicious and we look at, at behavior and they try to see are you doing your job as you've done or like as you should or are you doing something different? And so we should be doing the same kind of thing for agents, but other than humans.
With humans, we have privacy concerns. We don't do this for every human in an enterprise with ai, we don't have any privacy concerns. We should monitor everything that these agents are doing.
We should identify if the agents are following their proper function or not. I love it. Hey Michael, we're over time already, but people want to get more information on sanity.
Where can we send them? So I'd sent them to, uh, labs io Labs is our, uh, is the place where we write technical stuff for nerds like uss. And so there's no, no marketing material.
It's just pure research to understand this problem deeply. Listen, like, uh, I, I really appreciate this opportunity and I'll tell you, this is a deep problem. We haven't solved it.
Like we know we, we have solved some parts of it, but it's gonna take more than than us. It's gonna take the entire community. Yeah, no, this is, we're just at the, we're at the beginning of the beginning, not even the end of the beginning of this problem.
And, and so I, I agree with you. We're going to see this more and more. Zeny by the way, is spelled Z-E-N-I-T-Y and it's IO Labs Zen io.
Michael, thanks so much for coming on. I appreciate you. Maybe we'll see you on Black Hat in August.
Would love to. Thank you so much. This has been really fun.
Alrightyy Michael Bari, CTO Co-founder entity here on Textron tv. We're gonna take a break. We'll be right back.