The End of Reactive Security: MazeBolt CEO Matthew Andriani on Preemptive DDoS Defense
The cybersecurity landscape is shifting under our feet, moving from a reactive posture to a hyper-preemptive defense as AI-driven threats and geopolitical conflicts escalate. Techstrong Group’s Jon Swartz sits down with MazeBolt CEO Matthew Andriani at RSAC to uncover how his company is redefining DDoS protection by running continuous, non-disruptive attack simulations to find the gaps traditional mitigations miss. From the frontlines of drone cyber warfare to the rapid rise of autonomous threat actors, Andriani explains why closing these vulnerabilities before an attack hits is the only way to survive in today’s high-stakes digital world.
Transcript
Hi, I'm John Swartz. I'm back at, RSAC in San Francisco at Moscone South. It's day one, and, we hope you're off to a good start here.
We're here with Matthew Andriani, who's the CEO of, of Maze- how do you pronounce that? MazeBolt? MazeBolt.
MazeBolt. And Matthew, I'm gonna ask you to take the floor and tell me a little bit about MazeBolt. I had a b- a bunch of questions I wanna ask you, but first let's kind of lay a groundwork so our audience has a better understanding of what your company does.
Thank you, John. Good to be here. Thanks.
We are in the DDoS space with Akamai, Impurva, Amazon, Cloudflare, all of these mitigation players. We don't do what they do. We augment those systems.
They've got good protection that's deployed at various enterprise organizations. What we do is we find out how attackers are able to penetrate all of those layers of protection all the time. Mm.
So that's what MazeBolt does. So you kind of enhance what those other companies do as, as, as a kind of an additive. Correct.
Typically what we see as we go in is around a 63% automated protection on average. Using our data of attack simulations ongoing, we can get that to over 98% automated protection. Wow.
So you, um... just kind of a side light, but I, I- it's important to know. We're gonna talk, I'm gonna ask you a little bit about national cyber warfare and about geopolitical tensions.
But you arrived in the US a few weeks ago- Yes ... traveling from Jordan. Yes.
How was that? It was interesting. I took a taxi from where I live to the southern border in Israel, crossed the border, took another taxi to the hotel.
The next morning, took a flight out to Athens, Frankfurt, and then to the US. How long did that journey take? Left Thursday morning, got to the US where I wanted to be in Vegas Saturday night.
Oh my God. Yeah. Um, well, I'm, we're glad you're here and we're glad you're safe.
Yeah. Um, this is a, I mean, this is kind of a terrifying... not a, kind of, it is a terrifying era we live in right now and, I'm imagining the, given what's going on in the world and given the advances in AI, that we have this evolving landscape of DDoS attacks.
There must be some sort of strategies or, that enterprises are, are, are using to stay resilient. Could you maybe explain what they're doing to keep themselves defensed? First of all, you're right.
The current landscape, even before the explosion of AI, was already a very high threat where enterprises were deploying defenses with many layers of defense. What they are trying to do now is close those gaps before an attack comes and try and preempt. I think this is a theme across not just DDoS, this is a theme across the industry.
So before, if, just to be clear, it was kind of a, reaction- Correct ... reactionary, approach. Now it's a preemptive, defense approach.
I think in general across the cyber realm, right? Mm. People are trying to, w- people that are responsible, CISOs that are responsible for the organizations or government, they're trying to figure out, "Okay, we've got all these defenses in place.
" But your existing defenses need to be working. Mm. I think there's a huge focus in this area.
We focus in this area in DDoS. It's, it's interesting because I've worked with a number of folks who are security experts. Right.
They started companies, Alan and Mitchell, Still Secure, and they always talk about this kind of concept of s- of security where traditionally, maybe until now- Right ... it was more of a kind of an evolutionary industry or technology versus the revolutionary things that are happening around it. So for instance, as cloud came along, or as AI, they are quantum leaps in terms of how technology is used.
" And that, you're, you're kind of telling me in a sense that that, that attitude or that posture among CISOs and others is changing. I think you're right. The, the industry's evolving very quickly, and the technologies are evolving very quickly.
If you're not getting ahead of it and figuring out how to prevent damage, you're gonna have the damage. And I think visibility is critical, and figuring out how you protect your particular organization is critical across the spectrum, whether it's from the external, internal, lateral movement, whatever you're trying to protect. So, that brings me in a sense again back to AI in that I, we get a lot of surveys, we write about a lot of surveys, a lot of studies, and what we consistently see is that there is a pressure from the top down- Right ...
to adopt AI as quickly as possible, maybe with not as much stringent governance or upskilling among employees, safeguards, guardrails, whatever you wanna call them, and that that has created a tension or created a very difficult situation for the CISOs because they're under pressure to put these systems in place, like agents for instance, and, but they're also responsible for the consequences if something were to go awry. So I'm wondering how CISOs are kind of reconciling the pressure from the top down to adopt AI, yet still maintain safe and secure operations. So I think AI is a huge topic.
Um, CISOs are under pressure. Some CISOs tried to block AI at the beginning. That lasted a few days or a couple of weeks at the maximum, and they realized- What if they, what if, what if they...
I mean, were there CI- CISOs who got-Forced out if they did, if they were too slow or resisted? I don't know. I, I don't know of any, but I think the internal pressure was very quick.
I think what you've seen is the, the smart organizations are ta- looking at what they've got in the whole AI space, providing kind of a singular, offering to the various departments, scaling down the amount of AI tools, but still letting people fluidly, fluidly work. I think that any company that isn't using AI is gonna just fall far be- they, they're not gonna be around. They don't have a choice, right?
They, they, yeah, they're not gonna be around, and I think everyone recognizes that the speed is incredible. When you get to the attack side, you can see... If you just u-use ChatGPT, you can see the speed that you're getting answers.
Now, if you just apply that in a very limited fashion to just orchestrating attacks against organizations, you can imagine the speed that that's moving at. Any manual process that you rely on in an organization with an AI orchestrated attack, you don't stand a chance. Which brings us back to what we do in, in our company.
We provide that data prior for those defensive systems to be immunized prior to that attack ever arriving, because any type of reaction with a human element in it is slowly gonna become redundant. And when I say slowly, I think over the next 18 months maximum. Uh- W- w- maybe can you-- if you could go a little bit deeper into some of the products you have and what they do and how they work in concert with some of the companies you mentioned earlier.
Are there just a couple that you could just highlight just for those who are unfamiliar with your, with the tool? Sure. So at the core of what our technology does is we are a company that figured out how to simulate non-disruptive DDoS attacks against production systems.
That's the core patented technology that we developed over many years. It was released in twenty twenty-one. So if you've got hundreds or thousands of services, we're launching hundreds of attack simulations validating how your defenses work through actual data.
So you're kinda testing, but in a, in a non-threatening way. " So we give exact telemetry on every single layer of defense you've got, and we operate on big data sets, so we're launching thousands of simulations over a month's period. And with just a few fixes, you can de-risk many thousands of entry points for attackers in an ongoing way because of things like configuration drift in security policies.
We, in twenty twenty-two, started significant research in AI because we generate what's referred to as unique data in the AI industry. We are now able to find, with a limited amount of knowledge on the targets that we see in an environment, point our simulator there, knowing where those vulnerabilities are likely going to be, and get that data as quickly as possible to the vendor responsible for that particular layer of security, so that when the customer's attacked, you prevent this initial damage or extended damage at least. Was your...
So your back-- Was your background always in cybersecurity, or were you- Yes. So w-- I was, I'm always wondering about what, what led you to... I'm, I'm assuming you co-founded this company.
Yes. What led you to, to, to co-found this? You saw immediate need, or you'd come across some examples of, of kind of like, high profile incidents or...?
So I was very involved in forming the team in Radware, like in twenty eleven. Uh, that was a research team that we scaled to an emergency response team that I was essentially dealing with real-time attacks against large organizations, like the New York Stock Exchange, Hong Kong Stock Exchange- Oh, God, yeah ... Vatican, all the banks in the US during large operations, coming up with solutions in real time to mitigate those threats.
And I then started a services company, seeing that every one of those attacks that I saw that caused extensive damage sometimes, sometimes for months, could have been prevented relatively easily. Mm-hmm. And when you look at these large organizations that had seemingly endless budgets, what they didn't have was the knowledge of how those systems are bypassed.
So we started actually as a cyber services company, and through need, transitioned to a product company in twenty twenty-one. So I'm assuming that business is probably booming for you. Yes.
Or you're getting more inquiries than ever, because I'm thinking about this classic scenario of people employing AI agents. I mean, I even read that, Mark Zuckerberg's gonna have his own chief of staff AI agents- Right ... with access to, to his ideas and his information.
And I'm, and I'm just wondering, that, that must have, is setting off alarm bells in a lot of these, a lot of these, sectors where, the bad guys... I mean, they're, they're making as u- as much use of AI agents as, as the white hats are. Right.
And I'm-- But there must be a palpable sense of, anxiety, I think, within enterprises, especially when as agents, of course, begin to be adopted at these companies. Yeah. And depending on what you're...
First of all, yes. Uh, and depending on what you're responsible for, if you're responsible for hosting the agent infrastructure, you've got an entirely new threat to deal with in terms of even how you inspect your traffic, right? Agents are completely- Yeah ...
new traffic. They're not traditional web traffic that you, or API traffic that you were used to in the past. This is, different traffic.
And I think that, protecting these agents is gonna become very complex because they're very dynamic. They're expanding and contracting. Can I ask you really quickly?
So would conceivably we're gonna have security AI agents- Yes ... that defend against AI agents that are malicious. So we could we conceivably have AI agent versus AI agent duels between good and nefarious purposes and good purposes or?
I think in the enterprise space, you're gonna see definitely orchestration agents, operating. We already got it in companies. Uh, we're actually, uh-Gonna release later this quarter a very significant AI capability, which I can't get into too much yet.
Um, but it's gonna be something that is going to validate a lot of these types of protections because we understand that very, very quickly, and we're already, getting some information from vendors and customers we're working with, that AI is gonna be orchestrating a significant amount of attacks, uh- Do you, do you expect, on that, in that vein, do you expect a s- fair number of announcements at RSAC along those lines, like A- AI agent, defense systems of sorts that are, that are brought out by companies that are gonna have some sort of platform or architecture to, to address this, this, this special problem you're talking about? Or ... I think there's gonna be companies, dealing with many areas of, you know, you say AI agents, but obviously AI is a, a large area of- Or autonomous ...
LLM poisoning, finding out, for instance, all of the models that you use in AI, you know, how contaminated are these models? Where do they come from? Yeah.
They might be open source. What's in those models? Who made those models?
How, what, how are they leaning? Uh, you know, there's models made in China, models made in America. What's inside those models?
How do you isolate those models in an environment to make sure that, that you're not gonna damage your environment, and have unnecessary leakage? For instance, what we're doing in our company, we've got a significant, project ongoing now for a couple of years where we have, significant infrastructure being built, which is actually completed now, that we kind of, anonymize all of our PII data before even starting to utilize it in that area, non, what we deem the non-PII area of our environment. Because you don't know what these LLMs are gonna do.
Um, even if they're privately hosted, you don't really know, so you need to assume. Kind of like in the cloud. You send data in the cloud, if that data's not encrypted, you don't know where that data's going.
It's very similar with an LLM, model, whether you're, forming it locally or using a local, database to maybe query external LLM models like ChatGPT or Claude or whatever it might be. I mean, it's just, that, to me what's stunning or what's kind of troubling is the speed with which these new models are being pumped out. Right.
Like, yeah, I mean, conceivably, it seems like every other month there's a new model from Claude, there's a new Claude model or GPT or what have you, and there's a lot more use of open source. So there's speed at, with which things are moving and advancing- Right ... makes this a, a particularly difficult time to, defend your, your operations.
I mean ... I think it also opens up a lot of opportunity because, for instance, companies like us, again, we, we generate a lot of proprietary data that, or vulnerability data on environments across the spectrum. We've got millions of data points, which allows us to leverage this to better protect our customers.
And the AI, allows us to get big data sets much quicker to be able to deliver to the vendor in a more organized fashion to eliminate the most amount of vulnerability in the attack surface as possible. So it does bring a lot of opportunity, but you have to have a, at least as a vendor, you have to take into account what you're doing with the AI, what the threats are, make sure that everything is QA'd between results- Mm-hmm ... automatically.
AI kind of checking AI, QA'ing the AI so that, so that the, you know, that it's reliable, for example. That there won't be an accident. So, so what's your, without...
I don't know, I'm not sure if you share the names of some of your customers, but if you don't, I'm wondering which sectors are they, are they primarily come from, and, what, if any, are their particular, concerns? We're in the 87th percentile plus in the BFSI industry, so banks, insurance companies- Mm-hmm ... trading platforms, payment processes- Got it ...
credit card. Um, government also, large e-commerce, but we primarily focus on the BFSI industry. Okay.
And they're concerned about infrastructure uptime, service uptime, banking continuing, no disruption to banking services, transactions. You know, there's a high volume of transactions happening in these environments that can't have downtime. You see, I was, I was thinking about the landscape.
I mean, in terms of the infrastructure, there's this big movement in the inf- infrastructure towards faster, more use of data, AI. And I'm, I'm thinking about the landscape. We have these geopolitical tensions that you- Right ...
experienced firsthand. We've got, OpenClau phenomenon, which, I mean, it's hitting, executives within companies like Meta. We, there's, there was an incident recently there.
These increasingly sophisticated AI attacks. Um, it's, there's a lot to digest, and I'm wondering, do you foresee more kind of geopolitical, geopolitically motivated attacks or even national cy- cyber warfare? We talked a little bit about this before we, we started filming, but I, I'm wondering if there...
You, you mentioned DDoS involving, drones and, and, and others. I mean, can you maybe go over that a little bit again? Sure.
Uh, so DDoS is used extensively in cyber warfare. We saw it in Georgia, we saw it in Ukraine, Iran. You see it all over the place when you wanna cripple infrastructure, cut communications.
DDoS is a great attack tool to cause chaos. Uh, you also see DoS attacks more accurately, not DDoS attacks, for jamming drones. If you look technically, technically speaking, this is an actual DoS attack-Against the receptor on a drone, and this is what- Oh, yeah ...
stops communication and drops the drone. So this is utilized in, in, in that- Have you seen instances of that in, in where, the conflict in the Middle East now? Uh, or it's, it's, it's probably existed.
But I mean- It is ... are, are, are you starting seeing an escalation of that or, or maybe even infrastructure? I'm not an expert in drone warfare, but, you can see that there's a lot of, activity in the area.
Uh, you can see recently that, the Americans e- even asked Ukraine for assistance in this area, so- Yeah ... definitely, I was recently in Texas in a very prestigious research institute that does a lot of research for the, the DOD, and, they shared some very interesting, findings on what's going on with drone warfare. And what was very interesting is how much DOS attack is being used in that warfare.
So- Interesting ... definitely it's being used. Wow.
Um, wow, that's a little something to ponder. I mean, have, can I just ask you, how, how do organizations anticipate sudden surges and disruptions, i- in their, in their infrastructure? Are there...
I mean, you're helping them, but are there other means that they use to, to kind of anticipate things before they happen? I mean, I, I'm, I don't know much about your field or, is this something that is especially used, I would assume, in banking, in, governments, finance? Of course, the main thing any organization will to- do is try and have a solid architecture in their, in their deployment and make sure that it's redundant and all these traditional concepts.
I think what they're also trying to do is secure the application layer very heavily, too. Right. So we're very focused on the application layer.
Services are all over the place. They're in the cloud, they're in DC, they're in multiple clouds. So I think organizations are trying to first get a grip on the attack surface, figure out how to protect that attack surface as best they can and have the redundancy to scale, but without the protection, no matter how much scalability you've got, you'll still- This is like a, like a high wire act.
I mean, in, in a sense, there's so much going on there. The upside is incredible. Right.
And we should probably point out that the upside for the most part is, is what these companies are, are looking at, in terms of efficiency, profitability, et cetera. But there's always that kind of a threat lingering in the background that they have to be aware of, so. You can see, organizations that get hit with a cyber attack that makes headlines.
You can see the immediate market cap effect, which can take, you know- And we're seeing more of those ... 12 to 24 months- Yeah ... and sometimes never get back to the position that they were at.
Uh- So there is that, that, that imminent threat. I mean, it's not, it's not a threat for everyone. It, it's not gonna happen to every company, but for, for e- each company this, that this does happen to, it, it sets an entire industry kind of on alarm, so.
Right. And I, and I think this is gonna be a story we're gonna see repeatedly over and over again. You always just wonder when it's gonna reach a point where there is like the defining events, and I'm not sure if we've reached that, that event yet.
I agree. I don't think we've reached an event that says, you know, there has to be some fundamental policy- Right ... change or something like that.
And better of good luck to that happening. May- maybe by the way, in cyber warfare, that has happened because there's a lot of very quick targeting of, targets on the ground- Yeah ... utilizing AI and stuff like that, but that's of course not in the headlines.
Yeah. So I think AI has had a tremendous impact on warfare in general, just the speed at which everything is moving. It's in warfare.
And it's only gonna get quicker. Yeah. Um, and of course that translates into the enterprise space.
We see it already that, there are AI attacks being, identified and, the EU council is doing testing on, AI attacks and other governments are checking how they're gonna respond to this. So this is clear that this is happening now. Right.
It's not the future. Right. It's happening now.
It's interesting. Well, Matthew, this was a fascinating discussion. Um, I'm glad you shared your expertise with us.
Thank you. And let us know what's going on because things are changing faster than we could ever imagine, and, it's gonna make for very interesting times. I've never, I mean, I've never seen anything in the tech industry like what's happening with AI and especially on this side of things.
Right. So, thanks again for your time, and, um- Thank you, John ... it was nice meeting you.
Good meeting you. And, we'll be back with more interviews later today, day one of RSAC.