Your Cyber Training Is Already Outdated — Here’s Why
Lee Rossey is the CTO – co -founder of SimSpace which was spun out of MIT Lincoln Labs over 10 years ago. They are one of the premier “cyber ranges” in the market. Lee talks to us about how AI is changing the mission in terms of training your team how to respond to threats and and cyber readiness. Much of the playbook needs to be rewritten and SimSpace is helping their clients navigate these new scenarios
Transcript
Hey everyone. Welcome back here to Tech Trunk tv. My next guest is Lee Rossey.
Lee is the co-founder and CTO of a company called Sim Space. And let's welcome him. Hey Lee, welcome.
Thanks for coming on Textron tv. Uh, pleasure to be here. So Lee, we're gonna talk about sim space, we're gonna talk about AI and cybersecurity and all that.
But let's start off talking about Lee. Give us a sense of, uh, how you got here. Yeah, happy to, of course.
The, um, yeah, so, um, well I started probably like a few of us old guys 25, 30 years ago doing cybersecurity. I, um, in 2000, I joined a place called MIT Lincoln Laboratory, and MIT Lincoln Lab is one national lab building tech for, um, for the government, a national security apparatus, so intelligence, community, military and all that. And when I was at the lab, it was all about creating test beds and ranges and how do I test and evaluate cybersecurity.
We didn't call it cybersecurity at the time, it was No, we called it in, It was all the other stuff. But this general problem was the same, is how do I test, evaluate, figure out what capabilities to develop for cybersecurity in that space. And the lab as a national security is all about, hey, not just cyber, but cyber with that overlap on mission systems, defending radars and air defense and missile defense and space control.
So it's always about tech rigor. It was about measurements, it was about evaluations and how do we actually create the most effective cybersecurity solutions, um, as possible. That, that's my quick answer for the 15 years at the national lab.
And then when we were there, we spun out and created SIM based a company. So actually it was a wonderful time. I, I learned a lot.
We did a lot with the, uh, with the US government, but then the question became cyber is, is broader than just the national security. It's impacting banks, it's impacting cities, it's impacting our way of living. And we spun out the company to be able to help out the broader, the broader us.
Um, so, so that's how we started 2015 and we created the company. Um, let me pause there for a quick second so I'm not monologuing Sure. Hey, that's a great story.
You know, I'm trying to think who I knew they spun out a company outta Lincoln and um, uh, Well, BitSight is another one. So Steven Boyer, uh, another Boston based company. No, all about, uh, risk and cyber insurance.
Yeah, No, I know BitSight. No, this was like a personal friend of mine and I just, you know, you you're doing this so long that you start, it all runs into it. But yeah, they, I mean, look, the Lincoln Labs turned out some amazing, amazing technology, right?
You know, that's part of you, you talk about government investment and is it worth it? And pure r and d and stuff like that. Yeah.
Those labs were worth every penny They invested in 'em. Man, You know what? I talked to the leadership and we talk about tech transition and what does it mean to do tech transition for some of the labs?
It's one thing you do patents and do technology, but it started when I was at the lab and it was true when I left. It's about spinning out the people, the whole apparatus, which is, yes, you can spin out the tech, but there's an element of everybody that goes with it. The people that know the domain, know the space, have the passion.
Yeah. So I remember when I joined the lab, it was optical networking at the time. In 2000 and Uhhuh, the whole group spun out.
It was 50, 60 people that were created Sycamore Networks and Photon X. Yes. And yes, it's the technology, but it was literally the whole group.
So when we spun out, it was the whole team. And of course there was Hutch, the co-founder and a lot of experience in cyber command. And we created a company with the foundation of the people knowing the space, the technology, and then marrying it up to the problem, which was, which was really exciting.
I love it. I love it. And you know, there's a lesson out there, folks pay attention, Lee, let's talk sim space.
Yeah. So 2015 is what you said? Yep, yep.
So another overnight sensation, you know, not in 10 years. I know how that goes. I, I started this company in 20, well, technically 2013, but we first published 2014.
But I, I've been doing, you know, startups for 30 plus years. Um, you talked about kind of where the inspiration came from, where the passion came from. Yeah.
But you know, there's, there's been a lot of water under the bridge from 2015 to today. And maybe the biggest boat under there of course is ai, right? AI seems to be changing everything or it has the potential to change everything.
Yeah. Talk to us about AI and, and how it's kind of changing or, or diverting or, or, you know, influencing the mission of sim space. Yeah, no, wonderful question.
And let me maybe give a two minute on or a minute on what is sim space and then the impact for that. So fundamentally, what we are providing technology wise, it's a cyber range. A cyber range is a very realistic environment to allow you to train operators, test technology, develop it, validate it.
So it's effectively a proving ground. How do I provide a super realistic environment that matches, say, a bank or a power company or a military. In that environment, I can develop, uh, new technologies, new cybersecurity solutions, make sure that they work in a beautiful dev test setup so I can really support technology and then, um, allow operators, allow individuals, soc members, team members to train with the technology and then, uh, train as a team.
So from a training standpoint, how do I push people to failure like attacks and realism, but in a safe environment? So from a training, push the tech and push the people to the breaking point. So you can learn, so you can improve, you know what it's like.
It's, um, you wanna, you wanna experience failure many, many times So that in a, in a, in a safe setup in a range before you actually go through the real world to do that. So that's from a training and a testing standpoint, AI makes it interesting because now, you know, we always have these technology evolution cycles we've gone through from mainframes to client server to cloud, and now hitting the ai and the big push there is things are moving a lot faster. It's automating a lot of these day-to-day tasks for the SOX and the others.
And, and there is a transformation going on. Every large enterprise is trying to figure out how does this apply to what we're doing in terms of tech stack? And then also how do we actually get into the, the team aspect of it from a, from a retooling and a and adapting for the team members.
Let me pause there for a second because I wanna dive into a lot more of it, but, um, let me, let me, let me pause for a second for any. Sure. So look, the concept of a cyber range, yeah, I don't think that's foreign, you know, for our security friends out there, you, you know, you've AppSec I think they get what a cyber range is.
Some are by non-security people. Yeah. Think of it as just a huge testing environment where you can set up, you know, very elaborate, complicated, sophisticated type of environments to, to test your security on.
I mean, and this is, you know, cyber ranges are not necessarily new. No. Right.
We've had them for a while, right. Always Right. Testing.
But what, what is new, I think is the, uh, the, the, the pressure, the, the focus, you know, AI is, is making us sharpen our aim, if you will. Yeah. Shortening the cycle of Yeah.
Of, you know, when we discover things to when we gotta do things, it's, it's bringing more of a sense of urgency, let's say It is. But it's also becoming, um, I'll call it going from a nice to have to a must have. And let me explain it.
So to your point, we've been doing cyber arrange, or I've been doing cyber arranger for 25 years. It just happened to be for the government and for developing and testing tools commercially. People think of cyber as more for training, but that's more recent commercial angle on it.
Yes. Um, the rea, the reason why I think the ranges are really important for AI and AgTech is they need to be able to train, they need to be able to train on an environment they need to be able to learn. So how do you create the data sets?
How do you create the environment to allow the agent to be able to understand all kinds of different types of networks, the diversity that's in them, the different types of attacks. So they need to train on an environment, train on attacks, be able to figure out, am I making the right decision or the wrong decision? And being able to actually allow the developers to be like, Hey, as I'm developing this new tech, how do I make sure that it is doing the job equivalent to a human?
And we're not quite there, but it's getting a lot better to be able to do that. So the range we think of it as, again, it's an AI proving grounds. How do I put new tech in there to prove that it's effective, but also is it safe?
Like any new technology, it's interesting, whether it's cloud or crypto and all that, there's always the pluses. But then the question is, what about the negatives? What are the potential risks that I may have with, um, with AI solutions?
So how do I prove that the AI cannot be co-opted, cannot be deceived, cannot be, uh, manipulated to be able to do that. So you wanna be able to prove that out for that. But to your point, things are moving fast.
AI is accelerating the rate of the attacks. It is accelerating the rate, uh, people are doing, but it's also got the benefits from a defensive side is can leverage it to be able to sift through more data, understand what is happening, to be able to accelerate my response to an accelerating attack, uh, surface or an attacks attack. Attacks.
I get it. I get it. And, and you're right.
And, and you know, unfortunately we haven't had enough experience with a lot of these AI scenarios, right? And, and so being able to train on a cyber range is, is um, I mean it's a resource a, a badly needed resource, let's call it that, right? Because we just don't have the, we don't have a written book necessarily on this stuff yet.
No, and I heard a great quote from somebody, any enterprise who's gonna be leveraging AI is gonna get disrupted. So there is a disruptive element to AI in that. And that is not just the people side, it is the process.
You need to be willing to change your processes, how you do business, it's gonna change your tech stack. And of course, it's also gonna have to allow the operators to be disrupted, not replaced. In my mind.
We talk about a lot of these. It's gonna eliminate a lot of tier one, tier two SOC positions. I think people need to embrace, to some degree the changes coming with ai, even from a defensive side to leverage it to be able to actually go through and, and do the job a little bit faster and all that.
But, but it is transforming the way enterprises are actually, uh, operating. And along with that is how do I now train and work with alongside AI defensive solutions, ag, agentic and AI solutions. So operators coexisting working side by side with new technologies, AI based defending against potentially accelerating and more vicious attack scenarios.
So AI for offensive purposes, being targeted enterprises. And so, so yes, it is, it is changing how the defense is working in terms of the tools and the people, but it's also working to counter potentially an accelerating threat. Absolutely.
Lee, if you don't mind, I want to turn back to sim space a little bit. Yeah. 'cause we're running low on time for people out there saying, Hey, this is just what we're looking for, right?
We need, we need to get our people up to speed. We need to, you know, you can't fight or defend against something you don't even understand. We need to understand, we need to, you know, get our response battle Yeah.
Plans in order. What's the best way to engage sim space? Um, well go to the website.
If you go to the website, you can look at the URL, there's a link over there to be able to contact us and of course want to be able to engage and work through. com is, uh, is a way to get to us. But I would like to make the point, I think when we talk to a lot of our enterprise customers, the first question is even is, which AI is right for me?
How do I prove and find which the right solution is? How do I actually go through this pre-production before you deploy it for anything as disruptive? How do I even make sure that it is the right tech for me and in the right area?
And not only do I prove that it's effective, but how do I make sure it's safe and not bringing me down the railroad? And then of course, I wanna be able to train with whatever you've chosen, but I think there's an element of bill versus buy. What am I building myself versus what am I buying?
And then there's an element of how do I train my staff to leverage it? But there's a series of questions before to figure out what tech is appropriate and in what areas for a particular enterprise. Because you don't wanna rule something out that's gonna make decision on your behalf that you don't fully understand of what it's doing and how it applies to, uh, your shop.
But the website is the quick answer. Absolutely. Lee, I want to, um, you know, you gave, how do you choose what's the right AI or are they kind of interchangeable at some level?
Right? We, right now, we're still at the beginning of this whole journey. We are.
So we, we, you know, we have the frontier model. So do you want to use Claude? Do you want to use chat?
GPT? Yeah, you want to use Gemini, but really I think what we're gonna see going forward is a new generation of models. You wanna call 'em small language models, you know, based on rag, based on a lot of different things.
But it's, what we're gonna find is you don't need these big frontier models for a lot of the tasks that we're going to use AI for. I, I, so this is where let the vendors come up with the base way, the best ways to be able to solve the problem, whether it's big, small, whatever the models are. Uh, I look at it more as the solution is being provided by whomever it is.
Um, I think it's gonna be interesting to be able to see is they're all gonna come up with pretty decent generic models trained on broad enterprises and broad sets of data. That's gonna be awesome. I think the more interesting is how do you then tailor and retrain those models for the specific enterprises in terms of their network, their processes, their data and all that.
So, generic models wonderful for the wide set of attacks, but then how do I choose a technology that can actually train and understand on the enterprise specific businesses model architecture to be much more, um, suited for that particular setup. So AI is great, but needs to be trained and tailored to the specific nuances of that enterprise. Just like every human operator, they, they know their business, they know which ips are interesting, they know what their processes are.
Um, that's what you want these models to train on to get more specific to the enterprise, uh, itself. I love it. Hey Lee, I promise I'd get you outta here on time.
I'm going. Um, thank you very much for coming on and getting us a little smart here today and telling us about sim space. Congratulations on 10 plus years building a great company.
Come back, keep us posted. Happy to chat with you about this anytime. Well, thank you so much.
I really appreciate the time. And again, it's wonderful chatting. Thank you so much.
Alrighty. Lee Rossey, co-founder CTO of sim space here on Textron tv. We're gonna take a break.
We'll be back with more. Stay tuned.