Eyal Benishti, IRONSCALES | RSA Conference 2023
The rise of AI-chatbots brings both excitement and fear. The use of accessible large language models can be leveraged to find speed and scale with many tasks, like writing. But security experts warn that the same models can be weaponized by bad actors to execute phishing campaigns. This is why security awareness training is of utmost importance for end users to detect these sophisticated phishing emails missed by most email security technologies used today. Using a combination of AI-based security technology and human insights is necessary to effectively combat the ever-evolving tactics of cybercriminals.
Transcript
This is texturung TV. Hello and welcome. We are here streaming live from rsac 2023.
It is awesome to be back with you here at Moscone West. We will be here all week Monday through Thursday streaming these awesome conversations live right now. I am here with a all the Nishi.
He is the CEO of iron scales. Welcome. It's great to see you.
We're kicking this off together and I yeah cool. So tell me a little bit about your company iron scales what you do and what you are. What you're doing here at rsac?
So I was scared these about nine years old started back in Tel Aviv with the mission to help organization fight email fishing, and it was Security in general. we started the company with the mission to put human in the center of cyber security because there was so many kind of like different. Solution and vendors out there really focusing only on the technical element and the technical aspects of fighting fishing and fighting cyber in general that we decided that we want to get a more hybrid kind of Blended solution that brings human and Ai and put it in the same platform in an integrated way to provide with a better solution to the fishing problem.
Okay? And the human element is the weakest link, right? You can have all the technology and all of the cool, you know, shiny new things and Someone clicks on a link and it's all over.
So how do you meld that human the human Insight with the technological aspects of it? So the way we approach it is and the kind of the mission that we took on ourself is how you take something that is traditionally being considered as like you said the weakest link and how do we make it an active integral part in the in the company security posture? And the idea was that instead of kind of looking at people as the ones that normally click on fishing or open attachment and stuff like that that can be actually the ones that can detect and report back to the organization on the stuff that is sleeping through the current defenses.
I think that everyone knows that there is no perfect solution out there. We will never be able to build something that can just magically stop all the fishing email like that again, so was very important for us to to build this player to educate this layer to give them. Heel set and the mindset to report back to the organization when they see something suspicious and from that point on we know how to take it and we know what to do with it with the human insights that you just mentioned.
We know how to collect it. We know how to analyze it. We know how to respond to threats based on what the reporting back to us.
And we're doing all of these kind of things in real time in a self-learning kind of manner world. The machine is learning from the human but the machine is all also helping the human or augmenting The Human Experience in order to provide human with better kind of insights in order to make better decisions. Right?
It's you're taking the weakest link and turning it into the first line of defense. Almost With a Little Help. Yeah with a little help, right?
Um, there's a lot of talk throughout the industry about generative Ai and chat GPT is on everyone's lips. And is that the kind of thing that that you're talking about here when you say self learning and self That that augmentation. Yeah, I think should you PT and generative Ai and generally something that the industry still trying to web the hand around.
Yeah. We understand that like, you know and even before And GPT, we saw a tremendous kind of shift in the in the threat landscape form female fishing being this bad link or Ben attachment to animal fishing being these fake invoice. Fake wire requests.
Go buy me these go do that. So I like to say that they kind of shifted from tank to hack the the user and the end point of the user to hack the business process and trying to social engineer people to do something that they're not supposed to do obviously with AI and you know, the potential AGI that is coming. Everything will just be on steroids like, you know, that actors will just be able to create agents and say hey go and fish this company for you go and do research on all their employees on the internet all the social media and come up with the best fishing kind of scenario for each individual in organization.
So it's not just going to increase the risk the potential is because believe it or not yet can can ride brilliant fishing emails. Right? No grandma and gonna be right no more.
Jillian kind of scam type of typos and stuff like that. But the volume. The volume is going to create a serious operational problem to to security teams because they will not be able to attend to each and one of the fishing emails that are being detected or reported and therefore the importance of basically leveraging AI on the defensive side right to the point that you know, I believe that in 2024.
We see a lot of AI versus AI type of dog fights out there. Yeah and still the human element will be there to detect stop with all the stuff that AI is missing, but hopefully we'll be able to match the volume of the offenders by applying the right type of AI on the defensive side. Yeah.
It's it's an arms race right on both sides and each is escalating and it's It's incredible. We need to keep the cemetery because it can easily turn into an asymmetic kind of graduation. Well, the threat actors are armed with a lot of again free ai-based agent that can just you know, go in and do this stuff right?
That's where you guys come in exactly. So, um, another thing that's been in the news lately are and I believe you touched on this a little bit was business email compromise attacks BEC and I know iron scales has some new stuff coming out specifically to counter BEC attacks. Do you want to talk about that a little bit and I think that would be again one of the interesting thing is that what is malicious about BC's not necessarily the content.
It's not the legal attachment but it's the intend like no someone is trying to convince someone inside organization to do something is not supposed right? So when there is no clear what we call in our industry indication of compromise when I look at an incoming email and the IP seems Legit and there is no bad link or better judgment know what in most of the cases there are no links and attachment in rice ml but it's just someone asking someone to do something then it's a whole different ballgame, then it's all kind of into the point that can we understand intent can we understand the individual and how to protect the individual do we know? It's history?
It's communication habits communication studies social kind of interactions. And can we extrapolate it on the company level We Now understand who's this company is working with who they're penguin with to when and answer all these kind of contextual questions that are not necessarily that are very different from the questions that we use to ask ourselves yesterday, which is is listening to known to be bad. Always this attachments, right?
It's a very very different situation. This is why BC has become such a big problem for organization because traditional solution Legacy Solutions were not designed to stop this type of attack. Yeah, and in you set of Technologies like ion skills will build in order to basically figure be able to answer.
Maybe this email is not bad. But this is this email is actually a good email right the context of this mailbox or the context of this organization and it's a very interesting problem to solve very challenging problem to solve and we are enjoying solving it awesome. Awesome.
And you know, it's it always seems to me that it's it's a little better to err on the side of caution. So, you know, maybe you get at first while the technology is learning you get a few more cautious like all right, maybe take a step back and and check this a little more carefully, but then as it learns You know, then it gets faster and more more actually out of me. What we was for safe.
There is doubt there is no doubt. So we are taking this kind of a mole right extreme kind of approaches as you mentioned and if we are not one percent sure that it emails should stay in the in the inbox at the very least. We will flag it to the user because we really believe in the user and we really believe that if we talk to a user in a human reader in a human kinds of in alignment kind of film right there will be able to to help us stop that text or if an email landed in your inbox and we're not 100% sure that it's bad but we are not 100% sure that it's good.
We'll tell you how and you know, there is something fishy about it. Well, not sure enough like, you know, our conviction level is not high enough to Move it away from your for your for your inbox. But please take a look at this and that like, you know, like we know that you're getting emails from my albaneshti every Thursday and you're walking with ion skills, but this time it's coming from A yard benishti with a typo and it's coming from a Gmail.
We don't associate design together. So again, we will take this cars behavioral elements and what we know about you and and our communication in order to ask you to provide some more insights on this type of communication. So the machine can learn whether it should last it or not in the future.
Okay. Awesome. Let's see, so.
What are you most looking forward to here at rscc are there? You know other connections that you're trying to make or, you know Keynotes that you're looking forward to. Are you do you have a session here?
Yeah, we have a booth we have no no the next point to five to one five. Awesome. What a most excited about in United States in general is the opportunity to meet with existing and potential future customer to talk about the pain points to help educate them about, you know.
Generally speaking. We know a lot about animal security and speaking with cisos or other Security Experts and sharing with them. Like, you know what we see that always very curious about.
Yeah. What do you see? What other time you go?
What how do you approach this? And that this is where we learn a lot and we learn from them and believe it or not tell they're the ones that are fighting this fight every day on many different font. We are very focused on email security, but always helping us to broaden our Horizons.
It's conversations with CIS that can help us decide that we want to move from expand from email to collaboration tools protection. So we're adding Microsoft teams and we're adding stack protection as well. Awesome.
So it's conversation like that with people like that. I really help us kind of shape the future of the company the whole of the product and Help help them secure their environments. Fantastic.
All right. Well, thank you so much for joining us here today folks. We've got tons of great conversations all day Monday through Thursday here at rsac 2023.
Stay tuned. I'm Sharon Florentine. Thank you so much.
I all is great to talk to you. I'm here. Yeah, have a gay day.
You too.





