Understanding AI-Driven Security Risks to Businesses – Techstrong AI Podcast EP52
In this episode Amanda Razani speaks with Rod Schultz, CEO of Bolster, about AI-driven security risks, the impact of brand impersonations and phishing, and where business leaders stand in their ability to detect attacks and eliminate them.
Transcript
Hello and welcome to the Techstrong AI Podcast. I'm Amanda Ani and I'm excited to be here today with Rod Schultz. He is the CEO of bolster.
How are you doing today? I'm Great, Amanda. How are you?
Doing well. Can you share a little bit about bolster? What services do you provide?
Absolutely. So the best way to think about Bolster is we're an attack surface management platform that really focuses on protecting, um, an enterprise's brand, um, enterprise's customers, and the assets under management. So we really focus a lot on, on B2C, so, um, enterprises that sell to the consumer where that, um, image likeness, um, brand of the, of the enterprises being attacked, um, and being utilized for fraudulent, um, and illegal use to compromise customers and, and compromise the assets that are under management of that enterprise.
So our topic for today is understanding AI driven security risks to businesses, including the impact of brand impersonations and phishing, and where we stand in our ability to detect attacks and eliminate them. So can you, uh, explain a little bit more about what are some of those attacks that we should be concerned about, and we'll go from there. Sure.
I think one of the key issues, I mean, is that, you know, AI is this really interesting, you know, tailwind for efficiency and a tailwind for advancement. But, but those still same tailwinds are kind of being, um, leveraged and harnessed by, you know, the industrial fraud complex. And what we're seeing is an ability to fast follow copy and then trick.
And so traditionally what happens is when you know someone receives, um, some sort of information, uh, from, you know, a brand that they're familiar with, the automatic assumption is that it's trusted and these fraud, you know, enterprises are capitalizing on that information asymmetry, and they're going right after it. So what they're doing is they're effectively serving behind the ad and the marketing spend from large enterprises. And what happens is those enterprises spend a lot of money to capture customers and to send a message and market to those customers.
And fraudsters are coming in and saying, Hey, listen, there's a lot of money that can be made if I can trick, you know, one of these people into believing that they're, they're interfacing with the brand when they're actually interfacing with me, someone who's trying to fish them. And this results in a lot of financial loss. It results, um, in compromised accounts and it results in a lack of trust and confidence in the brand itself.
Yeah. Even though it wasn't actually the company. So that's definitely a big concern.
So where should business leaders start, uh, to avoid this problem? It's a really interesting problem because the more effort you put into curating your brand and making it large, the larger your attack surface is. So we talk about this as the shadow attack surface, and it's really a function of the size of your brand or the, like, the value of the assets that you have under management.
And because you have a large brand or a lot of assets under management, me as an attacker, that's a great target for me. And what you need to start thinking about is, listen, how do I manage down that risk? What kind of steps can I do periodically that will scale up and down in, in proportion to those attacks that come, um, in very, um, unpredictable ways and in unpredictable size, um, and magnitude.
So what we have at Bolster is we've created a platform that allows, um, a customer to leverage our defense mechanisms that actually go out and actually seek and destroy the infrastructure that hosts that the, that fraud, um, and then targets the customer with that fraud. So, so do business leaders have to basically, they can't just think about how to protect, they have to think about how to react if they come across risk. They absolutely.
And not just a question of protection, but how do you scale it? Because you might be fine for 4, 6, 8 weeks and then out of nowhere, you know, based upon seasonality as you're starting to approach a buying season, a holiday season, um, an end of fiscal quarter season, right. We start to see interesting patterns emerge.
Um, you just don't know when it's gonna come and how it's gonna come. So there's multiple vectors, there's fake websites, there's fake social impersonations, fake job postings. Um, we see all kinds of interesting and very sophisticated phishing scams that are really being run almost as if they're just an email campaign, right?
So it takes about two hours for the attacker to spin up a website in a corresponding phishing slash email campaign to then start to then send out hundreds of thousands of mails. Um, and it really only requires a small percentage of those to be successful and they start to then phish in and reel in a lot of, um, a lot of money. Wow, that is so fast.
That's kind of terrifying that it could be done so easily and quickly. Yeah, we're really surprised at the rates of creation and it's only getting faster. And so what used to take maybe eight to 10 hours, you know, maybe even a little bit longer, two or three years ago, has become incredibly fast.
And that's really the biggest challenge is you've now weaponized technology that was designed for good. And so over the last 20 years, we've seen a lot of advancements in ad tech and marketing tech through Marketo and Meta, uh, and Google, and a lot of ways of understanding who your customer is so that you can give them a better product and a better service. Those same techniques and technologies are being utilized by these attacking, um, kind of, uh, infrastructure people.
And they're just using the same things to then replay these concepts back at what we're used to seeing, but they twist them in a slight way and they turn them into a really, really nice attack vector for, for stealing, you know, money and, and iShare. Yes. And this technology is of course, rapidly advancing.
We have a a we're in the technological industry basically. So what advice do you have moving forward as this technology advances? My advice is that you, you're constantly gonna have to make a build versus buy decision.
Um, if you're running, you know, a a a brand or a fraud, you know, protection department. And I think the biggest challenge that we see is understanding how to scale, um, how to utilize the, the newest techniques, um, and trends, uh, with ai, the AI models, um, and the ability for those AI models to stay one step ahead of the attackers. Um, and then how do you start to remediate because there's your ability to understand what is happening and then the ability to, you know, take down that infrastructure.
Um, and so those two things need to, to operate, um, kind of in parallel with one another. And that is the, that's gonna be a problem that will never go away and it's not going to get easier based on one thing. And that thing is like, listen, people make mistakes where they're in a hurry never before in this attention based economy has our attention been under so much attack and they're leveraging, you know, your opportunity of saying, Hey, listen, I've only got 30 seconds to read my email really fast, or my text messages, I need to respond to these as quickly as possible so I can move on to the next thing.
And so the consumer is not getting smarter, they're, they're getting more and more short on time and the education campaigns of like, see something, say something concept is just not working. Yeah. So let's talk about the, the regular people side of things.
So for users and for regular folks, how do they differentiate what's real and uh, what's a scam so that they're not so easily tricked? Do you have any advice? I think the advice, the first thing I would start to do is you need to immediately look at like, what I call like the anchor points of either the website or the anchor points of the email.
And those anchor points are really what is the URL, you know, have I misspelled it? Is it off by, you know, by a letter? Um, does it look correct?
Is it asking you to do something really quickly? Is it trying to capitalize on a, on alarm or some sort of fear because I've gone to it forcing me to not think properly through, um, or checkpoint through, you know, what I know to do properly. Um, and that comes generally in the form of either a fake website, um, a fake email or a fake social posting that then drives me to a location where the, where the scam of cars.
Okay. Well if there was one key takeaway you could leave our audience with today, what would that be? My takeaway would be that the consumer needs to start asking these large brands for the, for their protection.
And I think moving the responsibility off to the consumer to get smarter, um, and to be up to speed on the latest and greatest attack techniques is not going to work and it's not going to scale. So my ask is that the consumer starts to ask their brands, um, to not simply send them to the consumer, you know, better business bureau, you know, for advice on what to do, but to actively, uh, remediate and start protecting them because the fraud that is perpetrated, um, on these consumers should be owned by the brand. Um, it should not be owned by the consumer.
Alright, well thank you so much for coming on the show and sharing your thoughts with us today. So much great to be here. All right.
And thank you to our audience. Stay tuned. There's more.