Bending the Risk Curve – The Inevitability Curve EP17
Chris Blask and Mike Dugent discuss the multifaceted topic of risk in the realm of technology, particularly focusing on operational technology (OT) and the intersection of artificial intelligence (AI) with cybersecurity. They reflect on their initial friendship and collaborations, before diving into the challenges of quantifying and managing risk, especially in light of increasingly interconnected systems.
Mike shares insights from his extensive experience in cybersecurity for operational technology and how these areas are becoming more critical at the corporate level. The conversation touches on the evolving role of AI in managing risk and enhancing situational awareness across various industries, including supply chain security. Their optimism about technological advancements is framed around the benefits of automation and AI, foreseeing a future where technology can significantly improve risk management, ultimately aiding defenders in cybersecurity.
Transcript
This is Textron tv. Hello and welcome to another episode of the Inevitability Curve. My name is Chris Blak and I will once again be your host.
And with me today is a good friend, Mike Dugin. Hello, Mike. How are you?
I'm doing fantastic, Chris. How are you? I am good.
There is, I don't know if I told, we had actually had a, a work call a week or two ago. I dunno if I mentioned this to you, but, uh, uh, before I left the boat center in Florida, I had a, a drink of the, uh, the bourbon. You, you left on board.
Nice. Nice. So that is appreciated.
Where in the world are you? I am based in Lugano, Switzerland. So we could tell from the accent originally from the Philadelphia area, but six years here.
Now You stole my joke. I was gonna say, I can tell from the accent you're from Switzerland, but I got preempted every time. Right.
So six years, I, in fact, I remember, I think we had met at a DHS event somewhere, the ICS Joint Working group. Yeah. It was weird actually.
We met, uh, not actually even at the event itself. It was, uh, we met at Detroit Airport or the Detroit Airport Marriott or something like that, sitting at a bar. Do you remember that?
Oh my God, yes. Yes, that's right. Yeah.
That, that's that small world thing. We think it's, you know, you, you know, when you start narrowing it down, how many people would actually likely be at that. Yeah.
It's not that unusual, but it's still, it is still a thing. Yeah, Right. This is way back.
This is probably, you know, I was working for Industrial Defender at the time, so this is probably 20 12, 20 13, somewhere in there. Yeah, Yeah. Certainly before you moved that, that was your first movie.
I don't think you'd even done a whole lot of international travel at the time. So since then, you know, the world has, has, Yeah, no, at the time I was, uh, I was really focused sales engineering United States. Um, uh, I started working more globally a few years after that.
Uh, and then I joined the zombie networks in 2017 and moved here in 2019. So, Neat world. It's been a While.
Well, and hand roll underwear, you know, from my, you know, like I, I was in Switzerland, Moores back in the day and ran out of, you know, uh, uh, fruit of Loos and in the, uh, hotel, they, they sold hand roll underwear, which I realized is one of the great gifts to life and mankind. So, uh, thank you. And your, your computers.
I have never seen that, but that is a fun story. Oh, yeah. Hand roll boxers.
I mean, seriously, not to get too, too dark into, but as we said in the, in the green room, we can, we might go as far as you, you could imagine on this. And, and we're talking about risks that today, right. Which is a great general topic, and, uh, we can apply it to all sorts of things.
And you and I have different career, you know, our specific career paths in this space, and we'll discuss that, that throughout this, but it's this wonderfully generalistic con concept that we all deal with, right. And it, and as a saved, just, just a moment ago in the green room, the, I literally just came out of a working group meeting where we're talking about supply chain security, and we finished up some working groups. We're looking at the next working groups and someone bring up, you know, how do we bring in risk analysis all of the, you know, all of this.
And I, I jokingly say, you know, my, my brain short circus because oh, hold my coffee. You know, what does that even mean? How do we quantify that?
How, how do we put that in scope? And, you know, to, to perhaps get us started, you know, in the look at the way back machine, how have we done that, you know, since prime evil, you know, times, you know, you have the eye spot helps you lower your risk because you can see a predator, you know, above you, between you and the light source. You know, and in human evolution, obviously, you know, that, that, you know, we've been, our ancestors, you know, have been really good at figuring out risk by definition, having li lived long enough to give rise to us and all of our iterations and technology, you know, for all that, you know, what you and I have seen in our careers and what happened before that we've apparently done well enough.
We're here, we're here, how the heck did we get here? Right? You have, what's your, what are your thoughts, you know, in your, in your career or wherever you wanna start with looking back, you know, actually putting quantification to risk in a practical way?
Yeah. I think, you know, I've, I've been blessed to have spent, uh, pretty much the entirety of my career in cybersecurity for operational technology, iot, that space. I really didn't spend a lot of time on the IT side, right?
Um, and when I started this is, this is prest stucks net. This is 2007, 2008 timeframe. Um, you know, risk wasn't something that was, that was even in the, you know, the, the, the top of mind.
You're thinking about ot, iot, cybersecurity, and iot really wasn't even a thing at that time. It was really just ot. Um, you know, at that point we're talking about IT, cyber risk.
Um, the, the OT environments were, you know, completely segmented from that. So I, you know, spent a lot of time, I, you know, I did technical work, firewall engineering, uh, intrusion detection analysis on process control networks at the time. Most of them were, you know, pretending to be air gap.
They were never really that air gap, but, um, you know, segmented well enough, right? That they were kind of kept outta that framework. And what I've enjoyed over my time working in this industry is, is that evolution now is, you know, you start to see the, the concepts of operational technology, cybersecurity, and the concepts of iot, cybersecurity start to get up to the board level.
Um, they're, you know, they're starting to be accounted for in those overall risk frameworks that organizations are dealing with. And, um, you know, it brings a lot of questions. It brings questions around what are we doing from a connectivity and a segmentation perspective?
Uh, are the, you know, what are we doing from a, you know, how, how, what's the life cycle of bringing these devices in? Are we putting effort into, um, you know, checking where they come from, you know, what, how they can communicate, what they can communicate with? And we're seeing a lot of these questions start to get, to get askeded up at the board level and working its way down to the executive team.
And, you know, I've really enjoyed being involved in that, uh, that process of, okay, we, we need to account for the potential outcomes of, uh, it, it doesn't have to be cyber threat related, right? But the potential outcomes of, um, you know, if something goes wrong with one of these devices, how does it impact the, the overall risk of an organization? And, um, you know, now that I've been four or five years focused, you know, more on the, the IT organizational side of operational technology and IT devices, building management systems, all the, you know, tangential devices connected to building management systems, you know, it's, it's really something that's be, that's being looked at everywhere, that's being looked at everywhere.
And it's, it's been an interesting progression. Well, I'm glad you, you glad brought in ot, the operational technology side of this, because I've appreciated that as well, that, you know, throughout my career. Because in the IT space, we go, oh my God, someone could, okay, let's be clear.
What steal my information, you know, send an email that looks like it came from me as opposed to the OT world where, oh my God, someone could tell us all literally, right. You know, like, open all the flood gates or close the flood gates or whatever made the damn break or turn the lights off or, and, and, and, and enact, right? You know, one, one of my presentations in all these years, oh, I got blank on the names.
Uh, I'm sorry, I have to come back to it. Uh, but, but it was, but it was, it was, uh, somebody went amongst us, had gotten the job as the CISO at a big rail railroad, and the requirements going in was that you will give me these things and I would get physical access to a locomotive and access to all these things and basically turn my friends loose on it. And they put together, uh, what in the presentation they gave was called the hillbilly barbecue, where they hacked the, the train scheduling system to put together train cars with all the contents they wanted, and they couldn't get a beer car, but they couldn't get wine cars.
Right. You know, apparently, you know, it's like, uh, so wine and sub combustibles, right? You know, and beef and various other things you need to barbecue and then hack the, the, uh, locomotive itself so you can take control and make it go too fast around a corn corner through this one actual tunnel, um, to roll it over on the far side and pile it all up and, and actually create a barbecue.
Um, and you can do that in ot, right? That's an actual thing. Sorry.
And that, you know, in, in the theme of looking back, and it's why I always liked ot. I like OT by its own self, but with it, people explaining, look, we've been doing this for a long time, you know, where standards and guilds come from and so forth. That's from the people who built infrastructure several a thousand years ago, because not the first ones, but the ones who came later.
Um, because when the famine or the flutter, whatever happened, if whoever built that first infrastructure, they were killed by the survivors, right? You know, they were like, and you kind of explain about weather cycles and so forth, you know, as far as everybody knows you're the one who made the thing that, you know, was supposed to feed or water or keep us safe, and it killed us all. Um, so we literally look back through human history and we see these guilds and so forth and, and not, not lit, not even just in our standards, but in our popular fiction.
Like, you go, hi, ho, hi. Go. You know, off, off to work we go, because I'm not going to build, I'm not going to agree to the, the, the retirement of the time to build a 10,000 foot tower out of Lego block blocks, because you may as well kill me now.
You know, I can't let anybody, any of my peers say that they'll do it, either. They'll kill all of us, right? Except OT takes risk and makes it personal because it's either the risk of, you know, the, the bridge collapses, or they built the bridge, it collapsed really, really angry at me.
It makes people thoughtful. So we start putting 'em together, processes and programs, and it's, it's really, I, sorry, I'm taking that one all over the, the landscape, but it's, you know, in ot, again, it just feels so new. Oh, we're getting, we're creating all these new things.
I like, you know, saying, have we done this before? And risk you, ot, we talk about safety, right? The risk is, you know, the, the safety will be bad and you hurt people.
And the risk to the, the motivating risk to, to the people responsible, even if they don't like people, is that things will happen to you, right? There is a risk to you, or the risk to your business in business terms. You know, your customers won't like you anymore.
You'll get sued, um, because you didn't have the same processes that mature industries just have. Um, so I, I dunno if I can even weave a question outta that myself, but, but, uh, but that it, that o OT IOT thing, right? It, it's, it expanded is as you like on that, that value of that in the IT world.
Yeah. And, and, and I, you know, I've seen a lot of efforts now and, and I haven't decided whether I like them or not, but the, you know, combining the concepts of OT and IOT and some other devices into this concept of cyber physical systems. But, um, you know, you kind of hit the nail on the head that, that the, you know, the operation of this type of technology has some type of impact on a physical process or a physical thing.
It's not, you know, something that's, that's predicated towards user, you know, interaction or user use. So, um, yeah, the risk is different. And, um, as we digitalize and the world's digitalizing very, very rapidly, um, you know, there's more and more of these devices that are, that are interacting with some type of physical process, uh, uh, across the board.
And, um, you know, quantifying how that impacts risk of any organization or even your personal day-to-day life is a, is an interesting challenge. Um, but it's, uh, it's, you know, growing very, very rapidly. Let's, that's part of saying take this into the present because, uh, yeah.
Um, again, you know, before this all started, uh, a couple, couple minutes ago, we were talking about AI and so forth. And, you know, the fact that I'm, I'm just, you know, I, I'm one of these people. I'm not really an early adopter, you know, I'm an early ponder.
I start thinking about things before people start using them. Sometimes I use it myself a little bit and stop, and I'll watch everybody else use them. And if they really stick around, I'll use it myself.
And I've installed chat GPT and iPhone a month and a half, two months ago, and now already I'm like, I can go to Google and type in three words that I really can't think of right now, or I can just hit voice to text and randomly speak poorly to this thing, and it'll come up with a pretty good summary. And there's that scale of ability in the present time. I'm, I'm trying to get into the present.
So we have that right now and, and things all across the entire secu security spectrum. You know, when I think about supply chain, I have this time to transparency problem. All of the information between me and every single point is there, you know, it'd be 17, you know, different organizations in my supply chain on a given op, uh, object, all the information is in their hands already, and all the relationships is already, are already codified in contracts and regulations.
And if I had the time, I could get any, any one of those pieces of information, I don't have the time. I'm not going to have the time. But with things like a ai, I suddenly have the time and I can just say, farm me all that thing and be done with it.
And I don't think we've got our heads around that yet. That's where we are right now. So at Nozomi right now, where, where you are day jobing these days and have, have been doing all sorts of, you know, neat things is a perfect example, right?
This isn't that situation while we're in a space that I've been obsessing with the last 15 or so years, right? You know, as we get more aware of our surroundings, the value of that awareness itself is the defense, or is the value and this acceleration of, you know, again, what we are currently calling AI changes our ability to, to understand what our risk is today. I mean, so how much does that change, like in current, last 12, 24, 36 months?
Yeah, I mean, I, I, what I love to think about, not just, it's almost like we have two, uh, converging, um, converging did a digital, uh, explosions, I guess you could say the same. You've got the, the artificial intelligence piece you keep touching on, right? We have all this capability now to, uh, to parse through massive amounts of data and drive context from it and, and, you know, drive efficiencies out of it.
Uh, while we are also seeing this process of digitalization with millions and billions of new devices that are collecting data and sending data and transmitting data, um, you know, creating more opportunities for artificial intelligence to be able to do some insanely interesting things in our lives. You just separate the cybersecurity piece of it. Um, you know, I, I love, actually, we were talking about it a bit where we're on, do I call it a boat?
Chris? What, what do we call the, the, the marine living quarters? The terrains, the solar powered boats, the, the, that some of my backgrounds are on the boats now.
It's a snowbird thing. It's the, like the, the sparrow spec. CAPAs ano is, you know, my showing up in Canada, you know, is a sign of, uh, warming weathers, but yeah.
Down on the boats. Yeah. Do you remember, I mean, we were, we were drinking a beer and we were talking about, you know, if, if there's a, a fleet of these, uh, marine living quarters with sensors in the water, you know, we're, we're tracking water pollution, water movement, uh, uh, looking at marine life activity, you'd be looking at air quality and you're putting thousands or hundreds of thousands of those out there, getting those into an artificial intelligence, you know, processing capability.
You know, can you imagine the potential outcomes of that? Right. Um, so I'm thinking about it in a lot of ways, you know, in my, in my current role, both, you know, with my organization and in general, because I'm fascinated by this stuff of, you know, how that's applicable to, um, to risk how that's applicable to cybersecurity.
And, uh, you know, there's a lot of different ways to look at it. You know, I enjoy, uh, thinking about the potential challenges of taking AI to all of the, um, you know, the interesting, you know, the process data. You can go to all of the event logs and, you know, ease the concepts or ease the process that analysts take to find out, you know, look at the things that they need to respond to, or, you know, uh, if you think about it from a risk perspective, you know, I, I like to think of risk, and it helps that this is how we're looking at it from the zomi perspective of, you know, there's different ta, there's different stages of risk management.
There's the identification of risk, there's the evaluation of, uh, the steps that you can take to reduce risk. There's the, the actual mitigation process and an ongoing monitoring. And if you can simplify that risk identification process and simplify the process of, um, uh, prioritizing where you want to put your efforts from a mitigation perspective, you know, you can apply this to any one of these different challenges that we talked about.
Um, you know, artificial intelligence can help, you know, really ease the burden of reducing risk in our day-to-day lives in every fashion. But I think about it a lot from the cybersecurity perspective. Well, I'm glad to mention the boats, because, you know, I love that analogy because the way we get data right now, you know, as I've sailed these boats up and down the Florida coast through, you know, uh, thousands, you know, hundreds and thousands of miles of, of water that is, we read about all the time because the sea grass or the manatees or the, or the, you know, agricultural, agricultural runoff or whatever it is, and to be clear, when we get the data, you know, we get data.
Well, because somebody, some group of public and private organizations will decide we should have a data collection point at some point in this body of water. And it's, after some period of time usually been measured in months and years, somebody will spend some amount of money probably in tens of thousands of dollars, at least to put a buoy in, Right? Right.
And now we have a data point, right? You know, title, you know, title is something everybody can understand. You would think there'd be millions of title sensors around Miami and so forth.
No, there's like 12, right? You know, because it's just, you know, big and cumbersome and slow. And one of the pushbacks that I've gotten to this whole idea, uh, that you're describing Mike, is, is well, not, you know, too many, too much, right?
Every boat on the water, you know, is a data platform that's producing temperature and salinity. And I mean, oh my God, there's so much data. What do we do with it?
And my, my, this is a very inevitability curve thing, you know, I look out in the future and I think we will do these things. So the problem, any problem you can think of, we will have solved by that point. You know, and this is one of them.
So much data, everything we're talking about now, it's like, well, now, and it's funny in, you know, 'cause you and I, that's, that conversation is like, at least two years ago, right? And two years ago, yeah. Like four or five, six years.
And the beginning of that, people would just look at me like, I'm crazy. But on this one right here, I think right now, if you, if I frame the conversation, most people would just nodding and agree. It's like, oh yeah, that's not a problem at all.
You know, move up all that data. Of course you do. But it's, and it was smiling as you, as you were saying the last bit too, because it struck me that, that, and maybe this is a characteristic of when something becomes emergent, because the big problem I have right now is deciding what questions even to ask.
You know, my little, you know, AI friends, right? Because, and, and they're all questions that I wouldn't have asked before. I couldn't have asked them.
Maybe I could ask them, you know, it's like, you know, I, you know, there's, nobody's gonna answer them, and there's so many of them. But just in terms of casual conversation, you know, with, you know, this talking about risk, right? You know, with like, like you, like all of us, you know, we're not just faces on tv.
We're not just corporate creatures. We live in worlds. We know people, right?
And I, and among my friends and family and so forth is the entire range, including people who are, as we speak on the street living, that not doing well, very, very hard. And in, in, just in the last month or so, I have hooked up at least two of those folks with chat GPT, because if they have one thing, they have a phone. And for that sort of situation, when life is really hard, very moment by moment, having anyone to talk, just ask a question, just the, you know, just be able to say, how do I get to the, where is the, you know, and maybe the big difference.
And it's, it's, you know, you know the risks you take. Well, you know, as opposed to finding out there's some way you can get a bite to eat without committing a crime. They'll put you in jail where you do to get a bite to eat, put you're in jail again, right?
Um, that's the kind of benefits then risk analysis we're talking about at every scale, you know? And that sounds sort of melodramatic perhaps in a corporate context, but No, it's not. It's literally the same stuff.
Perfectly applicable. Yeah. So, so this, you know, so the question I, you know, sort of had in my head about that is, is yeah, this prompt engineering is not just how to, how to frame the questions.
That's important. But I think as decision makers or the, the kind of people who watch shows like this, it's a, it's, now we have to not ask a bunch of questions. 'cause there's an infinite number we could ask, and you get fascinating answers that would occupy all our time.
But we don't have time for that. You know, what solutions can I invisibility into right now? Right?
Is that too simplistic? No, I mean, I, I can think about this a lot of ways. You know, I, I, you know, back to your chat, GPT example, you know, some of the selfish ways that I use it is just how do I make my day-to-day life easier?
And, you know, think about it from the context of the, the type of work that I do. Okay, I, I have an RFPI need to respond to, and, you know, a lot of the data I would be responding is on the internet. I just put the questions in and chat GPT and I'll get answers out.
And of course I wanna rephrase it, things like that. Recommendation letters, emails, you know, I, I think the challenge I have is just being careful as to, you know, what information I'm putting in there, especially if you're logged into it, is gonna be used in some other way and use the train engine. And, you know, privacy concerns is something I'm really worried about.
But yeah, I do, I mean, I, I spend a lot of time thinking of ways to properly prompt, uh, an AI system in order to make my day-to-day life easier to get things accomplished, uh, in, in seconds or minutes that used to take me hours or days, right? Um, you know, I think when I think about, uh, using AI in the same context from a cyber perspective, going back to, you know, what I've been doing from a career perspective, uh, you know, we're, we like to suck up a lot of data around, um, you know, asset information, how they're communicating, who they're communicating with, um, you know, where each of those individual devices is set from a segmentation perspective, um, what devices they should be communicating with, what, you know, logs we might be gathering from that data. And there's some really cool, again, we gotta think about the ways to ask the questions and, you know, ways to drive how those questions are being asked.
But if you can say, um, you know, if every individual one of those, um, you know, we could say A-A-A-P-L-C, we know who should be communicating with. There should be one master station that's controlling that, and then there's everything underneath of it that it should be communicating with. Then specific protocols and specific function codes within those protocols.
And if there's anything outside of that, you know, you can, you can really start to make an investigation, or if you've got A-A-C-C-T-V camera somewhere, uh, that is, uh, you know, typically only supposed to be communicating with, you know, wherever's controlling that camera over, it's sending the video feed and it starts communicating with a billing system or a phish tank. You know, that's maybe not something that's easy to pinpoint in the logs, but that's something that AI can, you know, really pick up and say, let's mitigate that. Or even, you know, in a simp in a much simpler fashion, if you have every little piece of asset data and full software bill of materials and hardware, bill of materials, and, uh, you know, something's being actively, you know, exploited or some new vulnerability and, uh, that's been discovered in any of that, and you can just, you don't have to type anything.
If it's an automated process to say you have, you know, 300 servers that are running this piece of software, that there's a new vulnerability that's actively an exploited, why don't you go to those 300 servers and, you know, turn that service off or update it in some way. You know, AI can make that whole process much, much simpler. Again, it's about asking the right questions and putting the right context to it.
And that's the, the, you know, the thing I'm excited to be working on with my, with my current organization is OMI Networks. I'm, I'm blessed actually, our organization, we have, we're at the four AI PhD, so it's, you know, I'm not completely relying on the chat GPT thing. I'm getting them, you know, learn a lot about the, under the covers, artificial intelligence pieces, and that's been great.
Well, you know, I'm glad you touched on that part of it because, you know, and again, this is not just about AI or, you know, it's not, you know, again, we're just calling something else, AI again, so we'll just keep using the acronym, but, you know, because we all know what we're saying, but it's not artificial and it's not intelligent. It's good, but it's very cool. Right?
Right, right. Yeah. And, and, and, and, you know, one of these things we do is like, well, I'm trust it's not perfect, and you can't trust it.
It's like, nothing's perfect. You know, I have a, I'm, we on a pretty, we're pretty good at, and again, we're talking about risk here. We're having innate ability to tell, you know, when something's just terrible or, you know, or, or, or let me put, put it this way, we have innate, innate distrust of things that seem really authoritative, right?
Yeah. You know, it's a, no, we're not gonna all believe what chat GBD says or what these AI tells us, but I'm not gonna believe what, you know, an intern I hired for the summer tells me either, but I've asked them to go out and, and create a summary report. They came back with a summary report, you know, I'm mostly gonna look at it and see if there's anything I didn't know already.
I'll see if they missed anything and I'll, you know, but again, you know, my point, use that four things and in the, you know, it's, it's still on my screen over here, you know, so sort of interesting example of it, because in this last, um, uh, uh, working group, and there's, we know, I think most people watch show like this, know the acronyms, but lemme spell it all out. So the Department of Homeland Security, uh, cybersecurity Infrastructure Security Agency, DHS CSA and the Department of Commerce on, uh, national telecommunications in, uh, infrastructure administration, any N-T-I-A-A-A, I'm missing an A anyways, a, um, non-agency administration. Anyways, um, the, the Department of Commerce, NDIA is where the software bill of material, the SBO m uh, um, work inside the federal government began, and then it moved over to the Department of Homeland Security csa.
So it was in that, you know, which is geeky sort of stuff, right? You have to be following to, you know, have no other good hobbies to even know these things. Um, but I was sitting in this CSA working group, uh, looking at, you know, uh, potential next, next efforts.
And one of 'em was, you know, SBO repository, defining an SBO repository. And as there was a half dozen of us who, who, you know, literally, you know, five of the best people in the world plus me, well, God knows why, you know, so we're, we're trying to figure this stuff out, and none of us know. The answer to a silly question is like, is there a, a current definition of an SBO repository?
And I can think of at least one other document that really is current and canon, you know, that it could be in. And if I was a better person, I would've read it by now, but I haven't. Um, so instead of saying, I don't know, during the last call or trying to make a note in my head because I'm talking at the same time and I've already down, I can't, you know, I'll forget what I'm saying.
And trying to remember, go read that document later, maybe next week, come back with something, you know, to, to the point that I'm not getting to here. I put myself on mute while somebody else was talking, and I asked Chad, GPT, you know, is there, you know, definition for an s bomb repository? And it said, no, there isn't.
And, you know, and back, you know, back in the call I said, no, there isn't. Right? Uh, and somebody else is talking again, I'm scanning back down through it, and I see us at the bottom of the response, you know, where it says, you know, the Department of Commerce, NCIA, the DH SSA working groups, you know, have discussed this in the past, but have not come up with a definitive and hold down to the camera.
It's like, it's talking about us, right? How first can you get right? It just did, again, the, the college intern level of, of research, but still good research with the entire internet and fed back into the working group, the knowledge of the working group's own environment, which is just, what does that mean?
So, I mean, everything you were saying just now, like, yeah, you know, and, and for people who are not familiar with all this, you might say, well, were you doing that already? Can't you just have someone look at that? It's like you're missing the point.
And and many of us have been looking at this point all along the way for, for, for years and years now, because you say, you know, 10 and 15 and 20 and 30 years ago, this someday what we're gonna do is we're take all the events from every device, oh, and we're gonna have a thousand times more devices per square foot, and there'll be a thousand times faster. And we're gonna take all the events from those, gonna hook from them all up all at the same time, and comparing all that together so we can see how our risk profile is actually being actuated out in the real world. And people will just say, you're nuts.
And everything you just said is premised on the fact that we basically do that now. We're already doing all that. Now we're up to this metal level where you're saying you actually need humans or something human-like to stare at this to get the nuance out of it.
But if you did, oh, and we do, what does that even mean? Right? So let me, you know, looking at time, okay, so we'll try to get in the future here.
So are, are you and I just too close to this, you know, and fascinated by this shiny thing and say, oh, we're just about to hit this next crux and this changes everything, or does it, or if not, how long does it take to get to that next level of where everything new we were talking about now is just built in? Yeah, uh, I mean, I've, and I've, and I've got my worries about, you know, you, you touched on a good point there about the recursive nature of ai, and it's sometimes only as good as the, the data that it's being fed and, and who's doing the searching, right? Um, and it can be trained in wrong ways.
I, you know, I, I'm interested sometimes by that context of, uh, the decreasing accuracy of some of the AI engines as more people put data into them and, and feed it potentially with incorrect data or that, or the, that, you know, algorithms are pulling from incorrect data. So there's, there's challenges there, of course. And, um, you know, I love the concept of, you know, just basic anomaly detection functions with it or, or prioritization functions and, and not just in a cyber context.
Uh, you know, the anomaly detection capabilities of machine learning and AI have been great for, you know, things like cancer research. You know, I love seeing stories like that where, you know, speeding up the time to parse through big pieces of data to, you know, make quicker or more predictive, um, you know, predictions there. Um, yeah, I, I, I don't know.
That's a really tough question. You know, I, when I, again, when I think about it from a cyber perspective, I like to think about, um, you know, can we reach a potential where we're not just, uh, finding problems and making recommendations around mitigations, but are, you know, can, can we use our automated process to automate the mitigation processes? Right?
Okay. Now we see, you know, back to the earlier example I used, you know, we see that there's, um, there's a known vulnerability or a new vulnerability. We see active exploitations, we see you have, um, you know, so many instances of this specific, uh, software or hardware that's actively being exploited.
Is there something that you can automate to, to protect yourself from that, um, you know, from that, that risk, you know, can we go and update that software or, or drop connections to that individual system that's got the, you know, vulnerable hardware? Um, or maybe we're automating things like, you know, I've seen some cool technologies recently. I like to look at a lot of startup technologies.
I've seen things like, um, you know, can we automate, uh, machine to machine authentication and key exchanges? We're not doing certificate management anymore. Can we automate, uh, and this, you know, become interesting?
We get, you know, to, to dealing with, uh, you know, how this, uh, AI and quantum computing impacts encryption and things like that. But, um, yeah, I, I'm, I'm interested in how can we automate the, the mitigation side of things and how can we automate the process of reducing risk, uh, you know, not just from cyber perspective, but maybe in our day-to-day lives. If you think about, um, you know, really basic things like pollution, censoring, traffic controls, all of that, that data can be fed to tools that can potentially, you know, do active mitigation in our lives.
So that's the next steps. Um, that's what, or at least in my perspective, that's what I'm interested in, in seeing where that's going. Well, I, I think that one's short term.
Let lay, you know, I'll, I'll, you know, I'll take the risk, you know, so I hope so. I'll see, yeah. Seven years from now when we're watching this, I was wrong, but one word I don't think I am.
Um, I think seven years from now, you're walking around with a lot of this built in, right? You know, because everything from, you know, it's funny, I hesitate, you know, when I say this, but, which is, which is a, a lesson all by itself, but toilets, you know, since I was a child, I thought, oh, one day toilets will be doing medical diagnostics all the time, right? Obviously, because that's what we test it, and we every brush samples constantly, right?
I would like to know when the first cancer precursor cursor shows up, not when I get my first annual checkup a year after that starts, right? And the, and, and environmental smoke in the air, you know, gluten, ev, anything, right? You know, why not you have these devices?
Just pick that up and just let me know about it. Why not have AI systems that will say, so not reading, given where you are and your context and everything else, is something you should actually know about, because the information's all around us already. You know, the, the, you know, the, I gonna try to leave this with a question.
I, I make no promises because, you know, one of the things that, you know, as, as a Apollo era, a kid staring up in the sky and thinking, all right, if I'm right and I'm lucky with a faster and light transport by the time I'm like 35 and I'll be able to go to these places, no, you can't. Um, and, and I never would've thought, um, at the time that if we just stared harder at that star and stared really hard and stared really, really, and stayed really hard. And so we can get a planet transiting around it and get, you know, with the spectrum, do a spectrum analysis of the atmosphere of that planet, you know, 130 light years away, right?
And be able to detect and, and, and, and, and, and, right? So we, I guess my point is that our ancients ancestors had that same information washing down onto them, you know, all the time. Anyone could have picked that inform, you know, out of the information that was already available.
And everything we're talking about now is information that's basically already always been available. And it's just getting into that crux. So I think, yeah, so I, I, I think I am overly optimistic.
Um, I mean, I'm joking. I think I'm optimistic about the future, and I think I'm right. I think this has way more impact than we can really get into our heads yet.
I agree. I, yeah, I don't know if there was quite a question there, but I do agree. Um, I know who said that.
Um, I'm, I'm optimistic about the future. I'm optimistic about, you know, there's, there's things we gotta do to protect ourselves, of course, but I'm optimistic about, um, you know, the things that we see evolving every day, and I, I'll say about, maybe again, no problem, but I'd more likely to find a question, this one. So, so the, one of the nice things about this, I think what we're doing is collapsing a lot of risks that have been around forever, you know, that, that people might have been saying, you know, you should do something about this 20 years ago and you shouldn't have, because that risk did not realize.
Um, but, you know, one of, you know, in its security context, the bad guys have these tools too. So, you know, a lot of, a lot of things that have always been impossible, but have really haven't been, you know, uh, used against us so far are being used and will continue. And that will drive the, the optimism side of, this is my question that'll drive companies who like staying in business and making money to come up with the resources in it to come up with better, more reliable, built in, uh, um, uh, uh, uh, solutions.
So do you think, you know, following that optimistic path that this actually will drive us, perhaps, you know, to accelerate reaching some of these long term, you know, and, and maybe even, you know, commonly I, I believe to be unachievable goals in security? I, I think so, and, and the optimist in me, I think, uh, artificial intelligence, automation, you know, these things are going to be a, a greater advantage for the defenders than they're gonna be for the bad guys, right? I really do believe that.
Um, yeah, there's, there's, there's risks in future technology that, that, um, that may have a bigger impact for attackers. I think the one I worry about the most is, you know, the impact on encryption via quantum computing. Um, yeah, I think about all the people like the Bitcoin network, for example.
Um, you know, I won't go, I won't go down that rabbit hole right now, but, uh, but yeah, but I think in general though, I do think that, uh, AI and automation are going to be, uh, an advantage for the defender over the attacker if we properly utilize it and harness it and make it available. Yeah, I think that's a, you know, that, that's a good note to, to, to end on as any, because I don't think that's true. Right?
You know, because the, the, and, and this is that ratcheting effect, we always get the wild west, you know, before the, the, the civilized urban infrastructure, which has its own problems, but in the end, you know, is very efficient and, and, and security and risk management is not an infinite field. You know, we've just been dealing for, you know, tens of thousands of years for tens of years in, in the IT space with the understanding that you can never see it all. So therefore we'll do these things and maybe we can see it all.
Yeah. And I mean, and I think for me, uh, you know, I, I think I was talking more in the context of security when I gave that answer, but in general, I think it, the, the benefits of automation and artificial intelligence, I know, you know, we hear a lot about the risks and, and, and, and how much, you know, how much regulation do we need in, you know, how much oversight do we need in all of the efforts that we're making in artificial intelligence and automation and digitalization. But I think in, in general, just like I was on that path for cybersecurity, I think for humanity in general, that the, the positives are gonna far outweigh the negatives.
Um, we gotta put the effort in. Yep. So I, I'm afraid if we go any further, we'll, we'll, uh, dive back into the darkness.
So I, we will leave it at that. And thank you, Mike, for everything you've done. You know, thanks for your friendship.
You know, I know your family, you, you, you're one of four or five people that, that has ever sailed visits at this helm of my boat. Right. So, and, uh, yeah, it's Been same, Chris, it's been, it's been great to know you all these years.
I appreciate the, the multiple invitations now to, uh, to visit you there in Florida and, uh, and have a beer or two talking about these exact same topics and concepts. It's been enjoyable. Thanks, man, and thank you all out in the world for spending your time with us today.
As always, we'll see you around on the, on this show and be good to each other.


