Latest / Noise2Signal / EP 9. Do AI or Be Replaced by AI w/ Craig Adams. AI-Native Future of Cyber Offense, Defense & PM
Transcript
- Speaker 1: You are one of the most accomplished product leaders in cybersecurity. Speaker 2: First and foremost, I really appreciate the opportunity to be here with you. I'm a big fan of this series, so Speaker 1: The thing I wanted start the interview with is the the role of a product manager. Do you think the product role takes more on the UX role? Speaker 2: Done. ⁓ so let me be let me be super clear. There those two have merged. Speaker 1: One of the reasons I started noise to signal because there's just just way too much noise. Speaker 2: The notion of everything sounds the same has made it truthfully for our buyers to have to be detectives to actually figure out what people do and what they do differently. Speaker 1: Let's ⁓ switch to a topic that is near and dear to both our hearts, vulnerability management. ⁓ let's talk about ⁓ methos. Speaker 2: I haven't heard of it. The customer problem is not a just a raw discovery problem or it's not a raw verdicting problem. I think they they have a fundamental exposure problem. Speaker 1: W one of my biggest distaste about selling cybersecurity software it it relies overly on fear momentum. Speaker 2: I think the biggest statement I would make and I and I and I believe this with every ounce of my body, I believe the organizations that win are gonna have the most robust response options available for customers to leverage. Speaker 1: Do think like the there are any any roles that will get replaced Speaker 2: If I look at the field of cybersecurity, I have religious level conviction that the number of defenders that work in cybersecurity will be more in the future than less. Speaker 1: Talking about AI driving efficiencies, one of the things th that is gonna get efficient in the age of AI is the exploitation in the age of AI. The big ⁓ Speaker 2: Biggest risk is gonna be for defenders to not use AI versus any incremental AI risk that exists. Speaker 1: Do you see an explosion of vulnerabilities and then a plateauing of the vulnerabilities because of the low hanging fruits have been found? Speaker 2: I strongly disagree with that one. So I actually like passionately believe that most organizations aren't gonna find the majority of their AI use actually done from an AI ⁓ provider directly. Speaker 1: Now are we containing AI or leveraging AI? Where which phase are we in? Do we see vendor consolidation or vendor explosion? Last topic for today. Let's do some predictions. Do we see more good guys becoming criminals or do we see more criminals becoming good guys because they have nothing to do? Speaker 2: Both are different life cycle stages. More good guys becoming criminals. Speaker 1: Ladies and gentlemen, please welcome Craig Adams, Chief Product Officer at Rapid Seven. Craig Adams, it's so nice to have you on Noise to Signal channel. You are you are one of the most accomplished product leaders in cybersecurity. You've been building scaling products for over 20 years. ⁓ recently you were the chief product and engineering officer at Recorded Future. And most recently, you are the chief product officer at Rapid Seven. The thing I wanted start with the start the interview with is the the role of a product manager is changing in the age of AI. The reason I say that is historically as product people, you would go talk to customers, you do the market research, you would talk and bring that into into requirements, talk to the UX team. refine it, iterate with the UX team, then go back to engineering, put that on a sprint plan and so on and so forth. And now what is happening is the product guy can build can actually build the prototype. The UX, the UX guy can build the the product. And the engineer is sitting there and why do I need the product and engineering people here? I can build the product completely end to end. So it's a game changing from a product perspective. As a product leader who's been building and scaling products, what's your point of view? What's the what's the role of a product manager in the age of AI? Speaker 2: First and foremost, I really appreciate the opportunity to be here with you. I'm a big fan of this series. So thanks for allowing me to join. So the second thing is first, ⁓ the role of the product manager has fundamentally changed in the world of AI. Let me first start ⁓ of the analogy of waterfall software development. It's dead. ⁓ the notion of I write the long doc, which I hand off to someone else, who then hands off to someone else, is just fundamentally over. And so we are now at a stage that agile. And and I mean agile from a total software development lifecycle is what we're going to be implementing, not just the engineering coding portion at the end of the day. And so first, ⁓ if we call waterfall dead, the product managers still, if some things stay the same and other things will change. The things that stay the same, the ability to come up with the right strategy to win, the ability to come up with differentiation, the ability to identify the moments that matter and the experiences that matter, which is more critical in the world we live in, all of those things stay consistent. What is gonna change is the skill set and skill demonstration that product managers are gonna have to have. It's no longer gonna be primarily assessed by the comprehensiveness of documentation that you write or the insights. It's gonna be the ability to come up with rapid feedback loops of my ability to have an idea, prototype it, run it by customers all myself in a way that then will change my downstream software development partners. It also means the role of engineering has changed. Yeah. Yeah, getting a document and writing code, that's out the window. We're gonna be moving to a place where a gentic ⁓ you know agents are gonna be prompting the engineer of the task that they need to do. But it's such an exciting time to be in tech. ⁓ this truthfully is the opportunity of a lifetime, and I think there's no better role than product management to help. Speaker 1: It's funny because I've seen engineers who have written more code in the last year than they have written in their entire year entire career. But they they now they're saying they haven't even looked at the code sometimes. Like you know, sometimes they are not the it's getting to the point where the product the code is so good that they're not actually they're looking at it from an architectural point of view and so on, but not like, you know, doing like a real ⁓ code review. The follow-up to that question I had for you, Craig, was The does the product role change based on the type of industry you are, whether you're you know, w whether you're in a service type of a product leader or you're building enterprise software, does that change at all? Because you've been in all these different positions in your career at Recorded Future at Rapid Seven. The does the the role of the product change depending on the type of the industry? Speaker 2: So so direct answer is yes, but there's more in common that's different. So for example, if someone's in B2B product management versus B2C, it's a radical different skill set, it's a radical different approach, it's a radical different metric structure that you use in how you define success. With the with those differences though, I still think there's a common core at the end of the day, which is fundamentally the ability to both set a strategy, vision, execution, ⁓ go through then and ⁓ define the areas that make sense to grow the business as well as the areas that we should not do, because a good PM spends more time saying no than yes at the end of the day. ⁓ There's more of a common core than difference. What I will say though is if you go from B2B in different areas, I think if you go the difference between a ⁓ intelligence product manager, so part of my career, or a network-based product management or a services-based product manager. Those have radical different lifestyle attributes of how you have to think design. So for example, if the end product is someone's going to consume my technology, that's different than if my end product is a human or an ingenic agent is going to consume my technology to do something for a human. So, but it's still a big common core with a round out at the end. Speaker 1: Do you think the product role takes more on the UX role? Speaker 2: Don. ⁓ so let me be let me be super clear. Th those two have merged. So if you talk about what's the skill profile in the future, user experience, I do think the ability to come up with design systems, library standards is absolutely critical. So no one is trivializing it. But if you do this the right way, ⁓ your gentic code takes that into account at the end of the day. ⁓ so in other words, you still have your user experience team creating, for lack of a better word, your libraries. But once those libraries are created, what you're end gonna have is the product manager is designing the capability. The user experience team probably is gonna own more of the end-to-end experience journey of the customer across the platform at the end of the day. But but all the rules are changing in I think exciting ways. I can't emphasize that enough. Speaker 1: And you know, in our field a lot of these roles changed in the previous era. Like we have the SecOps and then we had the DevSecOps. And I wonder if there is this new role that emerges from this where it is like gen DevOps or something or product engine ops or something. I don't know, maybe we should coin a new word and like, you know, and claim our clay and and have that our na name to claim. But Speaker 2: But ⁓ but I think this is a a common thing we've always seen in technology evolution. And so member with a role of a prompt engineer, which sounds almost quite quaint. Speaker 1: Yeah. When I first saw it that the w what is a prompt engineer? That can't be a real role. Speaker 2: But but now that role I would argue has gone out of fashion. Like I argue there there's no such really distinct job or a skill of a prompt engineer. And so I think through all of time we've seen ⁓ innovations come requiring new roles, and then new innovations come that evolve and change those roles in new ways. And so I absolutely think we're gonna see different roles come up. ⁓ which means the people that are successful are gonna be those that are actually living the growth mindset. It's the lean in. ⁓ authentically in every form of have they adopted the capabilities an organization has? Are they leaning in and how they're going to be relevant and contributing as opposed to the reluctant ⁓ laggards? They're screwed. Just to hit it really directly, they're gonna have a tough, tough run at the end. Speaker 1: And one other thing that happens is that you know ⁓ as more people build software, as more more software comes to ⁓ you know, comes to the comes to the top, it's one thing that becomes difficult is you differentiating yourself. You know, whether you're in product marketing, you know, I saw this firsthand at RSA. And and this is one of the reasons I started Noise to Signal, because there's just just way too much noise in terms of differentiating yourself. And I was at RSA, I was looking at The booths and everything was agentic AI, cyber security. And it was recycling of the same words over and ever across every booth I was walking through. And I was like, How does an you know started startup like my mine like differentiate themselves? And it's very crazy. It's crazy, right? So I'm curious, what you what's your point of view in this world where everyone is claiming to be AI native, AI forward, or ⁓ what's the ⁓ what's the ⁓ word that they're ⁓ forward deployed. forward forward deployed and ⁓ AI factories, whatever it is, whatever AI AI native agent would they add to it. I'm curious what you think of that ⁓ in the age of AI. Speaker 2: Also first, I feel ⁓ I feel both your pain of walking around at RSA, the the notion of everything sounds the same has made it truthfully for our buyers to have to be detectives to actually figure out what people do and what they do differently. And so that this has been the the the curse of the security industry is in simply put, ⁓ vendors making all promises that sound the same and then putting the onus on the customers to have to dig through. I think there's two parts that we're going to see as a trend. So, first, as sales cycles have changed, ⁓ this notion of like I'm uncovering, ⁓ identifying solutions, customers aren't walking anymore in the same volume around booths to learn of solutions to technologies at the end of the day. What they're actually doing is spending more and more time actually asking AI ⁓ with the problem I have. Who should I be evaluating, compare and contrast ⁓ across it? So we're gonna see the world of like SEO from the past actually change into it's gonna be like AI SEO of like how do I optimize? So ⁓ the text files that we put into pages so that we're giving the instructions to the scraping engines of what they should be paying attention to and telling them what to focus on and what's really important. ⁓ that is gonna be a skill that of course will also evolve like many of our So correct. Speaker 1: There is there is a new term for it. As and ⁓ first time I looked at it, what is AI? AI Yeah. AI engine engine AI engine optimization. Speaker 2: Yeah. That's exactly right. It's how you optimize your content so that you're giving ⁓ AI agents instructions of how they should process read and what to pay attention to at the end of the day. And so it's a fascinating field. But if we go up a level for a second, our question we're talking about is how do organizations differentiate? And and I think we're gonna enter a phase of ⁓ SaaS simplicity times ten. Where organi ⁓ buyers are gonna look at skepticism to every company they hear an amazing pitch from. And they're gonna want the ability to quickly see, try in a safe way. And so I think that's gonna mean in a certain world, I have sandbox environments, I can play with things. ⁓ I'm not gonna wanna speak to sales reps. I'm gonna wanna quickly go through, and I'll use the phrase quickly, independently, without the level of engagement. I think that we're gonna see the rise of I'll call old form content of. The demo verti videos versus demo humans are coming back. Okay, it's cyclical on how it's operating. But the ⁓ willingness of customers to speak to humans to learn everything they want to learn, those days are just over. And so organizations are gonna have to face it. Now, who's gonna win are those that don't describe the feature function, but they focus on the outcome value that a customer gets at the end of the day. Because truthfully, there's a lot of slop in cybersecurity. of I have a a capability that does X, that no one wants a capability. No one wants another tool. They're actually looking to get an experience, an outcome. And the organizations that talk that way, design products that way, and deliver that way, those are the ones that will thrive. Speaker 1: And in some respects, I think in some respects the human led demo was already trending down because that was the right product led growth. You know, it was like let me try the product and once the you know once the user tries the product, they love the product, they share it with somebody else, you know, the links in the referrals. That was already on that path. You were already on that product. I I think AI just ⁓ you know super supercharges that that journey that customers were already used to. Let me try it. Let me use it. Let me get the value. And once they are getting value, they like I have personally had this situation where I started with the twenty dollar cloud code subscription. I run out of my my usage. And then I'm like, dude, I need ⁓ I need to do more work. And here I am flipping my credit card. You know, let's go to the hundred dollar version and then to forth. So I never talked to a single sales guy at at Anthropic or Cloud. Speaker 2: But but I think this is multiply further on the the product growth side. while everything is branded because AI is the buzzword of the century, ⁓ an AI product looks like an AI product. You you don't have to have someone tell you what's AI doing. So I think the organizations that are gonna be successful are gonna be the ones that actually take the time to show work, show work product and what's actually being done. And so in an agentic world, one of the biggest fears many organizations have is the black box. It's when the robots go rogue, ⁓ chatting in the chat room ⁓ with each other about ⁓ who's the best and how to can penetrate an organization. But ⁓ I think people that embrace transparency to the tenth degree of how do they go through in and show work product actually will excuse me, show work product without detracting from customer experience. Those are gonna be the ones that have a real opportunity for exciting success. ⁓ but if you're an AI product, you gotta look like an AI product, you have to feel like an AI product. ⁓ and that's gonna be a key part of both product management, product design and execution. Speaker 1: Makes sense. Now let's ⁓ let's ⁓ switch to a topic that is near and dear to both our hearts, vulnerability management. ⁓ let's talk about ⁓ methos. Speaker 2: Nito. I haven't heard of such a thing. Speaker 1: So one of the narratives, ⁓ this was like two or three months ago, is cybersecurity is dead, VM players are dead, there is all these EI players are going to take over the market share, ⁓ Anthropic is going to do everything. and my when I read it, ⁓ that doesn't make sense because obviously these new models are finding new vulnerabilities that Right. Expo at exponential scale. They're finding thousand, ten thousand vulnerabilities, that is historically in you know, like ten standard deviations away from what's the normal standard. And my thinking on that was the exposure management players, the vulnerability management players, the defenders will be in more demand because somebody still needs to detect them. St somebody still needs to help organizations remediate them. And they cannot obviously patch everything, but like they will provide recommendations for compensating controls and you know, because These are all the things that need to happen. And and the s and now it is actually changing. But the initial glass wing was we are only going to give access to NVIDIA, Microsoft, and Google. And I was like, where is Callis, Tenable, and Rapid Seven? Like these are the defenders. Where are where are the defenders? There are no defenders here in this glass wing program. You're creating all these findings and vulnerabilities. And the guys, the enterprises, like, you know, I think if you collectively look at ⁓ Tenable, Callis Rapid Seven, there are sixty thousand customers across all all the you know key defenders that are out there and they're not even part of the program. And I was like, what is going on here? ⁓ so I'm curious what was you you obviously saw the mythos hype roll out and then you obviously saw the your customers asking what do we do about mythos and there's nothing to do because there is there what do we do? There is nothing to do at that point apart from doing like a board level pitch deck. So I'm curious what do you think of the all the mythos hype that has happened and the response from from your point of view. Speaker 2: And Rapid Simone, we're excited about the announcements that are happening around Mythos and otherwise. And I'll tell you why, which is it's it's changing the the problem statement in industry. So to be very, very clear, I do think ⁓ discovery and verdicting, ⁓ discovery gaps, verdicting gaps, those two are things AI does really well. That that is an AI disruption. We should call out, identify, acknowledge that ⁓ that's an incredible innovation. The problem is back to what you and I were talking about a little bit ago, like what's the problem a customer has to solve. The customer problem is not a just a raw discovery problem, or it's not a raw verdicting problem at the end of the day. They have a fundamental exposure problem. And so what all of these innovations are gonna do is it's gonna put much more pressure on the response side. ⁓ response if it's a a a vulnerability, a cloud misconfiguration, response if there's something malicious inside of my environment alert that fires at the end of the day. And so in the spirit of harnessing the innovation, not fighting it, I actually love what it now does for discovery. The the challenge is the typical organization has discovered more things already than they can fix. So putting five X more things into their discovered bucket of things to fix ⁓ is a non-sustainable cybersecurity model at the end of the day. And so where I think we're gonna see the evolution from Is absolutely the both number of vulnerabilities and using vulnerability exposure, pick pick your word, the identify risk and those are going to multiply, which means organizations are going to have to have a different strategy because they're not going to be able to patch their way out of it. Combined with the time to exploitation that AI is driving from an attacker perspective. ⁓ and so this is where I view the innovation as exciting because now it's going to move it to the actual outcome that a customer wants. So where does it leave a customer at the end? Hey, whoever they work with, they're gonna get the detection capabilities as part of it. But I'll tell you, people aren't buying something for detection. They're buying for the remediation, the response, the action side of things. That that problem just got worse, which means the case for why an organization ⁓ still needs ⁓ a capability to address it is still as strong as ever. Speaker 1: Yeah, w one of my biggest distaste about selling cybersecurity software, it it relies overly on fear mongering. The the and I have personally disliked ⁓ that aspect of it, the fear mongering and scaring people in term in terms of buying something. And I think mythos has in some ways mythos has been a has the has been a boom because they're generally scared out of their mind. And a lot of p l a lot of the executives I talk to They don't I mean mythos came out. They didn't they said Mythos bad. Mythos coming out, mythos bad, right? So that is like the narrative that went out. And then ⁓ and then there was no real good solution out there. Like, okay, what do we do? ⁓ we don't we we are not going to disclose the vulnerabilities. You're not going to tell you anything about these. They're gonna come out sixty or ninety days later. But mythos bad, right? Mythos bad. And then the executives or the non technical executives, they're sitting on the boards and they're hey, Craig. So what are you doing about mythos? And Craig is thinking like we don't have the details, but sure, here's a you know here's a step by step plan. ⁓ Speaker 2: So I usually so I haven't viewed there. So like we're working with Enthropic, we're working in Open AI and all those organizations of how to do that. I think the biggest statement I would make, and I and I and I believe this with every ounce of my body, which is in cybersecurity today as a fundamental perspective, we don't have an information problem. It's not the dominant problem we're having. ⁓ so so if I view Mythos accelerated information, ⁓ which it does, and and ⁓ mythos open AI, like all all the different vectors of it, that is phenomenal. That just made the existing problem we had worse. And so the question now, and this is where we're going to see, you know, different organizational profiles, is how ⁓ excited organizations are gonna be, excited was in air quotes, about well, if I am using AI to gather more information, how much do I want to enable AI to make it actually implementing my compensated controls? Which is net net, like can AI write to my organization? not just read, not just verdict, but actually change, lock the CEO's machine, ⁓ things of the sort. And and this is where you're gonna see a caution zone of, I believe the organizations that win are gonna have the most robust response options available for customers to leverage at the end of the day. But but this is a zone of ⁓ well sorry, there's one other thing we haven't talked about as I'm bouncing around, forgive me, is wild increased information. It did also binarily decrease the time to exploitation when ⁓ the vulnerability of risk exists in the higher. So so I do think the traditional cybersecurity model of identify a risk, ⁓ prioritize it among a team, have a team. We don't have time for that anymore. And so it's gonna mean back to the response side of how do we implement compensating controls. That's gonna become more critical than ever before. Speaker 1: Yeah, it's all dead. Speaker 2: And people are gonna need technology. I'm not sure people are gonna look at anthropic to to ride across their environment. I I don't see it yet. Speaker 1: What's ⁓ what's real and what's hype when you read about all these announcements around AI? Like one one thing I've seen consistently is fifty percent of our jobs are going to be ⁓ replaced and these jobs are not going to be relevant anymore. And I mean I'm conflicted because I feel like if you have a team that is skilled, you essentially 10x every member of your team with AI. Right? And you know, instead of cutting, you're essentially cutting yourself off. Like it is like cut if you had a kick ass team, had like great researchers and you had great ⁓ engineers and you gave these tools to them, they in our my humble opinion become much more competent in what whatever they were doing. and I f I mean maybe maybe there is some jobs that get replaced because they were not valuable at all. But but I feel like in net net Net net the number of jobs will increase. Because we are now doing more coding and more managing of the software than before be ⁓ ever before. I'm curious what do you think of? Speaker 2: Yeah, so so I have a few different thoughts. So so first, with every material technical innovation, there's always a displacement of what rules exist, what rules don't exist. So so I think this idea of churn, ⁓ which is change will happen at the end of the day, absolutely is occurring. ⁓ the second, if I look at the field of cybersecurity, I have religious level conviction that the number of defenders that work in cybersecurity will be more in the future than less, ⁓ even in a post-AI world at the end of the day. Speaker 1: But you know, when you say the defenders, do you think the instances of AI agent defenders or like human defenders? Speaker 2: In this specific case, human defenders. And by the way, I absolutely believe in every ounce of my body, the robots are going to do so many more tasks than humans. So it's going to be clear ⁓ the robots are going to churn of what's done by a human and that's going to evolve across an organization. But if we just take a step back for a second, and maybe to make an analogy, if you look at the world of cybersecurity ⁓ 20 years ago, and I'm hand waving numbers, 20 years ago, everything's on prep. So I understand, I understand what I'm trying to control, protect. Hey, then I move to the world where clouds are not. So now I have things I'm trying to control predict outside of my environment, but that's a step function of complexity. Then I go to the world of SASIFication where my crown jewels may not be inside of my environment and my cloud and uncontrolled in any way. That's something I predict. Now you're going to an agentic world where I've got machines and robots ⁓ running around. You're we're we're we're increasing this complexity of cybersecurity in nonlinear ways. Yes, we're gonna make house certain tasks way more efficient. Than I've ever been done in the past. But no way, like zero percent scenario, are the number of defenders, the number of people in information security departments in aggregate going down across the horizon. Where I do think we'll see changes is when we look at an organization creating software development. So so I I think the the changes we're gonna see, ⁓ ⁓ that inside of technical organizations, you're gonna see an impact. And we're already seeing it if you look at the number of CS ⁓ graduates ⁓ coming out of universities. It's now in a decline from a peak in the past, and that's projected to continue. ⁓ so you're gonna see disruption and churn. So I'm specifically focusing on the information security teams, the teams under CISOs and organizations. Those I have religious level conviction will be a size throughout society as a large, ⁓ we're gonna we're gonna have a fair amount of churn. where new jobs are being created, old jobs are going away. But that happens with every technical innovation. Speaker 1: But do think like the there are any any roles that will get replaced, like the tier ones will get replaced with more tier twos? Speaker 2: Absolutely. So so so if you ask my zone that like what what makes me ⁓ up at night is entry level positions are the center of the bullseye for tasks that AI can do in a more effective way, as a general statement. Having said that, ⁓ let me look at ⁓ Rob Seven's in but we're obviously using AI to do more and more things inside of our SOC. How do I have machines investigate alerts as opposed to humans? ⁓ at the same time. We're not planning on reducing the size of our stock. We're actually going to use those people on higher value security tasks. Because if we look at the cybersecurity model, and maybe that's the the punchline at the end of the day, ⁓ there's always been change and evolution. ⁓ and what was hard becomes commodized, and what ⁓ becomes more efficient with machines, you you see this a churn is just the best word to use. At the same time, the problem hasn't been solved. And so even with more tools, more information. The number of organizations compromise continues to grow year over year. The dollar impact of compromise goes year over year. And so what we're going to find is people moving up the security maturity journey in a more ⁓ rapid clip than I believe we've seen in the past. ⁓ most organizations, if you corner the CISO over a glass of wine, ⁓ don't say my security posture is perfect in how I operate. ⁓ they know the zones that they need to mature, it's a maturity journey. And I think what we're gonna find is AI is going to make certain tasks more efficient, allow more eff emphasis on other parts of the maturity journey. And I'm not convinced boards or C ⁓ or CEOs are gonna look at cybersecurity as the first area they wanna reduce their spend ⁓ or reconfigure their workforce. I think they might look at a few other areas Speaker 1: Talking about you know AI driving efficiencies, one of the things that are getting that is going to get efficient in the age of AI is the exploitation in the age of AI. The there is a rise of AI native exploitation. Craig, I started my career as a vulnerability researcher at Tannibow and I used to write exploits and it used to take time. lot of time, days, weeks to get an exploit working safely so that we can push that into an SS plugin and then test it. And you probably know it from the Metasploit the Metasploit project that is in Rapid7 takes a while to get a functional exploit code working. Now, you know, writing an exploit essentially takes a prompt. Right? So it's not not like as good as a Metasploit exploit, but you can reasonably get to a point where you can prompt your way to an exploit. ⁓ What's the ⁓ what's the future of AI native offense from your point of view? Again this is what's Speaker 2: This is so this is where ⁓ I look back with it's almost adorable to me when ⁓ security teams were nervous about using AI inside of an organization. Cause every technical innovation starts with a ⁓ fear inside of security teams ⁓ doesn't matter what the technical innovation is cloud, like how are you gonna secure the cloud? ⁓ the the attackers are utilizing AI with such incredible efficiency. ⁓ nonlinear impacts of how they're able to both identify, exploit, penetrate an organization that the the biggest risk is going to be for defenders to not use AI versus any incremental AI risk that exists. ⁓ imagine the scenario in the past of the phishing emails where it was the Nigerian prince and you want to have $20,000 that, but it was almost like comma-conportions. It doesn't matter the threat that you're seeing. If it's the ability to attack co-fishing opportunities, if it's a looking at how do we penetrate and identify an organization, find lateral movement across an environment, the time to exploitation is becoming your instinct. And so this is one zone where I believe you're gonna see a lot of focus on attack pathing. You're gonna see a lot of focus on compensating controls. You're gonna be able to see a lot of focus of, I'm calling robustness of response actions. ⁓ utilize the the old model used to be isolate the advice, isolate the identity. Those are the two like go tos when you'd see something go wrong. In a new world, ⁓ things are gonna move so quickly that we're gonna have to immediately shut down access to sensitive data systems or otherwise as we go through the organization. Speaker 1: Yeah, there are I've two I have two follow-up questions on that. Do you think, you know, with the mythos and the AI native offense and exploitation, do you see do you see an explosion of vulnerabilities and then a plateauing of the vulnerabilities because of the low-hanging fruits have been found? Right? You know, I and the second question I have is, ⁓ if the vulnerabilities plateau, is it the chaining of vulnerabilities that is the explosion that we see because historically you'd always needed one vulnerability to break in, get in, but now you can chain like multiple medium and low and you know high severity vulnerabilities to act actually which is the end goal of vulnerabilities to compromise systems. Whether you do it with one vulnerability or five, doesn't really matter. So I'm curious where it where your head is. Like do you see a plateau? Like if there is a big explosion over the next two years, all these low hanging fruits are found and then there is like a steady state where you don't find as many because all the easy ones have been found and fixed and pushed into the internet critical software. Speaker 2: I strongly disagree with that one. So let me let me let me jump in and make our our conversation spicy. So ⁓ the rise of AI generated code, it is a complete misnomer to think that that is high quality, secure, protective code at the end of the day. Have a conversation with Claude or pick a chat bot and ask it about software vulnerabilities of AI generated code. ⁓ it covers everything one else. So I I'm in this view that ⁓ there's no spike and then plateau of ⁓ vulnerabilities, exposures inside of environment. That that is a a multiplying exponential piece. Second thing you said is 100% true. There is a lot of organizations spend a lot of time on the critical stuff that kind of frankly got to the other stuff when they got to the other stuff. And so I think as you're going to find is a new both terminology, the new defender approach, really focused on toxic combinations. ⁓ and so it's going to mean a different path. And this goes ⁓ of not just how do I count the number of things because to begin, to be clear, there are already more things than a company found that they could patch. So I I'm starting out with patching is a ⁓ necessary thing for a stability security of an organization. And it will not be the way that organizations protect themselves against compromise. Like I the it's just the the ground I'll hold. And so we're going to find the robustness of response options. And that can be everything from virtual passing, maxing, ⁓ masking, excuse me, ⁓ changing attack path formation, permissions that then guide you to how when a toxic combination occurs, ⁓ I can be protected across my organization without this false thesis that I'm now gonna patch 50% more next year than I did in the previous year because it's not gonna happen. Speaker 1: Yeah. And then ⁓ if that is the case, ⁓ how do defenders defend in the age of AI? Like what it because my my sense is like the only thing that changes in this new era is the speed of response. Yeah. That is like Go ahead. Speaker 2: No, sorry, I probably apologize. I get excited about this conversation. And so so I think this becomes a defend with AI. So if I actually look at the SAS apocalypse that occurred a while ago. Speaker 1: Yeah. Two months ago, two or three months ago, every SA SAS software is dead. Like now it just give up, like give the money back to the shareholders. What are you guys doing? Speaker 2: I I think what we're finding is a a redefinition of what SAS software is. And and so I have a thesis that, ⁓ and pardon my poor grammar, that ⁓ every software provider is a place that you either do AI or you'll be replaced by AI. So so I actually like passionately believe that most organizations aren't gonna find the majority of their AI use actually done from an AI provider directly. I believe the majority of their AI use is gonna be from applications, take something outside of cybersecurity, Salesforce, CRM management. ⁓ Salesforce is gonna be a place that you do AI at the end of the day. I don't go in to get my raw data and my data feeds. I go in to get the analytics and the things that I need to be successful. It's gonna be that provided by the vendor itself. And so where the punchline where I was going is I think the question is when you're being attacked by AI, you're gonna defend with AI. But now we start hitting the inequality. ⁓ that exists inside of cybersecurity. There's a whole bunch of organizations. I'm looking at you, Goldman Sachs, that can afford every tool, ⁓ person capability on the planet, and they have the budgets to match that. There's a whole bunch of organizations, the regional bank, the water company, the town, the school district, that aren't gonna be able to create and run all of these agentic applications themselves. And so that's gonna become the new role for SaaS software at the end of the day. It's gotta be place where it gives defenders the capability to defend with AI through the tool suite that they get. Speaker 1: D do you do you think that ⁓ more and more soft SaaS software becomes much more customized to ⁓ customers environment because now you can do these because a lot of times what I've seen is ⁓ most ISVs, they build the software, it's one size fits all, everyone gets the same version and then you you go with it and you and then you have to hire like an army of professional services and solution engineers to get to get the job done. And this is where this is the gap that the SOAR players kind of fixed, where they came in, we are going to automate the workflow, we're going to take all your products, and we're going to create these boxes, and then you can do this. If this and this happens, then do this. And it was like a glorified professional service. It was a glorified professional services engagement. Do you think more and more ⁓ SaaS players will essentially help customers by agency? Speaker 2: It was brutal. Yeah. Speaker 1: Like go deliver this outcome for me. I don't care how you do it. Here's the software. Here's the here's the data. Now go aw work on this data and deliver this outcome that I need. Speaker 2: I I think yes, and and your spread of customization can be seen in it's a it's a simple example, but bear with me. every SaaS software product has reports. Reports imply that the fixed set of questions, I'm gonna go to a place to get a fixed set of answers, hence that's what the report does. If you look at what modern reporting typically looks like, there's AI-driven interfaces to it. So first, reporting still exists because you want to be prescriptive in your journey, whatever journey you're taking a customer on and how they operate. But modern reporting in the AI world's gonna be here's what you need to know, here's what's dynamic inside of your environment, ask me the things and it's guiding and Speaker 1: And here's the context of whatever I'm recommending, which is personalized to your environment, rather than a cookie cutter report, here are here are the high, medium and lows you have. Speaker 2: And that's why I think your world of customizations is dead on. Wha which is ⁓ it's customized to the environment and how it operates at the end. Speaker 1: Makes sense. ⁓ you know, when this AI journey started, Craig, there was a lot of hesitation in adopting AI in the organization. There were like a lot of i I remember in my previous jobs, there were mo there were people monitoring is anyone using chat GPD, is our sensitive information leaking? You know, we we we need to limit the access of AI, AI bad. That that was one narrative, right? And so there was like a Speaker 2: Adorable. Speaker 1: strategy to contain AI using the enterprise. ⁓ and now I think the shift is leveraging AI in the enterprise to do more. I'm curious where your thinking is, whether c you know, are we containing AI or leveraging AI? Where which phase are we in? Speaker 2: ⁓ so so first I think for I hundred percent agree with the pattern you saw and I'll say this is similar with other technical evolutions. No not dissimilar to cloud. When cloud first came out, it became a very constrained thing of like who has permission access and then we we hit a punchline where we dramatically accelerated. Then of course we figured out, well, how do we govern in the right way? I think with AI it's different. I I think we're to the point that the ⁓ biggest risk of an organization will be not leveraging AI. In an environment where your competitors and the market alternatives are. And so I'm I'm square on the side that the security team specifically that's not ⁓ embracing AI use throughout their enterprise, ⁓ quite honestly will hinder that ability of the enterprise to be successful and accomplish its mission at the end of the day. So I think we're at the square adoption zone. The challenge we have in the square adoption zone is ⁓ if I assume AI is more than a chat box. So i if I start that that that's not actually ⁓ the outcome that people want is I have a question, give me an answer. Yeah. They're actually looking Speaker 1: Past that now. Yeah, we are past that. It is way twenty it's all twenty it's twenty twenty three. Speaker 2: Then then you're in you're in the zone where the typical organization is challenged with the AI maturity journey of how do I identify what jobs to be done? How do I set up those tasks? How do I set up the monitoring infrastructure so that I have oversight of the AI, just like I have oversight of what my humans do at the AI. And they'll go on a journey. The journey is hard though for the typical small and medium organization. ⁓ that's something where ⁓ we'll see them go. But but I think back to your direct question, we're in the harness zone and ⁓ the biggest risk to an organization will be not adopting AI. ⁓ that will be the thing that limits the trend line of a Speaker 1: Yeah, and I remember I remember vividly the cloud journey when the tw it was two thousand twelve, two thousand thirteen and I remember very vividly there were healthcare organizations, my data is so sacred, it can never go to the cloud. And my or you know, if it's a financial or bank, ⁓ my data is so sacred, it can never go to the cloud. And now I see all the new infrastructure is getting deployed, is now getting deployed to the cloud. And I think the transformation in AI is essentially going to be the same because if you ⁓ if you don't adopt AI, you risk being left behind. Right. You risk being left behind completely. Your competitors will just leapfrog ⁓ the capabilities and you'll be stuck with a chatbot or something, some silly thing that is irrelevant from a customer's point of view. Speaker 2: What love about the leapfrog is the analogy I'll use is mail versus email. So it it's that dramatic. ⁓ and so your choice of ⁓ using A or not using is like, you know, sending the letter versus sending the the email message or the Slack. ⁓ yeah, that's the analogy and I believe it with every part of my body. Speaker 1: Awesome. ⁓ what happens ⁓ what happens next? Do you so one one narrative I've heard is the AI frontier models are going to take over the world. ⁓ it's only going to be five model, five companies that relevant that are relevant. OpenAI, Anthropic, Google, you know, XAI, ⁓ add a bunch of open source tools, maybe Meta, I don't know, maybe meta is maybe not relevant. I don't know. But ⁓ ⁓ that is one ⁓ way to think about it is there is vendor ⁓ consolidation. That is one way to think about this problem. And the other way to think about this is there is vendor explosion. There is there are all these new ⁓ startups that come up, new companies that spin up that solve this one niche, one problem, and then you know, they they solve it so well that no one else can do, and then there is an explosion of all these things from there. ⁓ And I personally saw this in the cloud journey. There was there was a lot of ⁓ well Google is gonna take over and all these things, but then eventually you saw like an explosion, right? So what's w what's your take? Do you see vendor consolidation or vendor explosion? Speaker 2: Both are different life cycle stages. So let me be precise. With every technical innovation, you see vendor explosion as a way that we secure and protect it. So ⁓ in the near horizon, I think you see a rise in the number of organizations that someone works with to defend and operate across their environment as a defender. ⁓ though just similar to cloud at the end of the day. When cloud first came out, I had to have new tools, new acronyms, ⁓ that are gonna help me actually protect my cloud environment. So I think you see an increase. Then, ⁓ I think you'll see the consolidation journey come back in. So while you have a spike in the beginning, I think if you go a horizon out, horizon measured in two years, not ten, ⁓ we're back to a consolidation phase. But you asked an important question, which is do I see organizations consolidating all of their security apparatus with a particular friend? Well, hell no. Like like like like the the the one of the greatest ⁓ myths of platformization. is the the one platform to rule them all. I have never seen that ⁓ any customer environment I have ever met with any of the providers that exist today. Speaker 1: Do you think this time is different? Speaker 2: No. So so what what could be different is the number of different ones I see across an environment. But do I believe Goldman Sachs is gonna say, Don't worry, we have anthropic. We don't need any of the nine hundred or one hundred and other eight security tools across my environment. No. Like I like hard no. And that's not trivializing the criticality, ⁓ the value, the disruption that AI is bringing. And and so what we may see is like certain sectors, ⁓ Take ⁓ take ⁓ the ability to scan codes and look for vulnerabilities inside of it or you know, those spaces, you're you're gonna see disruption in sectors and consolidation. But do I actually will see that across the micro? No, the second thing that I'll say is in addition to consolidation, inside of security, the typical organization actually doesn't want a technology product. They want a services outcome at the end. And so ⁓ the line between product and technology has long blurred. ⁓ in a space where is what I'm looking for raw information, or is what I'm looking for an assistance in managing an outcome that I'm trying to drive at the end, I think you're gonna see the rise of the services organization. In fact, there's some well written research that says the next trillion dollar ⁓ software company is a services company. ⁓ but this notion of software as the capability expands is gonna continue to be disrupted and changed and AI is gonna have a big impact. That's actually Most people don't wanna buy software. That's not that's not actually what they're trying to do and solve in the market. They're trying to solve an outcome and they're gonna rot people ⁓ to multiply the impact of the technology. Speaker 1: So do you then think that the value gets concentrated or the value gets realized in the service industry, then the software or the SaaS side of the business? Is that what you're implying? Speaker 2: I I am, but but I need to be I need to be careful because I don't think it's as one of it's not a binary one and a zero. Because if I go back to where we were talking about AI earlier, ⁓ vulnerability uncovering and discovery for a moment. ⁓ just because I now uncover five X the vulnerabilities, I have a fundamental remediation problem that at the end of the day that I'm still gonna probably have software or services help me manage at the end. And so I don't believe ⁓ I believe sa software itself is fundamentally gonna change. So there's gonna be like a step function forward of like what is the software providing platform of the future? and ⁓ I also think the services wrapper is something that the typical organization is gonna be expecting at the end. Because if we go back to the the skill sets that we're now talking about, I'm a regional bank in Minnesota. ⁓ ⁓ do I want to defend my apparatus, a, you know, five software partners? Or in the end, of like, do I want an organization to help me defend through software and AI use combined? I I believe the latter. I I really do. ⁓ and I think we see evidence of this. It's often just time blurred and how it operates. There's a whole lot of ⁓ software companies that spend a lot of money on customer success that starts to smell a lot like services if you look at it closely, I think you're gonna see that multiplied over a horizon. Speaker 1: Do you think there will be a renaissance of like margin expansion in the service industry? The traditional model is the the SaaS providers had like eighty percent margins and then the twist providers had like a twenty percent margin or maybe like a ten percent margin. Like do you think then like the service providers will have or at least have a line of sight for software like margins in the age of AI where they can do more with less, ⁓ and then deliver the same outcome, or is that like a fantastical pro prediction? Speaker 2: No, so so direct answers yes, I do. So to be clear, I think you'll see ⁓ service organizations with software like margins. And I also believe markets have a way of being efficient. And so as ⁓ more and more organizations have software like a service organization have software like margins, you will see a new rise of services organizations that ⁓ are looking or are willing to do a different margin profile, which will change the margin quality. So we'll we'll see a cyclical curve of more efficiency. But what makes it exciting for defenders is one of the fundamental problems of cybersecurity is cost effectiveness. My ability to actually afford everything I need to do and believe to be defended. That I think will see a compression across of what the typical product cost or capability costs at the end of the day. Email monitoring, pick an example today, think across the horizon, that's going to cost less, which is then going to give more and more organizations a chance to implement these security controls. Because again, to say it twice, the typical CISO knows there's areas in their maturity journey they want to do next. And so how do you make that cost effective at scale? I think that's what gets really exciting. Speaker 1: Do ⁓ do you think then the the role like if there is I guess more expected for the human analyst ⁓ to do with these services, then d does their role change in a meaningful way a meaningful way? Like the f role of the security analyst or the security engineer? Speaker 2: Hundred percent. I I I think it's a ⁓ there is there will more be different than is the same. ⁓ because today the role of an animalist starts with let me process information, reach a conclusion, determine which action to take. ⁓ I think those tasks are gonna be dominant automated in a way. However, I stand by the statement I made earlier. I don't think the security size of organizations is gonna decrease in aggregate. I think you're actually gonna find rather a rise in security maturity. The cost of compromise is too significant, the ROI of spending on security is too high, or the cost of not doing it is too big. Speaker 1: Reputation damage is too high. Once you lose the reputation everything is done. Like if you're once we turn on you're done. Speaker 2: This is going to be one those magical areas of efficiency will bring enhanced outcomes. ⁓ and I think it will do it in a way that's gonna enable security defenders to focus on higher value tasks as opposed to lower value tasks, as well as organizations to have ⁓ less security incidents across the horizontal. Speaker 1: Awesome. Awesome. ⁓ Craig, ⁓ last last topic for today. ⁓ let's do let's do some predictions. ⁓ yeah. Given all that we have talked about, do you think the first first question, ⁓ do you do you think there will be more C V E's in twenty six, twenty s t twenty twenty six and twenty twenty seven compared to all the years combined before? Speaker 2: ⁓ all the years combined. I thought you were gonna ask me if there's more and I was like, this is a softball question. Of course it was yes. no, not all ⁓ excuse me. There will be more in each of those years. ⁓ those two years will not be more than all of total history. My prediction it doubles a number. Speaker 1: Are we going to be secure by default or more of the same? Speaker 2: More of the same. ⁓ the why behind it is the weakest link in an organization is still the processes, the people that execute it, not the the tool at the end of the day. That's the laggard and innovation that I think we're still need enhancement on. Speaker 1: D do you think new new attack vectors emerge or do we see more of the same? Speaker 2: So so this is a both one, which is there are new attack vectors. If you ask me the question of which ⁓ attack vector is most likely to compromise, more of the same. We're still on the point where people clicking on links, ⁓ compromise credentials, these still have a shocking percent of incidents occur. So the more the majority of compromises that occur are gonna be more of the same. Sure, there's gonna be new novel attack vectors that come out. ⁓ But it's more of the same. It's gonna be the typical risk an organization's gonna face. Speaker 1: Next prediction, by end of 2027, do we see more enterprise security tools or less in an enterprise? Speaker 2: more excuse me end of twenty twenty seven ⁓ you're now you're right now in my inflection curve less I think you see a spike ⁓ between now and then so I think it starts going up and then I actually start to see the point of decline. So if you would have said 2028, I think there were screw tools provided right at the end of 2027, I think it's when the decline starts. Speaker 1: Last prediction that this is a fun one, because of AI, do we see more good guys becoming criminals or do we see more criminals becoming good guys because they have nothing to do? Or n nowhere to hide? Speaker 2: More good guys becoming criminals. So Speaker 1: It's easier to attack and completely Speaker 2: I as simple, which is cybersecurity, we've always had our colorful characters of ⁓ of attackers that become defenders and have well learned places. That's a well learned trough. I think when you make ⁓ something easier to do and it's binarily easier to operate and implement a cyber attack than difficult, you will see a dramatic rise ⁓ at the Speaker 1: Dramatic rise of what, good guys becoming criminals? That is good point. That is a good point to end this interview. This is this ⁓ Craig, this has been ⁓ an epic interview. Thank you for your time. You're way too generous. yeah maybe you come back again next year and then we revisit these predictions and see how accurate or inaccurate you were in terms of Speaker 2: What good point in the interview. wine for that conversation but count me in