This episode explores how AI is transforming the cybersecurity threat landscape, featuring Gregory Richardson and Ismael Valenzuela from BlackBerry. They discuss the evolution of cybercrime, the motivations behind attacks, and BlackBerry's strategy for defense, emphasizing the distinction between AI hype and practical applications like predictive AI and classification. The guests highlight the ongoing 'AI standoff' between attackers and defenders, stressing the indispensable role of human expertise in navigating complex security challenges and the future risks and opportunities AI presents.
Welcome to Practical AI, the podcast that makes artificial intelligence practical, productive, and accessible to all. If you like this show, you will love the changelog. It's news on Mondays, deep technical interviews on Wednesdays, and on Fridays, an awesome talk show for your weekend enjoyment.
Find us by searching for the changelog wherever you get your podcasts. Thanks to our partners at fly.io.
Launch your AI apps in five minutes or less. Learn how at fly.io.
What's up, nerds? I'm here with Curt Mackie, co founder and CEO of Fly. You know we love Fly.
So Curt, I wanna talk to you about the magic of the cloud.
You have thoughts on this. Right? Right.
I think it's valuable to understand the magic behind a cloud because you can build better features for users, basically, if you'd understand that. You can do a lot of stuff, particularly now that people are doing LLM stuff, but you can do a lot of stuff if you get that and can be creative with it. So when you say clouds aren't magic because you're building a public cloud for developers and you go on to explain exactly how it works, what does that mean to you?
In some ways, it means these all came from somewhere. Like, there was a simpler time before clouds where we'd get a server at Rack Shack and we'd SSH it or Telnet into it even and put files somewhere and run the web servers ourselves to serve them up to users. Clouds are not magic on top of that.
They're just more complicated ways of doing those same things in a way that meets the needs of a lot of people instead of just one. One of the things I think that people miss out on, and a lot of this is actually because AWS and GCP have created such big black box abstractions. Like Lambda's really black boxy.
You can't like pick apart Lambda and see how it works from the outside. You have to sort of just use what's there. But the reality is like Lambda's not all that complicated.
It's just a modern way to launch little VMs and serve some requests from them and let them like kind of pause and resume and free up physical compute time. The interesting thing about understanding how clouds work is it lets you build of features for your users you'd ever would expect it. And our canonical version of this for us is that like when we looked at how we wanted to isolate user code, we decided to just expose this machines concept, which is a much lower level abstraction of Lambda that you could use to build Lambda on top of.
And what machines are is just these VMs that are designed to start really fast or designed to stop and then restart really fast or designed to suspend sort of like your laptop does when it closes and resume really fast when you tell them to.
abstraction on top of generally like Linux kernel features. A lot of our platform is actually just exposing a nice UX around Linux kernel features, which I think is kind of interesting. But, like, you still need to understand what they're doing to get the most use out of them.
Very cool. Okay. So experience the magic of Fly and get told the secrets of Fly because that's what they want you to do.
They wanna share all the secrets behind the magic of the Fly Cloud, the cloud for productive developers, the cloud for developers who ship. Learn more and get started for free at fly.io.
Again, fly.io.
Welcome to another episode of the Practical AI Podcast. I'm Chris Benson. I'm a principal AI and autonomy research engineer at Lockheed Martin.
And with me today, I have two guests that are gonna join in the conversation. They are both from BlackBerry. One is Gregory Richardson, who is vice president and global advisory CISO at BlackBerry.
And there's also Ismail Valesuela. Did I get that correct? Yes.
Thank you, Chris. And I normally have Daniel for that. And he is vice president of threat research and intelligence at BlackBerry.
Gentlemen, welcome to the show. Thank you so much for joining. Honored to be here, Chris.
Thank you. Thank you, Chris. Really glad to have you.
We're gonna talk today all about security and threats and issues like that. I know that there's a blog post to get us started, and I'll let you guys kinda take it from there that that you have on the BlackBerry blog that was the AI standoff attackers versus defenders. And I know Daniel was the first person to see it and said, We gotta get these guys on the show.
And then ironically, he is not able to get here today, and I know he's disappointed about that.
But wanted to kinda start off and kind of, can you tell us a little bit about the topic in general before we dive into the specifics and the landscape and who does it affect and why should they care? So maybe it has to do a little bit with our backgrounds as well, right? So I cannot really say I'm an expert in AI.
Well, I cannot really say I'm an expert on anything. And the more I spend time in this industry, less you feel you know, right? But I can say my career has been mostly dedicated to cyber defense.
I started on the offensive side, but then I quickly moved into the well, not quickly, but over years, I moved into the defensive side. So I've seen both sides and I still like to pick on the offensive side to learn from it. I call that, think red act blue, right?
Think as an attacker to become a better defender. So obviously, when I was writing about this, I had to bring the AI flavor to it, like is it really, is AI going to represent an advantage to attackers or defenders? And we usually get that question.
So I wrote this from a cyber defense perspective.
Right? And and that's what you see there. So before we dive fully into the article, what what was driving the need?
What are you seeing? You guys both at BlackBerry, there's clearly a need driving, addressing cyber. Tell us a little bit about how you see the lay of the world from a cyber standpoint and what it is that you know, what what's the problem you're trying to solve in the large?
Yeah.
kind of perspectives because I actually didn't know that Ismail, who I've worked with for many years now, even at different companies before BlackBerry, I didn't know that you were, you started on the offensive side and then switched to the defensive side. I am very much the opposite, well, except for the switch. I started on the offensive side, and I remain on the offensive side.
The part that I am most intrigued by and always have been is what I call well, what's called vic attacker ontology. So I've always wanted to understand what makes the attacker behave like an attacker so I can better defend. But my primary areas of research and areas of work and my primary focus has always been trying to anticipate what the attacker is going to do, you know, so that I can help our clients strategize, etcetera, etcetera.
It's always been like even before. And just from an AI perspective, cybersecurity has been using AI for well over twenty years. I'd say probably thirty years almost.
So it's not as novel as it is to, you know, the average layperson. But even before the popularization or the democratization of AI that we've seen in the last two, three, four years with companies like OpenAI, etcetera, Even before, you know, AI was so much in the forefront. I've been very intrigued with how we can build strategies that help customers, organizations, governments anticipate earlier what they need to be protecting against.
And that's kind of where my perspective comes. So my I didn't contribute to to the blog, I believe was primarily Ismail's blog and maybe Ismail and his team. But my perspective on the blog was very much how can we use AI to also help level the fields a little bit more?
It's a constant, you know, battle with the fields going back and forth and kinda who's winning the race between attackers, you know, cybercriminals, and defenders.
anything we can use to help balance that out, that's always been my interest. I'm curious, before we fully dive into the AI stuff, can you describe because, you know, we we have a very AI focused audience, diversely in that area, but a lot of folks maybe have never been really addressing cyber themselves. And when you talked about that, the ontology, and kind of talked about maybe some of the motivators that, you know, why what are these people out there?
Who do they represent? What are they trying to do at a baseline, like with or without AI? What are we dealing with in the world?
longer than most. I'm like your age, Chris, So I'm approaching 60 years old. Yep.
Exactly. Old curmudgeonly. Get off my lawn.
That's right. So I'm approaching that age, that, you know, scary age of 60, at least is scary to me. So I remember a lot of things historically about the cyber security industry that give me perspective.
One was I want to say it was around twenty ten, eleven or '12, somewhere around there. It was the first time that I noticed in the FBI's threat intelligence report that they used to release every year in that report around twenty ten, eleven, twelve was the first time that they reported, the FBI reported that profits derived from cybercrime surpassed globally, surpassed profits from heroin, cocaine, marijuana sales combined.
Wow.
And for me that and I'm talking this was, you know, 2010, like I said, that to me was a tipping point. That's in my mind, I've built the narrative that right around then or maybe a year or two, year or three before then or after then, that's when a criminal organizations focused in on cybercrime. And it switched from being, you know, the harmless hacker in the grandma's basement.
You know, I'm thinking like a Kevin Mitnick type of a guy who who who kind of started off that for those who are in the cyberspace. They know the name. You know, he was kind of like a quote unquote harmless hacker.
He was arrested. I think he might have been one of the first cases of of a full fledged arrest and conviction for cybercrime. But, you know, his his cybercrime was always focused on what can I learn?
You know, what can I gain from these things that I'm illegally getting access into? It was less if at all, it was not about, you know, what can I financially gain? Now it is largely financially motivated.
I'll let Ismail deal with this a little bit more because, you know, this is his forte. He runs our threat organization. But from my perspective, it is largely based on what can we monetize.
Ismail, what do you have to add to that? Well, the first thing is I'm so happy to know that I'm the youngest one in the room. Okay?
Says me with a white beard. Right? We're all showing it a little bit, but that's okay.
We're on top of things, man.
our job is to characterize the adversary and to translate that into, we call it countermeasures, right? So think about, you know, you're analyzing, or your goal is to design a vest to protect law enforcement, for example, right? So we analyze the weapons, we analyze their tools, we analyze their motivation, How they operate.
And then we take all of that and we use this information to design the most effective vest to protect against those bullets, right? But it's not just about the bullets, it's about like who is using these weapons and what's the reason they're using them for. That's the motivation, that's really the key piece.
And this financial motivation, Greg has been saying, has been growing very fast. And that's why we all know about ransomware, for example. But there's a lot of other motivations and maybe we don't talk about that much.
Well, some of them we do. Spionage, nation states, the so called APTs, advanced persistent threats, that we often see in the news, especially, you know, right now around election times, there's a lot of talking about this manipulation of information by these nation state actors. These are very well funded and typically they're the most advanced of all of them.
But there's other motivations too, there's hacktivism. You know, we have seen groups like Anonymous in the past, like many others, that they would target organisations just because they make money, I don't know, records, right? And they think that's evil.
But at the end of the day, cyber is just a weapon, right? It's a weapon that can be used for good. It's a weapon that can be used for evil, same as AI, right?
AI is just one more tool in the arsenal of any of these people.
cyber war if you want. So how does BlackBerry, can you kind of layer in BlackBerry having kind of given us that landscape of what you're what you're looking at in the world? And how does BlackBerry start layering into this?
What are what are your interests in that capacity, and what are you trying to accomplish? Good question.
for quite some time, right? I think everybody those Blackberry devices. Don't do devices anymore but we do software to protect devices, not just phones but also endpoints of you know, all over all over the world.
And specifically my team, what we do is to, as I mentioned before, try to characterize these attackers to be able to protect customers, right. And this takes the form of products, it takes also the form of services From endpoint software to zero trust network access to, you know, high military grade encryption, secure communications, to even software to manage a crisis. It could be instant response, like the environment's on fire, the attacker's here and we need to remediate that or it could be even like a natural disaster.
So when we talk about threats, we just even go beyond just the cyber security threats. That's a high level overview. Don't know, Greg, if you wanna go deeper into that.
I don't know if I'll go deeper.
off of one of the branches. The side of BlackBerry that I'm maniacally focused on is really just, I wanna say, purely the cybersecurity part. So obviously, BlackBerry does a lot of other things.
We have our automotive and IoT, section segment that that's very, very, very large, probably a billion dollar business in and of itself with, you know, operating systems that run-in any car that has anything digital in it, etcetera. The part that I'm focused on though, is pretty much purely my area of expertise, which is cybersecurity. So, what we've been doing from my side of the house is helping customers build their defenses in a way that allows them to do something that I call preemptive security.
If you remember in my earlier preamble, referred to, you know, we need to be able to predict what the attackers are going to do so that we can defend against it. I help my customers strategize around building those platforms, those tools, those combination of different tools to do exactly that. The nuance of it with cybersecurity is just because of organically how the industry has grown and VC investment and a million other reasons, we've sprawled very much into, there's thousands of tools to get the job done.
And there's probably thousands, if not tens of thousands, of different little aspects that need to be protected in the average organization. You might have endpoints, computers. You might have servers, you might have a network, you might have stuff up in the cloud, you might have operational technology or IoT technology, all different aspects, that all need to be protected, that all require completely different tool sets.
That sprawl has made it difficult for customers to have a homogenous approach to how do we defend against it all. Ismail can probably talk more about one of the things that attackers do, I want to say very, very, very well, is attack the gaps between our tools. So if they detect that you have a great tool that, you know, is the foremost tool on protecting computers, your endpoints, but your network stack is a little bit weak, they're gonna attack right in the middle of that network stack and gain access to the endpoints.
Vice versa, if they see your network and your endpoint rock solid, but you have a weakness over in the cloud, you're gonna start seeing cloud attacks. What the industry has not been very good at that BlackBerry is trying to help resolve is how do we help customers pull all of that telemetry in to be able to get, as I said, a homogenous view of everything that's attacking them and everything they're doing about defenses across all those little silos. That's what I help my customers strategize on.
And my customers vary from governments. I met with the government of Morocco a couple of weeks ago, two large corporations, the biggest banks in the world, the biggest airlines in the world, etcetera, etcetera. And it just spans the range, but all of them have that problem.
The most mature organizations have well developed tools that are unintegrated, and the least, like the SMBs, which are also our targets, our customers, have six oftentimes less developed security stacks, but the problem is the same. Even if they say, well, know, we can make an investment in this one little tool, then they have their gaps and they're not being able to ingest all of that intelligence that they have. It says something about the industry, and I'm going to kind of shoot at my own job now.
It says something about the industry that a strategist at that level focused on those types of problems is even needed. Like you don't have that in the medical industry, as far as I know. You definitely don't have that in, for example, the automotive industry.
Like there aren't integrators that need to help you with how to integrate, you know, your car to work properly. You go to Ford, you say, I want a SUV. They give you the whole SUV.
They don't say, buy the motor here and then go down the street and get four tires and go across the way and get a transmission. You glue it together and you make it work. They give you the whole thing.
Cybersecurity doesn't do that. We don't give you the whole thing. So that necessitates a cross section of strategists like myself and the team that supports me to go out and actually help customers parse through this web of tools that they've built.
If I, you probably don't go to cybersecurity industry events. I do, Ismail does as well. Ismail speaks at many of them.
The amount of vendors on the expo floor, I remember going to RSA thirteen years ago or so, handful of vendors. It was a small convention. Now, it's early thousands, three, four, 5,000 vendors.
40,000 people last year. That's a lot. And, dude, I I thought it was blig.
I went to a conference called Jitex. Holy spook. Almost a million people at Jitex at a conference talking about techno it was crazy insane.
The amount of boots, I think it was 40,000 vendor, like insane that there's an appetite for all of these tools and customers are bubbling them up. And it makes their environment more complex and that's where we oftentimes come in. And noisy too.
There's a lot of noise in this industry.
Okay, friends. Here's what I love about Notion, and I'm a big fan of Notion. I think all the new improvements they've made recently with Notion AI built right in is just astounding.
Being able to have your notes, your docs, your projects, your to dos, your tasks, your dashboards, all the things in one single place beautifully designed, and then add on top of that Notion AI with the ability to search, analyze, chat, and even describe to you how to build dashboards. You can ask it, hey, I wanna do this, and it will help you build out a dashboard or a database or a template that makes sense for you, your workflows, your business, your orgs, or whatevers. Notion really is the perfect place to organize your tasks, track your habits, write beautiful docs, collaborate with your team.
There's just so much you can do with it, and Notion AI already has the context of all that work. It's also connected to multiple knowledge sources. It uses AI knowledge from GPT four and Claude to chat with you about any topic.
And you can search across thousands of Notion docs in seconds to quickly answer really any question you have about your context, which is all of your Notion docs. They also have AI connectors. This is now in beta.
Notion AI can search across Slack discussions, Google documents, Google Slides, Google Sheets, and even tools like GitHub and Jira, those are coming soon. And the cool thing with Notion is it could be used by small teams, individuals, or even Fortune 500 companies. It is a very scalable tool that can help you spend less time emailing, cancel more meetings, save your time searching for all your work, and reduce spending on multiple tools.
And this helps everyone be on the same page. Try Notion today for free when you go to notion.com/practicalai.
That's all of our case letters, notion.com/practicalai to try the powerful, easy to use Notion AI today. And when you use our link, of course, you are supporting our show, and we love that.
Again, notion.com/practicalai.
Okay. So as you guys have watched the industry explode and you're and you're dealing with these things that that other industries don't necessarily have to address, you talked about kind of just the sprawl of assets to defend and the gaps between them, and the fact that there are so many tools addressing different components. I would imagine that's quite a challenge, which is one of the reasons I'm sure the industry has gotten as big as it is.
As you're looking at that, and you're starting to see these new things, and when I say new, meaning some of the more recent tools on the AI realm and stuff like that, as cyber experts, how is AI starting to layer into this ecosystem? How do you see that? What are the pros and cons, the risks and threats that it creates?
Can you tell us a little bit about how those two converge?
Yeah, as Greg also mentioned it before and explained really well that this is an industry that is always like chasing the new shiny, right? Like what's the new thing that can solve all of my problems? And there is no such a thing.
It's a lot more complex than that. And every time that we try to find that single tool, that super bullet, we often fail, right? Because of a lack of an understanding of how all these things need to come together.
So we're in the middle of that hype. And now the tool is, of course, AI, right? And I would say even more specifically LLMs, generative AI, because we know and you guys in this show know well that when we talk about AI, it's not one thing, right?
It's a lot of different things. For example, at BlackBerry, we have been using for many years, coming from the Silence engine, from the Silence days, a predictive AI engine, right? We know we're talking about predictive machine learning, essentially.
And I remember, well I wasn't at Silence at that time, but some of my colleagues at Ware told me that they were at Black Hat, I think probably 2016 or something like that, right? They were talking at black hat about this and a lot of people were like, you know, that's not possible. You're selling smoke.
You know, that's not the way you detect malware. Fast forward to today and everybody understands that you cannot fight malware with signatures, right? I mean, in our report, and we produce these reports on a quarterly basis, we talked about the latest increase in the last quarter, we're talking about a 53% increase in unique pieces of malware, Right, I think, I don't know if the audience is familiar with the concept of a hash or a fingerprint.
You take a binary blob of data and you create a fingerprint or a hash of that and that says, okay, that's unique, right? Different hashes, different files. So we're talking about over 11,000 pieces of unique malware per quarter that we have seen with our telemetry.
How in the world are you going to create a database or maintain a database? It's an unscalable issue. It's not scalable, right?
So predictive machine learning helps us with that. And it's been helping us for many years to have like really, really good detection of these type of things. Now LLMs can also be useful for different things.
So once again, I think the summary is AI is a useful tool in the hands of defenders. It is also used by attackers and we can maybe get into that if you want. But I would say that once we go over this hype cycle that we always have in this industry, we'll probably understand that it's just one more tooling in our arsenal and that we need to remain problem focused.
Just because we have a solution to a specific thing, it doesn't mean that it's going to be solution to absolutely everything. Right? But of course, it helps.
Yeah. I'll comment on that if I may, Chris. Sure.
Absolutely. Ismail touched a little bit. He's kind of grazed over LLMs.
And I'm glad you only grazed over it because of what I'm about to say. We think LLMs, as good as they are and they have some excellent use cases and value, I think they contribute to a lot of the noise and the hype machines that we hear in the industry right now. I'll speak specifically for cybersecurity.
I am not yet convinced of the utility, the usefulness of an LLM, particularly for its natural language, ability ability to process things via natural language. I'm not sure that that was the problem we had. I speak to SOC analysts and chief information security officers literally on a daily basis.
That's my job. I've I can't remember in the last thirty years doing this that a group of operators, SOC analysts, etcetera, have told me, you know what would be great, Greg? We don't know how to extract the data from our tools.
If we could only say that in natural language, that would really help. That's not the problem. The people that are doing these jobs in the socks, etcetera, etcetera, very adept at their tools.
They don't have the problem communicating with the tools and writing a a a parsing command or a a query or whatever to extract the data. That's not the issue. There's other things that AI and machine learning can help with.
Classification is a big one. Ismail has already referred to prediction. I think that's a very, very big one that is underutilized today.
But classification, how do we classify not only files and hashes, but behaviors, indicators of attack, indicators of compromise? How are we able to classify, you know, these three things that are connected together or in the case of a cyber attack, these 50 things, these 50 behaviors or indicators we find, how can we pull them all together and say, listen, this is leading up these all belong together. These 10 things that we found on your network and these 15 things that we found on your endpoint and these 12 other things that we found simultaneously in the same temporal window in your cloud environment, they all belong together and they're all part of one attack.
That classification process, I think that's somewhere where AI can help because that's where the gap is. Taking the ton of data that comes in that swamps our security operation centers with alert fatigue, parsing through that to quote unquote make sense of it and kind of narrow it down to a few cases. And when I say few, though, that few may be thousands still, but it's a order of magnitude or more drop from the tens or hundreds of thousands of events that you get.
If you can drop that down to a significantly smaller amount of cases and then tackle those cases, that's one of the problems that I see AI solving in cybersecurity extremely well. It's really interesting to hear you say that.
Just as an aside for a moment, for our audience who is going episode to episode, this is a topic we talk about a lot. It sounds like you're going through, you're familiar with the Gartner hype cycle. It goes up over the top, maximal hype.
People become frustrated. It plunges down in the trough of disillusionment where they're very unhappy, and they say, This stinks. Don't wanna And deal with then people kinda take a second look, and they go, Well, it's good for some things, it doesn't solve everything, and they find their plateau of productivity where it's actually useful.
And it sounds like you've been going through that same process like many other industries have, you're really practical. And you also drew out another point that I'd like to emphasize, and that's that when it comes to generative AI and LLMs and such, we have a habit of forgetting that there are other techniques in the AI realm out there. Classification Both ways.
Yeah, exactly. And you guys are like, we have other tools here that are really productive for what we're doing, just maybe not the super hyping part of it.
are practical AI on the show and we're trying to get people on track. I'll just give you an example of how absurd this is getting. I saw a large vendor, and I'm really tempted to say the name, but I want, that was showing you know, how cool these generative AI is applied to the SOC.
So you know, the SOC security operations center, they typically use dashboards, right? They have dashboards and they're looking at, for example, number of DNS requests or number of alerts for these or for that. So there's this dashboard and there's a peak of activity at 7PM.
So now the the LLM is like, see, I saw a peak of activity at 7PM. I'm like, how much money are you paying for that? Right?
There's a large cost in this type of subscriptions. And I can easily train an analyst to catch that and that person can give you even more context, right? And have probably more intuition, more maybe even knowledge of the strategy, right?
Talking about strategy, Gregory. And even more creativity than that. So absolutely, like you kind of know what the tool is useful for.
It's very useful for contextualization, summarization, pattern matching, generalization, hypothesis testing, right? I could go and say, Hey, based on all of these reports that I have written on all of these database that I have, give me a going to the offensive side, Greg give me an emulation plan for emulating this threat actor, right? And it's not going to be super creative because it's going be based on things that have already been the data that has already been gathered.
But it will save me a lot of time because I will not have to go through all of these documents myself and have to extract all of these different things. So I may iterate over that faster and get to that faster. But yeah, there's a lot of hype.
again, I've been in this industry for almost forty years. So it's pretty much the only thing I've done professionally, you know, since I came out of college. So I'm very passionate about it in case that's not extremely evident to your audience yet.
Therefore, also, I also tend to look at myself and my industry with a really, sometimes a bit of a harsh lens. And so I'm gonna say something now that might be applicable outside of cyber, but I see it from inside of cyber. And we gut ourselves.
We do legit harm to ourselves by feed and when I say we, the vendors primarily, by feeding into the hype cycles and selling stuff that we know good and gosh darn well are absolute smoke and mirrors or have limited usefulness, but they sell well. You know, the the notion of we're gonna have an AI powered SOC and you're not gonna need SOC operators anymore. You know, you you you all these analysts, you you won't need them.
You're gonna get just less analysts because the AI is gonna do all of that for you. The more we hype that up, the more you get that the Gartner flip cycle where people try it and they go, oh, god. This is doesn't work this way at all.
I still need the humans. The humans add, as Ismail said, context and awareness and situational strategy, not to mention things like morality, which AI is terrible at. Now, can the AI do bulk volume of data processing?
It absolutely can. And that's where that's one of the places we should lead into. It's been touched on things like vision and, you know, some of the more esoteric parts of AI that we don't speak about every single day.
So I'm not limiting it to prediction classification and large language models, but I'm just saying large language models are amazing. I use them regularly for processing anything having to do with language, whether that's, code language, indicator language, or spoken read language. One of my very practical things that I do with almost every piece of content I'm attempting to digest now is I I try to get the audio and I run a transcript.
Send it to Whisper. Send it to whatever API. Give me a transcript of it.
Analyze the transcript for me. Give me some key talking points. What are the things that I said, what are what are some tweetable lines that I wanna broadcast out, what are some key quotes that I that I said.
And I build my brand on social media, and I flavor my other talks with that content that I've said already. I'm going to do it with the talk that I'm doing right now. That's why I'm in addition to as a backup, I'm also recording my own audio here so that I can extract that.
And so that I use LLMs. They have utility. But it's, they're not the end all panacea, you know, oh my God, they're great.
We should throw everything at an LLM. It's the more we do that, I think the more we do intrinsic harm to the industry and most importantly to our customers' ability to defend themselves because the threat actors are not, at least I don't see the threat actors out there building a hype cycle. I see them out there efficiently sharing threat intelligence and leveraging it to build new novel attacks that there's unique ways that they can get their objective, which is, you know, monetize weaknesses in our environment.
We are not as maniacally focused on our task at hand as that yet.
What's up, friends? I've got something exciting to share with you today, a sleep technology that's pushing the boundaries of what's possible in our bedrooms. Let me introduce you to Eight Sleep and their cutting edge Pod four Ultra.
I haven't gotten mine yet, but it's on its way. I'm literally counting the days. So what exactly is the Pod four Ultra?
Imagine a high-tech mattress cover that you can easily add to any bed. But this isn't just any cover. It is packed with sensors, heating, and cooling elements, and it's all controlled by sophisticated AI algorithms.
It's like having a sleep lab, a smart thermostat, and a personal sleep coach all rolled into a single device. It uses a network of sensors to track a wide array of biometrics while you sleep, sleep stages, heart rate variability, respiratory rate, temperature, and more. It uses precision temperature control to regulate your body's sleep cycles.
It can cool you down to a chilly 55 degrees Fahrenheit or warm you up to a good, nice, solid temperature of one ten Fahrenheit, and it does this separately for each side of the bed. This means you and your partner can have your own ideal sleep temperatures. But the really cool part is that the pod uses AI, and it uses machine learning to learn your sleep patterns over time, and it uses this data to automatically adjust the temperature of your bed throughout the night according to your body's preferences.
Instead of just giving you some stats, it understands them, and it does something about it. Your bed literally gets smarter as you sleep over time. And all this functionality is accessible through a comprehensive mobile app.
You get sleep analytics, trends over time, and you even get a daily sleep fitness score. Now I don't have mine yet. It is on its way.
Thanks to our friends over Eight Sleep, and I'm literally counting the days I get it because I love this stuff. But if you're ready to take your sleep and your recovery to the next level, head over to 8sleep.com/practicalai and use our code Practical AI to get $350 off your very own Pod four Ultra.
Now you could try it free for 30 days. I don't think you wanna send it back, but you can if you want to. They're currently shipping to The US, Canada, United Kingdom, Europe, and Australia.
Again, 8sleep.com/practicalai.
So Greg, that was great kind of explaining how you're approaching that, trying to keep the AI practical, trying to have the right AI in the right place. And great call out for the fact that like so many other industries, there is a proclivity in your industry to also do the kind of AI in everything. You know, you said, you used the phrase, you know, selling smoke and mirrors and stuff, and you guys working really hard to productively give solutions and strategies that are not built around the hype side of all this.
Could you dive into a little bit more of that? And also Ismail, if you could also address a bit about the blog itself that you wrote so that we can draw of our listeners into that, and they can also read that as they're finishing up the episode and understand that. I really appreciate that.
So kind of both the, what are you doing in that practical sense?
And what are you producing for your customers? And then kind of how is the blog contributing to that? Do you want to start maybe with the blog and then Greg, you can talk about the solutions we're building.
Yeah, so the blog is essentially trying to address the hype that we're just talking before, right? And saying, so what is AI being used for by the attackers? Let's start with that.
Some people may think that, you know, attackers are crafting this malware that is autonomous, that it just goes out and finds a vulnerability like a zero day, right? We call zero day in this industry like something that we haven't found yet, it's no avail, nobody knows about that vulnerability. Now this autonomous agent is going to exploit it, it's going to get into the company, steal the data, ransom the environment and no.
Then you wake up, right? There's no such thing. Not as of today, at the very least.
I think we're talking about people I'm going say around the same age. You probably remember Blade Runner from 1998 the original one, right? The replicants.
There is no replicants as of today. There is deepfakes, that's a different thing that could look like humans, that's the closest thing. But there's no autonomous agents that can do all of these things.
Or we don't see people that, I don't know, like you are training dolphins, right, for your entire life and then all of a sudden, now because of AI, you can hack into companies and make a lot of profit out of that. Probably not. So what we see is attacker systems use as a tool essentially for the initial phases of the attack.
And that means that they're getting a lot better at writing phishing emails. We have seen an increase in phishing emails with language that's non English. For example, before, we would see some of these Eastern European organizations or Russian criminals sending emails in English that was like broken English.
And you could quickly spot them and say, Oh yeah, this is phishing or spam. These days everybody speaks not only perfect English, also perfect Japanese. We have seen an increase in number of phishing against Japanese companies, other languages that hardly would be used by these cybercriminals.
And that's a clear use of LLMs. Now in terms of coding, there's a lot of debate, it's very controversial, right? Like, can you learn coding from scratch or can you just like use this to create code from scratch and we'll do these things?
Probably not today. These models are getting better, but I still find out that every time I ask any of these agents to create some code for me, still have to understand the code, understand what I'm trying to do and being able to refine it and to tune it. Also bear in mind that these models are crafting things based on the training that it has received, based on previous data that is already known.
Therefore, when Greg maybe talks about predictive solutions and AI, that makes us also even more successful in the use of our AI because we have trained these models with everything that has been seen in the past as well. So at the end of the day, I think that AI is not going to be that much of an advantage to attackers. There's always a little advantage, but just because they're attackers, because they take the first step.
You're on the defense side and you don't know, right, if they're coming tonight, if they're coming tomorrow morning or if they're coming next month. You may anticipate that and that's where my team does threat intelligence, which is looking at the geopolitics, looking at like the weather forecast, right? What are the cloud signaling?
And then based on that, you adapt your threat model. But you're always like one step behind by nature. That's what defense is about.
But even though defenders may take, may have that temporal advantage, I think when used properly by defenders, the field could be leveled and AI could be effectively used to do more things at scale, especially when you have a solid strategy.
It's interesting that Ismail referred to updating our threat model, and he drew that analogy back to, you know, like the weather. You know, like like you look at the clouds and based based on what you see in the clouds, you react accordingly. You might pack an umbrella or something along those lines.
I think that's such a a propelled analogy because interestingly, as it killed in the seventies, growing up in The Caribbean in a hurricane zone, I remember sitting around the big box TV in the living room. I think it was even black and white at one point because I'm old and permudgeonly, as I said earlier, and watching the predicted hurricane track for some storm that left the the the Western Coast Of Africa that's barreling towards the Caribbean Islands. My island is a small five mile by seven mile island.
We could get and routinely got decimated by hurricane. If a hurricane's coming, you need to know. Those predictive tracks with the little circles and saying the storm looks like it's gonna go there, those in the seventies already were drawn and calculated by AI.
It was one of the first very widely, used use cases for predictive AI. So it's interesting that Ismail uses that as an analogy because that is exactly what we're doing. We're taking a use case that was well developed with weather prediction, and that's what we're applying to attacker prediction.
So you asked how we can apply this to the customer environment. One of the things that I am maniacally focused on right now is helping customers, as I said earlier, draw this all together. So I'm not gonna get into product names because this isn't a sales pitch, but we've just developed something in the category called a managed, extended, detect and response toolset.
And what's unique about our approach to that, that approach in that space is not unique at all. It's been existed. Just about every large cybersecurity vendor has something that plays in that space.
What's unique about our take on it, we are heavily focused on regardless to what your security stack consists of. That's what we're gonna ingest. Most of the other vendors use XDR type tool to say, listen, to get the maximum benefits out of our tool, you should really be using all of our stuff.
So you should get our firewall. You should get our endpoints. You should get our cloud stuff, and then it's gonna be maximized.
Our take is different. Our take is we understand that you, the customer, probably struggle with two things, a widely diverse, ecosystem of security tools. And the second thing, especially for medium to smaller companies, you're probably struggling with finding the human resources to do these jobs.
So we we have a managed solution where our threat analysts, our security analysts, our well trained human experts combined with predictive AI that, as Ismail said, has been well trained on sensors and sensor data and threat data that we've been receiving for the last, you know, ten, fifteen years. That's how we are able to not just ingest all of the data, classify and recognize that this is an attack that we've seen before, even if it's using novel and brand new unseen before malware and then provide you defense defensive strategies against it. That's how I believe BlackBerry can help the market, the customers the most.
I I mentioned that I started as on the the attacker side. I I was never an illegal attacker. I started as a pen tester.
And then, you know, so pivoted into reversing code and doing some other things like that. And, you know, I went from there. But most of my career was on the customer side.
I proactively switched or maybe was convinced to switch to the vendor side probably about ten years ago because I saw that gap. I saw that as a customer, I could buy all of these new widgets and toys, and it really wasn't making me more secure. So I came to the vendor side to try to influence the vendor defensive motion and product strategy to put out more products that legitimately can help customers solve those two problems.
The manpower problem, the diversity of toolset problem. The amount of times I am told by a customer, Greg, we'll rip everything out and put in whatever you tell us, that's infinitesimally it has happened. I have had a couple of greenfield customers that said, Listen, none of it's working.
Take it all out and help us replace it. But that's rare. Most of the customers either have financial constraints, time constraints, or some other constraint, so they need to make do with what they have.
Let's build a toolset that allows customers to use what they have and maximize the value they extract out of it.
we wrap up here, you've done great kind of level setting how you guys are able to add value for your customers in this realm, this is such a fast changing arena. You've got AI playing at some productive place in your approach, your strategy, and your solutions, but this is a fast changing world that we're dealing with. As we wind up, do you have any thoughts from either of you or both of you about what you're expecting to see over the next few years?
How you think things will change?
a little bit looks like? Yeah. So I'll get started.
I think we're gonna see more deception, right, used by attackers leveraging AI, especially, you know, with deepfakes. I think that's a very powerful application of AI to offensive capabilities. We already see a trend in the increase of volume and scale, right?
Think that's one of the key things that AI also enables attackers with, which is the augmenting their existing capabilities, make scale. But that's exactly what defenders can do as well, right? But the main thing is starting with the definition of the problem.
I think that's the most powerful question you can ask as a defender, like what is the problem I'm trying to solve? Because AI not any other technology, it doesn't really change the mission of your organization, right? Are you a hospital, small hospital or a large hospital, your goal, your mission is to protect the citizens, the people, right, that go to have care.
And you don't want this environment to get ransomed and admissions to be done by pen and paper so people could effectively die because they didn't get admitted to the hospital. That's the kind of thing that we're looking at here, right? Or protecting critical infrastructure, protecting school where our kids go to.
So, AI doesn't change the mission of your organization, AI doesn't change even the approach, the strategic approach to cybersecurity. You just need to find out where are the areas that can help you to scale and maybe cover some of the gaps that you have. And I think we talked a little bit about that, right?
But improving detection and response times, disrupting attacks at specific places of the attack chain, giving you the ability to contextualize a lot of data to give you some I'm a firm believer in the human machine teaming, right? To give you some input, so now the human can, with that information, take an action. And then also the models, the machine learning models, learning from that to effectively combine that human machine teaming, That blade runner, or in this case, the Replicant, that takes the best out of both worlds.
vision about that. I'll chime in on that as well. The top five companies in the world by market capitalization right now are tech companies, all founded or co founded by individuals with heavy technical background.
This is very unique in this era that we find ourselves in now. This is changing leadership in a way that we, leadership, entrepreneurship and just vision and strategy in a way that we haven't seen before. I think we're at a unique precipice to where we can maximize some technological applications that ten, twenty years ago, we wouldn't have even been having the conversation.
The technology was there, was readily available like AI that was written in textbooks in the late 1950s. The technology has been there. It's being popped into the forefront now because of that seismic shift where the biggest companies are tech companies.
So my daughter who's 15 years old is very tech savvy. When I was 15 years old, I was an oddball because I was tech savvy. Like they looked at me like, you know, I had three heads.
So what do I predict? I predict we're going to see acceleration in how those types of use cases and opportunities and candidly, business opportunities are going to appear. But I also see so there's always the positive and the negative.
I see a risk, a huge risk of moral and character failures at the level of those leaders who have a unbalanced sense of high technical prowess, but potentially low morals, potentially low leadership acumen, potentially low spiritual acumen. There's an opportunity to balance that out as well. Personally, that's where my focus is.
That's how I met Daniel from this podcast because his, you know, we we've spoken at events or met each other at events where we're trying to talk about those types of topics. You know, how do you pull together technology and other things that are more from a moralistic perspective, and and, you know, help have the technology, but balance that out and vice versa. I think that's where we're going to have to be very cautious that we don't over rotate and, you know, end up accidentally.
And I'm not talking about politics now at all, but end up accidentally handing the reins over to people whose gifting got them to a place where their character potentially could not sustain them. And I think we're at very big risk of that. So those are the two things that I see kind of for the future, both opportunity and risk.
Fantastic insights from both of you. Gentlemen, thank you very, very much for coming on the show. It was a great conversation.
I learned a lot.
And I hope I can, as as things progress going forward, I hope you guys, would will come back on and and give us updates on on where cyber is going forward. Love having you on the show. Thank you.
A pleasure. Thank you, Chris. Thank you, Chris.
Alright. That is our show for this week. If you haven't checked out our changelog newsletter, head to changelog.
com/news. There you'll find 29 reasons. Yes.
29 reasons why you should subscribe. I'll tell you reason number 17. You might actually start looking forward to Mondays.
Sounds like somebody's got a case of the Mondays. 28 more reasons are waiting for you at changelog.com/news.
Thanks again to our partners at fly. To Brakemaster Cylinder for the Beats and to you for listening. That is all for now, but we'll talk to you again next time.
Shared via Hopper