#313 Evan Reiser: How Abnormal AI Protects Humans with Behavioral AI

16 Jan 2026 · 50 min · 22 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Eye On A.I. Podcast Episode Notes

Episode Title

#313 Evan Reiser: How Abnormal AI Protects Humans with Behavioral AI

Episode Summary In this episode, Craig S. Smith interviews Evan Reiser, co-founder and CEO of Abnormal AI, to discuss the transformative role of artificial intelligence in the cybersecurity landscape. The conversation highlights the increasing sophistication of cybercrime, particularly in social engineering, and how AI can be leveraged to protect individuals and organizations from these threats.

Key Topics and Insights

  1. Origins of Abnormal AI
  2. Evan Reiser shares his background in ad tech and how it led to the formation of Abnormal AI.
  3. The initial focus was creating a behavioral security platform that understands and predicts human behavior to prevent cybercrime.
  1. Current Cyber Threat Landscape
  2. Phishing remains the top threat in cybersecurity, despite advancements in security technology.
  3. Cyber attackers are now employing sophisticated social engineering techniques, exploiting human psychology rather than just technical vulnerabilities.
  1. Behavioral AI vs. Traditional Defenses
  2. Traditional cybersecurity defenses rely heavily on known threats (signature-based), which are insufficient against unique and evolving attacks.
  3. Behavioral AI focuses on identifying "known good" behaviors to flag potential risks, allowing for the detection of novel attacks.
  1. The Role of Social Engineering
  2. Social engineering exploits human trust and psychology, making people the primary attack surface.
  3. Many attacks bypass technical defenses by manipulating individuals into providing sensitive information.
  1. Evolving Nature of Cyber Attacks
  2. Cybercriminals are increasingly using generative AI tools to craft highly personalized phishing messages.
  3. There's a notable increase in the volume and sophistication of cyber attacks, making it challenging for defenders to keep up.
  1. Asymmetric Cyber Defense
  2. The cybersecurity landscape is described as asymmetric; attackers can try numerous methods with a high tolerance for failure, while defenders must be correct every time.
  3. The conversation stresses the need for constant innovation in defense strategies to keep pace with evolving threats.
  1. Future of Cybersecurity
  2. The discussion touches on the potential for new forms of cyberattacks that harness AI in ways that are currently unimaginable.
  3. AI's ability to automate and scale attacks presents significant challenges for cybersecurity professionals.
  1. The Concept of 'Humans as the New Zero-Day'
  2. Reiser explains how humans represent an ongoing vulnerability in cybersecurity systems that cannot be 'patched' like software.
  1. AI-Native Companies
  2. Reiser discusses what it means to be an AI-native company, emphasizing the integration of AI into core business processes.
  3. Abnormal AI is committed to openly sharing its AI transformation strategies to serve as a model for other companies.

Key Takeaways

  • Cyberattacks are Evolving: Cybercriminals are becoming more sophisticated, making human behavior a primary target.
  • Behavioral AI is Essential: Understanding human behavior is crucial for developing effective cybersecurity measures.
  • AI is a Double-Edged Sword: While AI can enhance security measures, it also enables attackers to craft more effective strategies.
  • Ongoing Innovation Required: Cyber defenders must continuously innovate to outpace attackers who can test multiple strategies with minimal risk.
  • AI Transformation in Business: Companies should embrace AI to transform their operations and improve customer engagement.

Additional Notes

  • The episode underscores the critical role of understanding human behavior in cybersecurity and the necessity for organizations to adapt to the rapidly changing threat landscape.
  • Reiser's insights into the intersection of AI and cybersecurity offer a glimpse into the future of threat detection and prevention.

Conclusion This episode of Eye On A.I. provides valuable perspectives on the complexities of modern cybersecurity threats and the need for innovative solutions that leverage AI to protect human behavior as the primary vector of attack.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Evan Reiser's Journey to Abnormal AI

0:46 to 2:25

Evan discusses his background in AI and the inception of Abnormal AI.

“understanding, creating behavioral models of people, trying to understand what they do and they're exposed to different types of stimulus.”

The Threat Landscape and Phishing

2:26 to 4:36

Discussing the persistent threat of phishing attacks and their evolving nature.

“So the attackers are also using behavioral psychology, I would guess, to craft their attacks.”

Human Vulnerability in Cybersecurity

4:37 to 7:12

Exploring how attackers exploit human psychology to bypass security.

“Well, we're not going to break through their firewall.”

The Role of AI in Modern Attacks

7:13 to 9:13

Analyzing how AI enables more sophisticated phishing techniques.

“I could someday I'll write a book, a very long blog post about the top thousand attacks of the century or something.”

Personalized Attacks and Their Impact

9:14 to 14:01

Evan shares examples of personalized email attacks and their effectiveness.

“I think if you look at the FBI has this interesting report where they publish for people when you lose money, you don't you know, you don't call the New York Times always.”

Understanding AI-Driven Attacks

14:01 to 15:00

Learn how attackers utilize generative AI to exploit trust in digital communications.

“So like, you know, you just wouldn't expect to get a an attack from someone you've worked with for a long time with a real email account referencing things.”

The Rise of Cyber Attacks

15:01 to 16:15

Explore the increasing volume of cyber attacks and the challenges faced by defenses.

“And like, I think the only reason it's not overwhelming is because you don't need these old specific techniques to like make a lot of money as a scammer or a criminal.”

Behavioral-Based Cybersecurity Approaches

16:16 to 19:05

Understand how behavioral models are used to identify and block suspicious activities.

“And so you're using, you're training a model for your system, which presumably is a bunch of models to understand the norm in an organization and flag things that deviate from that norm.”

Email Security and Its Layers

19:06 to 20:55

Discover the role of email security gateways in protecting organizations from attacks.

“And the reason that's like really important in this age of AI is that if every attack is unique, you don't have like training data for your machine learning models to help you stop the next thing, right?”

From Engineering to Cybersecurity

20:56 to 22:18

Hear Evan Reiser's journey from engineering to building cybersecurity solutions.

“But we do replace kind of third party solutions, right?”
Show all 22 chapters

The Asymmetry in Cyber Warfare

22:19 to 24:12

Examine the asymmetric nature of cyber warfare and its implications for defenders.

“and now get to build cool stuff with AI for our enterprise customers in cybersecurity.”

Future Threats and Cultural Impacts

24:13 to 27:41

Discuss the potential long-term cultural attacks enabled by AI technologies.

“And it is true, there is kind of like a cat and mouse game.”

The Role of Culture in Geopolitical Conflicts

28:00 to 28:38

Explore how culture is historically used as a weapon in geopolitical conflicts.

“I'm a huge sci-fi nerd and sci-fi reader, I've read basically pretty much every book about space and AI in the future.”

Humans as the New Zero Day Vulnerability

28:38 to 30:39

Understand the concept of humans as vulnerabilities in cybersecurity and how cognitive biases can be exploited.

“I'm actually very optimistic long-term on behalf of civilization, but we got work to do.”

Behavioral Profiling in Cybersecurity vs. Advertising

30:39 to 35:56

Learn about the parallels between behavioral profiling for ads and cybersecurity, and the objectives behind each.

“And that's going to be an increasingly common thing.”

Motives Behind Cyber Attacks

35:56 to 38:44

Discover the main motivations behind various cyber attacks and the financial implications.

“From what you see, what is the main attack, the intent of the main attack in all of this?”

The Lifecycle of Compromised Passwords

38:44 to 41:34

Examine what happens to compromised passwords and how they are exploited by criminals.

“But I would say a lot of it comes down to kind of money and the normal things you'd imagine for why people go into crime.”

Reconnaissance Techniques in Cyber Attacks

41:34 to 42:00

Understand the reconnaissance tactics criminals use to initiate social engineering attacks.

Understanding Malicious Text Messages

42:00 to 43:31

Learn how malicious text messages are used for reconnaissance and social engineering attacks.

“We call that kind of, you know, again, assuming it's malicious, we would call that a reconnaissance, you know, email or text message.”

AI Transformation in Business

43:31 to 45:39

Discover how companies can integrate AI into core business processes for better efficiency.

“It's called like lateral movement through your accounts, your friends' accounts.”

AI-Driven Business Processes

45:39 to 49:08

Explore the comprehensive ways AI can enhance product development, customer journeys, and employee management.

“So you're not open sourcing the models, your defensive models, you're talking openly about your own digital transformation to an AI native.”

Real-World AI Applications

49:08 to 49:40

Understand the practical applications of AI in various business functions, from engineering to sales.

“evan misunderstand where he's not listening what can i do better right and i kind of have that feedback to me.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Let's have you introduce yourself. Tell us how you got to abnormal AI and what abnormal does and then we'll talk about the current threat landscape. Sounds great. Well, first of all, Craig, thank you so much for having me on the show. My name is Evan Reiser. I'm the founder and CEO of Abnormal Security, which is now called Abnormal AI. And my background is not in cybersecurity. I spent the grand majority of my career getting people to click on ads. So if you imagine all those annoying, you know, the companies that maybe, you know, suck up some of your data and follow you on the internet with ads, showing you things you looked at on different websites.

0:33That's almost certainly my fault at some level. So I apologize. And now trying to fight back a little bit by, you know, stopping some crime and putting bad guys in jail. So I'm a bit of a cybersecurity outsider, but I've been an AI insider for a long time. As you probably know, behavioral eye targeting, it's all about looking at large sets of data, understanding, creating behavioral models of people, trying to understand what they do and they're exposed to different types of stimulus. So that's kind of how I got into cybersecurity just through, honestly, I love the technology. I've worked in AI for a long time.

1:01I saw the technology obviously getting way better even seven or eight years ago. It's changed a lot in the last 20 years. In the last two months, it's changed. So the idea for Abnormal was actually not really an email security company. That's what we're most known for today. It was really to create a behavioral security platform that could basically understand humans' identities better than humans and then predict their behavior. And the idea was if we could do that, we could probably help businesses and stop some crime. We started with email because phishing is the number one cause of breaches.

1:30Business email compromise, the number one cause of financial loss in the enterprise. And a lot of the conventional solutions are overly reliant on threat intelligence, different signatures, patterns, and heuristics. And what we see, especially in the age of AI, and due to very sophisticated criminals, there's new attacks every day. They're personalized, they're targeted, there's a lot of social engineering. Every attack's unique, you can't use some of the conventional techniques. So rather than kind of studying known bad, we focus on known good. We create behavioral models of every person enterprise by integrating directly into their IT systems.

2:01And then when a new email comes in or other activities happen for other products, we analyze it to say, is it risky and is it normal? And does it look weird? Kind of same way a human would look at that if you had 100 hours instead of 100 milliseconds. So we do that. And it turns out that technique is very effective for stopping different attacks. So we've been doing that for about seven years. We have a bunch of other products as well. The company is over a thousand people today. And today we protect about 25 % of the Fortune 500. So excited to go stop our crime in the future that's a quick yeah that's uh that's really interesting one thing about about phishing and i keep i'm always amazed when there is a major breach or attack and it turns out that it all started with a phishing email because you would think yeah at this point people would know not to click on things particularly on their work email but But the attacks are getting increasingly sophisticated.

3:02So the attackers are also using behavioral psychology, I would guess, to craft their attacks. How do you see the... First of all, isn't phishing kind of archaic at this point? And aren't there new attack vectors that are being developed? or is it still, does it still boil down to getting the person to click on a link? Yeah, I mean, some stuff is old, right? The days of like the Nigerian print scam, we don't see that. Which interestingly enough, my wife's Japanese American, her mother has passed away, but she was a Japanese citizen. And my wife just got a letter from, you know, it's the Nigerian print scam, but it's in Japanese from someone in Japan.

3:56I was like, wow, they're reviving that? I think. Yeah. But anyway, go ahead. So, I mean, we see some of those, right? But they're certainly less sophisticated, right? That's not probably the best way to go hack the bank. Same thing. We don't see typos in emails, right? There's no bad grammar. Every criminal obviously can use ChatGPT to send out perfect messages that are super personalized, right? They know all about the person that read every webpage on the internet about you. They know your coworkers. They know the business process. So things have changed a lot. What hasn't changed is still about kind of tricking humans, right?

4:28And that's going to be a consistent thing. And this, I'm going to make up a totally fictitious example here. But Craig, imagine you and I went to go create a cyber gang. We kind of gave up on our day jobs. We said, we're going to go hack the biggest banks in the world, right? How would we do that? Well, we're not going to break through their firewall. We're not going to hack their satellites. We're probably going to send a bunch of like, you know, text messages and LinkedIn messages and emails to all their employees, right? And a big bank might have 10 ,000 employees. Someone is going to do something or say something they shouldn't be, right?

4:54Someone will maybe think we're someone else and maybe reset a password or send us an invoice. Can we pretend to be their vendor? Right? I mean, that kind of human judgment is still like the weakest link in most organizations. You know, if you're a criminal, like why would you try to go up against the big bank? They spent a billion dollars in cybersecurity. They got every piece of tool, technology, every FBI threat to investigate. It's super hard. But if you email the poor support help desk person and say hey i forgot my password or you email their accounts you know accounts payable and say hey like i'm the ceo's blah blah blah and if you don't do this like we're going to delay our service and the flight won't take off and god knows what will happen to you like you know people are you know it's like 99 people are like good citizens are trying to be helpful and so i think you know criminals are really trying to kind of exploit the good intentions of humans they're trying to use our own you know people in kind of it systems against us that's very hard to defend against because unlike your you know network you can't shut off the fire you know shut off the ports and block access right you need to keep emails open for visits phone calls open you need to tell your staff that they should like you know try to listen to customers try to help them out and help out the co-workers and you know attackers are using kind of our good intentions against us yeah have you seen presumably you see these attacks have you seen them evolve and when you talk about an attacker knowing everything about you if it's corporation with you know 20 000 employees or something they're not doing that is it do they have a comparable ai system that's putting together all the various data points about each individual and crafting you know personalized attacks for each of the 20 000 or however many employees are the answer is kind of like yes and no right let me i'll show some context right just to add, you know, appropriate and hopefully not too much or too little credibility to my upcoming answer here.

6:43So I've been doing this for, I don't know, eight years or so. You know, we protect thousands of companies. We process more than a billion emails per day. A hundred thousand attacks get blocked every day, maybe a million. But I would say at least every day we find one novel attack that's never been seen before in the history of civilization. So, and I talk, you know, I personally, I talk to at least one CISO a day. I probably met half the global 2000 CISOs at some point in the last couple of years. So like while I'm not a cybersecurity expert in some ways, I am kind of like Wikipedia for like email scams and fraud and social engineering.

7:14I've heard about everything. I could someday I'll write a book, a very long blog post about the top thousand attacks of the century or something. So the answer is like, yes and no, right? No in the sense of like, you don't need hyper sophisticated AI to get people to like do some they shouldn't be doing, right? Sometimes it takes a basic email, one line, right? You go register fake Gmail accounts. You create a fake LinkedIn profile. You send one little message. And it's like not that hard. You don't have to be that sophisticated. You don't have to have a PhD in computer science or machine learning information retrieval or like high dimensional math to be effective.

7:43So I think from a volume perspective, you don't see that many high risk sophisticated attacks, which is not necessary. However, they do exist, especially when you look at kind of organized criminals and nation state attacks. They are using kind of all the technologies you can imagine, right? Again, the same things that you and I would use if we were the bad guys. But I think that the asterisk there is like, they don't need to go spend a billion dollar training custom ai bottles right you can use off you know off the shelf open source kind of large language models any of the foundation models that are available for free on the internet and you can just ask it hey i'm a small vendor i have some financial difficulties one of my customers the big bank you know you know my bank account like there's some issue and i had to open up a new one can you help me write an email to explain why it's really urgent that they need to change my routing number because if they don't do this right you know i'm not going to make payroll to my three employees and like, you know, that's what I rely on.

8:32Hey, here's the person. Here's every email that we've had in the past. Here's kind of like some information. Here's their Twitter page or LinkedIn page, right? Like, can you help me imagine like, what do you think the process is at a big bank, right? To change that, right? What are the compliance, you know, hurdles? There may be ways to get around it. Come up with 10 ideas and draft me a hundred different emails, right? That you might think might be effective to get that person, right? And then you can go send those, right? And so within five minutes, you're sending a hyper sophisticated, targeted, personalized phishing email that probably like five years ago like that you could only deliver that right if you were like a nation state actor and now a petty criminal right even with no computers you know technology knowledge can be kind of working at levels of efficacy so i think that's the challenge last comment i'll stop talking about like that's the challenge i think with the these attacks in the age of ai is that ai allows non-criminals to be criminals because i'm not sorry non-cyber criminals to be criminals right it allows criminals to kind of increase the scale of these attacks where they can automate it but it's through fancy python scripts or ai and the third piece which is most disturbing is that ai allows for a level of sophistication these attacks that are beyond kind of human imagination right we literally see i personally see maybe no maybe not every day but once a week there's some new attack where you look at it like i don't think that's an attack and i would say probably yeah almost every day a customer complained to us say hey you blocked an email that was a safe email and we go investigate we say no actually this is sophisticated let me explain what they're doing to kind of trick you so like we're now at the stage where these attacks are kind of surpassing the human's ability to perceive them wow yeah that's frightening yeah there seems there seems to be an uptick in i mean it seems like everybody knows you know three or four people that have been scammed out of a bunch of money the but also it's like it's not like it's kind of like not the most interesting or sexy thing to talk about.

10:26I think if you look at the FBI has this interesting report where they publish for people when you lose money, you don't you know, you don't call the New York Times always. You don't go on Twitter X. You do call the FBI. Say, let me get you. How do we get my money back? So the FBI provides this really kind of, you know, I would say like a most a more objective view on kind of the where what cyber crimes are causing what type of damage. So I have this report which describes I think they call it the IC3 report for the Internet Crime Complaint Center. And it basically kind of talks about when people call us and they say there's money lost.

10:53We ask them, how did you lose it and they kind of track the money lost by cyber crime and so the number one cyber crime i think outside of like i think ftx kind of messed this up so maybe minus ftx and investment fraud but the last seven years the number one has been social engineering through email there's actually more money lost for that for i think then credit card theft identity fraud and like ransomware combines right yet if you look at like the visibility of some of the you know social engineering via email right in in media and even cyber crime kind of news it's very underrepresented right so it's kind of interesting how it's kind of like boring right one said if a team clicked on a link where it's kind of not super fun to talk about yet that is still you know the number one cause of breaches right so it's the difference between like what's actually happening versus you know where kind of our attention as an industry and society is yeah and when you say that you see attacks that you've never seen before there or this example of an email that a customer complains has been blocked and then you show them can you give us an example that is sort of out of the ordinary that demonstrates that sophistication i'll give one that i think is extremely ordinary but my guess is for most listeners they've not considered this that i've heard about it right so one of the most it's not the most common attack by like you know the number of these we see is pretty small but if you look at like if you look at like okay if money was lost how did it get lost it shows up very highly there and that is thing called well i don't know what it's called we call it a vendor account compromise and so imagine you know you're you're a big bank super hard to hack in the bank right so if i'm a hacker i don't want to you know it's like it's silly it's a waste of time i'm not going to hack your firewall or break through cryptography what i can do is i can find out who your maybe water supplier is new york city right and i'll go hack them right because they probably don't have you know 2fa and like you know any cybersecurity training.

12:40So I'll break into their account, right? Maybe I'll go and LinkedIn, I'll search for the accounts receivable person. The person's kind of demanding invoices. I'll break into their accounts. And once I'm in their account, I have access to all their old emails, right? And so what I can do then is I can take every email I've ever sent, which might be, I don't know, 10 ,000 emails, and I can load it into, you know, a large language model, right? With a chat GPT or, you know, an open source one like Lama, I can do it on my laptop. I can say, hey, go through every email I've ever sent and find every one we've ever worked with, everyone we send an invoice to, find out their account number.

13:09And then I want you to send an email to everyone that we've ever worked with in the past and explain why they need to send us some payments, right? Use their real account ID, use their real name, use their email address, and then look through our past conversations and make sure you include in that message, right? Any, some sort of indicator that I know them personally. And so we'll see these kind of personalized messages. And it's really hard on the victim side. You get an email from somebody worked with for 10 years it's the real domain right it's it's like the real email address it's replying to an old email right that where you talk about something and in that email references i don't know hey evan it was great seeing you you know i hope you're recovering from your sickness from like the holidays or something i don't know right yeah and it looks your personal and there's some like reasonable pretext or excuse hey we're at you know sorry repeat this all is there but like you know hey we were at svb and our bank account got shut down and you know blah blah blah.

14:01Right. So like, you know, you just wouldn't expect to get a an attack from someone you've worked with for a long time with a real email account referencing things. And so like when you imagine from the attacker side, it's not too incredible. But, you know, if it's Tuesday morning 8 a.m., you get that email, it seems super reasonable. You wouldn't even think that like you should think about that attack. So that's an example, right, where people are obviously using, you know, generative AI technologies, but they're really kind of relying on just getting good intentions and trust and digital identities that we're so kind of accustomed to in 2025.

14:31Yeah. And now that we have sort of agentic automation percolating through all these systems, presumably, you know, the criminal could set up one of these systems and it sends emails daily, you know. Sure. Yeah. Yeah. Non-stop, right? I mean, it's just seems like it would be an overwhelming amount of attacks coming now that AI is hooked up to it. Yeah. And like, I think the only reason it's not overwhelming is because you don't need these old specific techniques to like make a lot of money as a scammer or a criminal. And it's because like the basic stuff still works, unfortunately. And there's a new attack every day.

15:14You know, I think we will see more, right? I mean, one, I don't know our official data point is here, but like I'll give like the plus or minus 25 % version. When we deploy, we are kind of the last line of defense. So we sit behind every other line of defense. So there's things that process that may filter emails. We are kind of the last kind of check before it gets in front of a human. We so that means that if things would get blocked higher up in the stack, we can't see it. We can only see stuff that like would normally get sent to the user. So in the last like last 12 to 18 months, we've seen about a 2x increase in the number of attacks that we see, which means that with abnormal removed, it's right there'll be two x more getting in front of kind of our customers employees mailboxes so and i think that all the systems around around us right they're also getting better but i think the criminals are kind of outpacing like good guys and so just these attacks are very effective and you know i don't know if it's because of ai or other reasons but we are seeing just you know higher volume of attacks and for the attacks that are for the top one percent top one percentile most sophisticated those are now past the point where humans can recognize them we have yeah like I said, we get complaints about people saying, hey, you missed this attack.

16:16And sometimes we do, right? But like a lot of times it's because like it didn't miss it, just the AI picked up on something that, you know, the human analyst didn't understand or doesn't even really kind of believe even when it's explained, you know, by the AI. Yeah. And so you're using, you're training a model for your system, which presumably is a bunch of models to understand the norm in an organization and flag things that deviate from that norm. Is that right? That's right. And like, it's, you know, in some ways, like it's not that smart, obviously, like, I think it's pretty cool technology, but you know, most of cybersecurity historically has been focused on just detecting kind of known bad stuff.

16:58And so, and that's not how things work outside of cybersecurity, right? I think like it's intuitive to most people how credit card fraud gets stopped, right? And so let me use that as kind of the analogy here. So that's probably more relatable. So imagine like if every time you use your credit card, the bank said, okay, is the vendor that Craig just sent money to, is that a known scammer? If so, block it. If not, then it's probably okay. That's how most of cybersecurity works. Now, as you know, that would not be sufficient because there's new scammers targeting new people with new kinds of trends to steal their credit card, steal money all the time.

17:28And so obviously, if you get a credit card charge on your card and it's from a coffee shop in Brazil and the charges for$10 ,000, your bank doesn't need to believe that's a scammer, right? They just have to say, Craig, I don't think Craig's in Brazil. I don't think coffee shops historically haven't spent $10 ,000 for like a latte. And so we're going to block this one to play it safe. And maybe we'll just kind of send, you know, Craig a note. If it's on the fence, we'll just ask him. We're going to default to no. So that's kind of more of a behavioral-based approach. So that's kind of the technique that we do, right?

17:57So when we see a new email come in or maybe a new login, right, to kind of Microsoft or Google, what we're going to do is we'll go, what do we know about this person. We have a pre-computed behavioral model. Well, here's who they work with. Here's the time of day they're active. Here's their tone and their personality, their style, and the projects they're working on. And we say, okay, what do we know about the sender, the receiver, the topics, right? Like we were talking about some business reports. If I send you an email saying, hey, Craig, thanks so much for that analysis you sent me, right?

18:23Ari, I'd be like, that's not a thing we've ever heard about. So you basically kind of look at all these entities, right? The identities and the people kind of all together. And then we're using it as context to make a decision. And the decision we're making is really kind of across two dimensions. One is, is it risky? If I got an email from someone I've never seen before and just says, hey man, great seeing you last night, that's not risky. So we're going to kind of ignore it. But if it is risky, right, saying, hey, can you pay me soon? And it seems abnormal, then we're going to block it. So we look at the kind of utility, the multiplication of these two things, right?

18:54Is it risky and is abnormal? And if so, we don't know that it's bad. We just know it's not good and we block it. And And so that's kind of the difference. Most cybersecurity, like we said, focuses on kind of known bad stuff. We basically kind of flip it where we say we're only going to let known, you know, kind of known good or known normal stuff in. And the reason that's like really important in this age of AI is that if every attack is unique, you don't have like training data for your machine learning models to help you stop the next thing, right? If I knew every attack in the world and I built a model to say, you know, is it an attack?

19:23I can't predict the next one because it's never been seen. It's outside the trained data set. But we have a lot of data on what is normal behavior, right? But every day, all of us are kind of leaving behind this giant exhaust stream of like every click and every keystroke, everyone we talk to, all things we do for work. That's a lot of training data for known good stuff. So we use all that stuff to kind of train our machine learning and AI models to figure out what's known good. And then if it doesn't seem to be good, we block it. And that turns out to be extremely effective. In some cases, it's like two to 10x more effective than the conventional threat intelligence-based approach.

19:54Yeah. And you were saying this is the last line of defense. so it doesn't replace other filters or other, you know, alerts that a system may already be using or a customer may already be using. Is that right? Kind of like yes or no. You know, almost every business in the world has some form of what's called a security gateway. And that is kind of like the conventional email security technology. If you use Microsoft or Google as a business for your email, you have that built in, right, to provide native security. made, you know, sometimes bigger enterprise will buy third party secure gateways. We're kind of agnostic.

20:31We say you got to use some secure gateway because there's some unique technology there for stopping spam and stuff that you're going to need. And you can pick a great one that's probably a third party or you pick the free one that comes with, you know, Microsoft and Google, which is our recommendation. But whatever one you pick, we're going to make sure that anything gets through those things. We're going to stop. It isn't good for any users. So, you know, there is kind of need of security in Microsoft and Google, right? That is the process of these messages. And, you know, it does stop a lot, you know, a lot of more of that kind of spam, maybe the more commodity type attacks.

20:58But we do replace kind of third party solutions, right? That's kind of like more conventional third party email security solutions. And that is one of the reasons why people buy us, right? They want to stop more attacks, but also like not pay for the old kind of legacy thing. Yeah. This, so you're coming from the world of ad techs and you, what did you study in school? I studied stuff in a school I've never used professionally. So I went to school for electrical engineering, which really is, sorry, computer engineering, which really electrical engineering for the purpose of building, you know, computer stuff, right?

21:28So I took classes on CPU architecture design and networking and things like that. I then decided that I couldn't stand the slow iteration rate of like building CPUs and circuits, right? I couldn't wait six months for it to be fabricated. So I really, I got into kind of really web-based software development and, you know, just fell in love with, you know, programming and software engineering. I didn't really kind of study that in college. I never programmed before. I went to college, took a couple of computer science classes. I just loved it. I wrote, built my own video games. It was like so fun.

21:55And then after school, I lasted about two years in the industry and then kind of have been doing startups since, but just really love kind of building stuff for people. And working with kind of machine learning has been just really fun. You can do kind of these magical things and like the industry's been changing so fast for the last 20 years, which is very intellectually stimulating. So yeah, my background is in mostly software engineering. Then I kind of got dragged into kind of product management because I love building stuff with customers. And then you've spent a long time in ads and now get to build cool stuff with AI for our enterprise customers in cybersecurity.

22:24Yeah, I was asking because I thought maybe you came from a behavioral psychology background or something. So I don't, but actually my dad is a psychologist. And because of that, I've got really, I've always been very interested in behavioral psychology. I've, I don't know, I've read, I don't know, dozens, if not a hundred books. And I've always just, you know, my specific area of interest that was actually even pre, you know, predates my cyber-dressing interest is I love reading about cognitive biases, right? Understanding like the evolutionary basis for why your brain works a certain way and like why it's like really set up to work in like a world that is not the modern world and just kind of understanding why we make some decisions versus others.

23:04That's more, I would say that's more of a hobby interest, right? I have like zero academic training and probably don't know half the right kind of like words for things. Yeah. And, but do you think as, I mean, LLMs, for example, as they become more nuanced in understanding human psychology, which they clearly are. Do you think that, I mean, everyone talks about it's an arms race, you know, the attackers get a little ahead and then the defenders catch up and then the defenders get a little have back and forth. Do you think that this will plateau, that there is only so much social engineering that you can do and that as new defense systems like yours develop, that the attackers will run out of new ideas?

24:01It's an interesting question. I don't think so because the AI is going to generate ways of attacking us in ways that we can't imagine. I'll give you one example. The other comment I'd say is it's a bit of an asymmetric war. And it is true, there is kind of like a cat and mouse game. They try this, we block that. They try this, we block the next thing. And it is true that there is a new attack every day. And that requires companies like us and all of our peers to have new defenses every day. And that is the bare minimum, just like tread water. You can actually still be losing. You can be getting better every day and still underpacing the attacker.

24:34And so it's a very interesting industry. And frankly, it's very intellectually stimulating to work in an industry where it's actually kind of like challenging and fun to like know that if you don't get better every single day, you lose. The reason it's kind of asymmetric is because attackers, they don't have to, they have a very high tolerance for being wrong about stuff. They can try a thousand attacks, you know, they only need one to work and they don't have to worry about privacy or security or compliance or like obeying the laws. They can try crazy stuff. They usually don't have to deal with like supporting a million customers, 100 ,000, you know, coworkers.

25:04So they have to like only get it right at once. The good guys on the other side, they have to be right every single time, right? The one time they mess up, and it's not just a breach. It could be like they roll out the AI model too fast. They don't have the right compliance for the new privacy law. They can only get, you know, they have to be right every single time. So it's a little bit unfair, right? Even just the adoption of AI, right? Criminals are adopting this technology instantly. You know, ChatGP came out three years ago. I'm sure there's some phisher using it the next day. And there's some enterprises today They're still trying to figure out, hey, how to roll down a safe compliance way.

25:33And so it's a bit of an asymmetric war. And so it's kind of unfair. Right. And I think that's the, you know, I do think there are some advantages that the defenders have. But I think to your question, like, I think it's going to be, you know, the we're not going to get to it. I think there's going to be always new types of attacks that are going to escalate. I do think the defenders will have the data advantage. Right. We have, you know, we'll have more data about inside of like how the business works and how people behave and the bad guys. Right. There's more data inside the enterprise and outside.

25:58And so I think that's why defenders will win long term. And just the final thing I'll say is like the future of cyber attacks, even cyber warfare is going to be very strange. The same way if you explained your cybersecurity, someone from a thousand years ago, they wouldn't know what you're talking about. I think it's the same thing. Like 10 years from now, there's going to be cyber attacks that we can't imagine. I'll give kind of one example. I talked to one of my, maybe a friend is too strong of a statement, but like there's a customer I'm close with, who's a CCO of a big bank that we've all heard about.

26:25And I said, Hey, what is your biggest worry about kind of AI? What's the biggest AI attack you're worried about, you think no one is talking about? And what he said is that, he's like, look, there's a lot of stuff I'm worried about that we're trying to actively face, but there's new class of attacks I think we can't even imagine today. What if like one of these models had a small cultural bias, right? A malicious cultural bias that was not observable, you know, on a day-to-day basis. But every day, right, it was giving answers that would make all of our employees maybe 0.00001 % a little bit more socialist.

Read the full transcript

26:55And we wouldn't know. It took 10 years to realize that it's actually a cultural attack. The culture of the company is being changed very slowly of all these AI models. It may not be malicious. It might be unintentional. Whether it's socialist or capitalist or any dimension, any kind of values chart, it doesn't really matter. But there may be kind of a cultural and values-based campaign that's being run either intentionally or unintentionally. And he's like, I have no idea how we would even detect that in the short term or the long term. And so some of the kind of second-order consequences of these AI usage is still, I think, to be determined.

27:26And how those will be weaponized and used against us, I'm sure there's a bunch of very bad, very annoying people out there that are going to try everything they can to discover those new techniques. And obviously, it's job of me and Abnormal and probably all of our peers to help stop them. Wow. Yeah, that's fascinating. That idea of sort of long-term, subtle attacks that are not trying to get into your bank account but change your opinions. I mean, that's going on actually with that was the concern about TikTok. Exactly. I think historically, if you look at it, I'm not a military expert by any means, but historically, if you look at some of the longer term conflicts, geopolitical conflicts, there's many examples where culture was used as a weapon in very subtle ways were used to influence our populations to achieve political objectives.

28:18I'm a huge sci-fi nerd and sci-fi reader, I've read basically pretty much every book about space and AI in the future. Yet we're still seeing new ideas emerge in 2025 about ways these technologies can be used for bad purposes. And so I have to believe that whatever the worst thing we see in the future is, it's probably not imaginable today. And that's why we have to invest to make sure we're prepared. So I don't mean to be super negative. I'm actually very optimistic long-term on behalf of civilization, but we got work to do. Yeah. You talk about humans as the new zero day. Can you explain what you mean by that?

28:55Yeah, I think if you look conventionally at cyber attacks, there's been this game of you're trying to identify the flaw in the technology system before it's fixed, right? And that's true for petty cyber crime, for organized cyber crime, even nation state cyber crime. Look at cyber weapons. The idea is like, yeah, you found some flaw that no one knows about, and you kind of hide that you keep on it you want to use that for some purpose and like that's kind of like the zero day attack is right you're trying you're launching attack but when there's like zero knowledge about the weakness right and like these things can get quick fixed pretty quickly so you want to kind of get ahead of that i think the challenge is like you know ai is going to help us defend against a lot you know fix things quickly ideally like remove all these vulnerabilities in software right we've actually seen our number of like bugs per unit of what you know something go down with you know ai software development so i think kind of like the conventional attacks of like using these zero days and malware and i'm sure there'll be crazy negative examples but like i think that that's gonna be a lot harder someone i said earlier right you know the best way for me and you to hack a bank in our new cyber gang craig is like not by generating some custom malware and breaking into iphones or windows servers right it's going to be to you try to trick humans in some way and so i think that's the vulnerability that that's the persistent vulnerability that is always going to be there right you can't kind of not to sound not to you know land a catchphrase here but like you You can't patch human brains.

30:13As we talked about earlier, when we talk about cognitive biases, we all have them. We all do things that are irrational in somewhat predictive way. Humans for years and centuries have exploited those irrational decision-making systems in our various biases. Criminals still do it today, and AI will take advantage of that in the future. So maybe calling that a zero day is not quite right, but I do think every day we're going to see a new type of attack that's never been seen before and could not have been predicted about how some criminal or bad guy or AI system is trying to deceive or trick or bypass critical thinker judgment of humans.

30:46And that's going to be an increasingly common thing. It's already very literally the number one cause of financial loss, right? Report FBI, is social engineering, which essentially is a technique to bypass critical thinker of the humans. And I think it's only going to get worse going forward. That's interesting because I would think as agentic AI becomes more prevalent and which are backed or based on foundation models, that the models themselves would be the attack vector, would be the vulnerable point. Because you have agents that have access to proprietary data or even to financial systems, that the attackers would be focused on fooling the LLMs, you know, as opposed to humans, but you're saying the opposite.

31:45I think it's a little bit nuanced, right? And maybe both are true. I think that obviously like, you know, just, you know, you just kind of breaking into the support staff's brain. There may be limited assets there to steal, right? Compared to the bank account or a bunch of corporate data. And so like the real target for a lot of criminals is probably, you know, it's basically just to make, outside of nation states, it's basically to make money, right? So I think that they will be going after, you know, bank accounts and passwords and data and ransomware, things like that. That is kind of the objective.

32:14But I think the strategy and the approach that criminals, you know, take today, and I think will be increasingly true in the future, is they're going through humans. And my kind of first principled argument would be that, like, there does exist a state, right, maybe impossible to reach or difficult to reach, but there does exist a state where you could have perfect technical security. You can block off all your firewall ports, right? You can, you know, patch all your vulnerabilities. You can have perfect software and all the code you use, right? And you're impenetrable in theory, right? I know it's impossible to get to, but in theory it's possible.

32:43However, as a business or an organization or a government, you can't shut down your channels of communication between your people, right? You can't not read emails. You can't not, you know, close down your phones. You can't like have all your employees not talk to anyone on the outside. No organization can work like that. So the purpose, that's the reason why we have organizations. It has to do something. And so you can't firewall that stuff off. So there'll always be an open channel for a bad guy or a rogue agent to be able to interface with people inside that organization. So as long as that exists, that's going to be the front door that people get into, or the side doors.

33:15Maybe they're going for other things inside the house, but they're going to come in by trying to trick people in various ways. Yeah. And you came from ad tech. Are there parallels between behavioral profiling for advertising and cybersecurity? I would say yes. Obviously, the objective is totally different. But if you think about modern ad systems, and this is true at Google, Twitter, Facebook, and obviously, it's all public information you can read on the internet. The core systems are trying to understand people, primarily consumers. What are their interests? Who are they? most importantly what's what might they be you know interested in buying or consuming and what are some of the techniques we could use to get them to kind of push them over the edge to go from consideration to purchase and so if you're building an ad system you know a lot you need a lot about the people you need a lot about the products and then in some ways it's a bit of a matchmaking game right i know that you're in the market for you know buying some soda before that party coming up and so i'm going to try to kind of subtly push you from going from you know diet coke to diet pepsi right and then it's like what's kind of the perfect stimulus right whether it's a audio or video or an image that i can use to kind of influence you to kind of explain that oh well you know here's the identity of a pepsi buyer right and like craig don't you want to be a little more like that and so like that's kind of what you're trying to use machine learning to do understand people understand the products understand kind of like do the matchmaking about kind of what creative or what media is going to cause them to kind of influence your decision So that's like the core of most digital ad systems where a machine is kind of making that, doing that modeling and that matchmaking.

34:53There's no human involved in that process. And as you and probably most of your listeners know, that happens every time you load a web page on the internet. There's some ad auction going on behind the scenes. A thousand computers are calculating a million things to figure out what should I show on that page to influence you in some way. It's not always well done or kind of smart, but that's kind of how system works. There are some similarities, at least kind of our technology. right we are trying to get a bunch of data on people except it's not consumers it's enterprise workers it's also not random websites they visit it's kind of what do they do for their job and then we're using that behavioral model to make more intelligent decisions about kind of how they might be influenced or persuaded in some way because the difference is we're not trying to like convince you know our the users we protect to do something we're trying to figure out how might they be convinced or tricked by a third party and how do we defend against that and helping us kind of like block that block the wrong you know media from kind of getting in front of that person like that's you know there's a similarity there what's a little bit different is you know we are trying to understand their behavior and then identify you know is it appropriate in some way or is it normal and that's maybe like it uses some of the same kind of pre-computation of behavior modeling but again i think maybe like the business objective and some of the techniques are a little bit different so there's certainly some parallels but you know i hope we're acting much more as you know i think we're doing a lot more good in the world than getting people that click on ads.

36:10Yeah. From what you see, what is the main attack, the intent of the main attack in all of this? I mean, what are attackers, what are most of them trying to get? Because there are data breaches and then there are direct financial, you know, theft, like getting into a bank account and wiring out money. I mean, what is the main... It's almost always money with like, with some exceptions, right? So you can break the criminals into three buckets. You have your petty criminals, right? We're just trying like petty criminals and scammers. They may work in groups or by themselves. That's probably 90 % of the attacks, right?

36:56It's probably 90 % of the attacks and a small percentage of the money is actually lost. Then you have your organized crime, you know, criminals. And that's probably 99, it's like 9.99 % of the attacks. And that's like, and some of these are very specific organizations. These organizations have IT departments and recruiting arms and like different divisions to pass on stuff. One team will kind of get the password, it'll pass off the team too. There's like, when I say like organized crime, they are highly organized, right? Maybe more organized than some, many businesses in the world. And then you have the remainder kind of 0.1 to 0.01%.

37:31And that's kind of the nation state attacks. And those are not, they don't care about money, right? They have money. What they care about is some political objective, right? It could be cultural. It could be chest beating. It could be intelligence reasons. It could be because like they just, you know, want to be a mean person, right? I don't know. Most, you know, very few people will encounter that kind of 0.001%. You know, if you're a large enterprise, you may be at risk. If you're a critical infrastructure, right? You're certainly at risk. If you're a government, you're absolutely at risk, right?

37:59Because that's what they want. They have political objectives. But outside of that, people are trying to get money. And everything else is just a step in the process to get money. Why steal your password? No one cares about it. No criminal cares about your personal email. They only care about the extent that it can access other accounts, eventually get in your bank account, or convince your friends to send money or send gift cards, right? Why do you care about hacking a computer? No one cares about like, you know, my Microsoft Word document I wrote to my grandma. They're trying to put ransomware on there to get me to pay 100 bucks, right, to them.

38:26So all the kind of like symptoms, right, you see in cybercrime, I would say always goes back to like, they're just trying to make some money, right? And these are, you know, these criminals are, they run businesses, right? They're illegal businesses, but their goal is almost always to make money, sometimes indirect, right? And you see, you also have like, you know, more conventional organized crime doing cybercrime to enhance their kind of, you know, real world, you know, criminal operations. But I would say a lot of it comes down to kind of money and the normal things you'd imagine for why people go into crime.

38:56Yeah. Although, and you're talking about corporate attacks, it seems that most of the corporate attacks you hear about, they're stealing customer data. I mean, they're not stealing financial assets. Or are they? And you don't hear about it. Well, they absolutely are. You don't hear about it. Again, like, don't take my word for it. You can go to the FBI's website. They have the Internet Crime Complaint Center. They publish a report every year. I think it's in May. Where is money actually lost? That's like the truth, right, about where is money lost. It's very underreported by, you know, one or two orders of magnitude.

39:34And I would say a lot of things you hear about, like, you know, data theft, whether it's kind of consumer data or enterprise data, that's just a means to an end, right? I don't think criminals care about, like, you know, all the things I bought at that one retailer, right? outside of the extent it helps them make money. So they might steal that as a threat to the company and say, hey, we're going to leak all this data, make you look really bad, make you look like a bunch of bozos if you don't go do X, which is usually pay us some money. But I'm sure there's some edge cases, and it's obviously very nuanced, but I would say the grand majority of time, everything is a means to the end, and the end is to make money as a criminal.

40:05Yeah, and the data theft, then that data is sold on the dark web to brokers or, i mean it's not used directly i mean i have all you know i'm sure everybody these days you know use a password manager and like half your passwords are compromised by some breach somewhere you know and i know i should change passwords and but but what's but i haven't been attacked so what's happening to those passwords that have been compromised is it just that someone buys a million passwords and they just haven't gotten around to attacking me? Or is, yeah, what's going on there? I mean, it's nuanced, obviously. If some website is breached and they stole their passwords in a really foolish way and plain text something, then criminals will use those passwords to try to log in other websites for the same email account.

41:07They might go through a billion other websites and see where you use the same username and password, break into that, see what data is there. Eventually that kind of like propagates and spreads. And so they find something that's valuable, right? And it could be, I don't know, information to go blackmail people to make money. It could be to log into your Amazon account, to ship them some something. It could be your bank account. It could be your email account itself. So I can reset your other passwords and kind of spread. So I'd say like a lot of, and again, I'm being very reductionist in nature, right?

41:30Obviously I know there's other mechanisms and there's obviously organized activist groups that do have political objectives are not kind of nation states but i'd say generally people are kind of these are all kind of means to like you know making money in some way and so like at least that explains i think the grand majority so yeah like it's complicated but i think most people most of these criminals trying to like you know make money yeah and i'm getting a little off the topic because we've all faced this and yeah wonder i mean there's this other vector that you get text messages and i'm sure everyone's getting them you know it's crazy are you going to be there on sunday you know from something what's going on there yeah i mean you know sometimes i answer just to see if they'll say anything yeah and most times it it ends there they don't follow up yeah it's again it's kind of the same thing these are all kind of like many steps along the way to get to like some money so you might get a text message it's very innocent Hey, how's it going?

42:31We call that kind of, you know, again, assuming it's malicious, we would call that a reconnaissance, you know, email or text message. Does the phone number work? Is there a human on the other side? That's kind of helpful because maybe they want to, you know, set attack from a different angle, right? So knowing like will someone respond or they might not want to burn like maybe they broke into my cell phone and I have your number, Craig. They don't know if that's a real number. They can validate with kind of a cheaper number. That's a human before they kind of risk using their compromised number.

42:56That might be more effective for social engineering attack. That might be one technique. There's other things a little more direct. They say, hey, Craig, this is Evan. Like, thanks for having me on your show. They saw this post online. Hey, do you mind, you know, I'm stuck at the airport. Do you mind sending me like a Starbucks gift card? Like, I know it's like silly for me to ask, but blah, blah, blah. That's just, again, trying to get money. It could be, hey, you got a pack, you know, you missed a package delivery, right? Just log into this website, right? And that website, you know, I don't know, they're trying to get UPS passwords.

43:21They can actually reroute your mail. Or maybe they're trying to actually, like, they put a Google and Microsoft login or Yahoo log in front of that, try to get into your email account. It kind of propagates like the next thing. So they kind of take this like land and expand the approach. It's called like lateral movement through your accounts, your friends' accounts. But the goal there is, again, do they really care about, you know, your Starbucks gift balance or like your UPS deliveries? No, they're trying to like make money in somewhere, receive some sort of goods of value. So again, I'm being reductious, but my guess is like 90 % of these can be explained by someone trying to do something, you know, through a couple of hops or steps to kind of get money or value in some way.

43:55Yeah. Yeah. And you guys, you're open sourcing your AI native strategies. What is that? I mean, what are you talking about when you say that you open source your AI native strategies? I think like what we're trying to do is really, so I think probably what you're referring to is like what we're doing AI transformation. And my belief there is the way companies should operate in the future using AI to kind of integrate that into their core business processes is a lot different than, you know, the way all of our companies, including ours, have worked the last couple of years. As you have to imagine the best way to engage your customers, the best way to build product, way different than the age of AI.

44:29And so I think there's a lot of talk on the internet about people saying they want to use AI. I'm a big believer in kind of do it, don't just talk about it. So one thing that we've done is we started publishing all of our internal AI transformations. It's everything from AI generated art for our software, new features, automatic bug fixing in 24 hours, sales and marketing tools that kind of use AI that help customers, help our staff kind of better engage the customers. We're trying to share that, not because we think it's like some unique IP, but we want to be a role model of like how an AI-native company should work.

45:01And I think that's, again, I think people will figure out these things by themselves. We just want to share with the world. And it's somewhat selfish nature. We want our customers to see that we will listen better and respond faster and build products faster and better because we're using AI. We want all the people, all the builders in the world that want to work at a company like that to come join Abnormal. So we have this kind of awesome program where, yeah, once a day we publish new ways using AI to kind of transform our business. And my goal, at least my stated goal, and who knows how you measure this, but I want to be kind of the most, the furthest along compared to any other company kind of using AI to reinvent how we run our business.

45:35And I think we're just, you know, sometimes we're just getting started, but I think we're very far ahead of our peers. I see. Okay. I misunderstood that. Yeah. So you're not open sourcing the models, your defensive models, you're talking openly about your own digital transformation to an AI native. That's right. Yeah. Like I do think that the value of proprietary code base and go down with AI software engineering. And I think the reason we're best is not because we have the new code, but because we have the best data, which allows us to kind of train these models. So maybe at some point in the future, we should open source like everything we have, because I don't think it'll matter, want to help our competitors kind of win against us.

46:12But yeah, I think we're trying, at least right now, we have closed source software. That's our proprietary advantage right now. We want to kind of share all the ways we're using AI. So we've always been an AI-native product, right? You use machine learning AI since day one, you know, eight years ago. You know, that was before generative AI. Now there's new ways of kind of, you know, building, running, and managing our business using AI. It's better for our customers, better for our employees. And we want to share that with the world because I think every other company needs to be doing that they're not going to win in the future and what are some of the areas that that you're talking about because this is something i'm tracking and i'm interested in there there are all these legacy players in every industry but there are ai native startups that are you know starting with llms and building businesses up from there and they're going to be much leaner more efficient 100 targeted than legacy companies.

47:06So is that what you're talking about is becoming an AI native company and where do you start? So we do AI transformation, it's across every part of the business. And I think about kind of the four core business processes. You have your product development lifecycle, your employee lifecycle, your customer journey, and kind of like the sales and marketing lifecycle. And then you're kind of like the meta business management process. And we're kind of investing in all those areas. In software engineering, we're doing all the things you expect. We have all AI-generated product design. We listen to 80 % of our customer calls.

47:37That gets kind of interpreted by basic AI product management. It pulls out features to build, bug fixes. We have AI bug fix validators, which try to take the feedback from a customer call, reproduce the bug. If it's a bug, it submits it to our bug tracking system. We have an adversarial AI which goes through every bug in our bug tracking system and say, hey, the user got it wrong. Prove them wrong. They can't prove it wrong. We have another AI go generate code to fix the bug. A fourth one to go figure out how to, you know, if the bug fix works. A fifth one to summarize that for engineers, they can do human review.

48:07If they accept that, a sixth one to go and kind of respond back to that customer, right? We're trying to have 24-hour bug fixes. So all things you'd expect. Same, everything from like technology selection, architecture design. I think people underestimate the, you know, how much you can do there. In like customer success, right? We are kind of on the hr side we have ai that listens to our calls to customers it analyzes kind of how well did the person do where are they showing empathy where they showing kind of good product knowledge it gives kind of a personalized executive coach for every employee right their managers see their feedback just say hey here's what you did great here's an upper game so you become better at your craft for on the sales and marketing side we have ai that will basically kind of do meeting briefs they'll go do deep research on every person every customer are they in the news so every salesperson enter a conversation with the equivalent of like 20 hours of the research here's the people here's they care about as they said online here's the technologies we think they use basically we can see on the internet so every person's coming in fresh all their homework done without spending all that time you know we're using ai i personally use ai for executive coaching i have ai go through every i record all my calls inside the company i have my hey i go through that and say what did evan misunderstand where he's not listening what can i do better right and i kind of have that feedback to me.

49:16I have AI go through all my meetings, all my documents and summarize for my human executive coach. Here's what would be most valuable for him to see to give me better coaching. So I think across every part of how we do business, AI can transform how it works. And like in some pockets of engineering, we've seen a 10x improvement, not 10%. And so I think the, you know, obviously there's never more hype around AI technology, but I think the, you know, this is like the real deal when it comes to transformation.

From the publisher

In this episode of Eye on AI, we sit down with Evan Reiser, co-founder and CEO of Abnormal AI, to unpack how AI has fundamentally changed the cybersecurity landscape.

 

We explore why social engineering remains the most costly form of cybercrime, how generative AI has lowered the barrier for sophisticated attacks, and why humans have become the primary attack surface in modern security. Evan explains why traditional, signature-based defenses fall short, how behavioral AI detects threats that have never existed before, and what it means to build security systems that understand how people actually work and communicate.

 

The conversation also looks ahead at the AI arms race between attackers and defenders, the economics driving cybercrime, and what it truly means to be an AI-native company operating at scale.

 

This episode is a deep dive into the human side of AI security and why the future of cybersecurity depends less on code and more on behavior.



Stay Updated:

Craig Smith on X: https://x.com/craigss

Eye on A.I. on X: https://x.com/EyeOn_AI


(00:00) Abnormal AI's origin

(02:31) Why phishing is still the biggest threat

(05:57) How attackers manipulate human trust

(10:05) The true cost of social engineering

(11:58) Vendor account compromise explained

(15:02) How AI changed cyber attacks

(16:28) Behavioral security vs traditional defenses

(19:55) Where Abnormal fits in the security stack

(22:24) Human psychology as the attack surface

(24:01) Why cyber defense is asymmetric

(28:48) Humans as the new zero-day

(31:01) Why attackers target people, not systems

(33:21) Behavioral modeling from ads to security

(36:10) Why money drives almost all attacks

(40:06) What happens after credentials are stolen

(42:18) Text scams and lateral movement

(43:55) What it means to be AI-native

(47:13) How Abnormal uses AI internally

More from Eye On A.I.

All 266 episodes
#313 Evan Reiser: How Abnormal AI Protects Humans with Behavioral AIEye On A.I. · 50 min
Listen in VO