In short
Practical AI Podcast Episode Summary
Episode Title
AI is Changing the Cybersecurity Threat Landscape
Episode Description In this episode, hosts Chris Benson, Gregory Richardson, and Ismael Valenzuela discuss how artificial intelligence (AI) is transforming the cybersecurity landscape. They explore the evolving threats posed by cybercriminals, the crucial role of human defenders, and the ongoing AI standoff between attackers and defenders.
---
Key Themes and Discussions
- AI's Impact on Cybersecurity
- Advancements in Threats: AI is being leveraged by cybercriminals to enhance their operations, making attacks more sophisticated.
- Human Element: Despite advancements in AI, human defenders remain essential for effective cybersecurity strategies.
- AI Standoff: The episode discusses the ongoing battle where attackers and defenders continuously adapt to each other's tactics.
- Understanding Cybercriminal Motivation
- Financial Incentives: The shift from "harmless hackers" to financially motivated cybercriminals marks a significant change in the threat landscape.
- Diverse Motivations: Besides financial gain, motivations include espionage, hacktivism, and political agendas.
- Characterization of Adversaries: The need for organizations to understand the attackers’ motives and methods to devise effective countermeasures.
- AI as a Tool for Defenders
- Predictive AI: The use of predictive AI to anticipate and prevent attacks before they happen.
- Classification and Contextualization: AI can help classify threats and contextualize data for better decision-making in crisis situations.
- Human-Machine Collaboration: Emphasized the need for a collaborative approach where humans and AI tools work together effectively.
- The Hype Cycle of AI in Cybersecurity
- Overhyped Expectations: The discussion acknowledges the hype surrounding AI and its perceived capabilities in cybersecurity.
- Realistic Applications: Focus on practical applications of AI, rather than treating it as a panacea for all cybersecurity challenges.
- Skepticism of LLMs: Critical views on the utility of large language models (LLMs) in cybersecurity, emphasizing the need for focus on more practical applications like classification and threat intelligence.
- Future Outlook
- Emerging Threats: Expectations of increased deception techniques used by attackers, particularly through deepfakes.
- AI's Role: Anticipated growth in AI applications within cybersecurity, stressing the importance of using it wisely.
- Leadership in Tech: A call for ethical leadership in tech as the industry evolves, balancing technological advancement with moral responsibilities.
---
Key Takeaways
- AI is a double-edged sword: While it empowers attackers, it also provides defenders with tools for enhanced security measures.
- Human intervention is crucial: The need for skilled cybersecurity professionals remains paramount even as technology evolves.
- Understanding the attacker: A deep understanding of attackers' motivations and behaviors can guide effective cybersecurity strategies.
- Practical AI use: Emphasis on the importance of applying AI in realistic, effective ways rather than succumbing to hype.
---
Notable Quotes
- "AI is just one more tool in the arsenal of any of these people." - Ismael Valenzuela
- "We gut ourselves... by feeding into the hype cycles and selling stuff that we know good and gosh darn well are absolute smoke and mirrors." - Gregory Richardson
---
Featured Guests
- Gregory Richardson: Vice President and Global Advisory CISO at BlackBerry.
- Ismael Valenzuela: Vice President of Threat Research & Intelligence at BlackBerry.
- Chris Benson: Principal AI and autonomy research engineer at Lockheed Martin.
---
Further Reading and References
- [The AI Standoff: Attackers vs. Defenders | BlackBerry Blog](https://blogs.blackberry.com/en/2024/03/ai-in-cybersecurity-attackers-defenders)
- [BlackBerry Website](https://www.blackberry.com)
---
This detailed summary captures the essence of the podcast episode, highlighting key discussions, arguments, and insights while ensuring accessibility for readers interested in the intersection of AI and cybersecurity.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:03Welcome to Practical AI, the podcast that makes artificial intelligence practical, productive, productive, and accessible to all. If you like this show, you will love The Change Log. It's news on Mondays, deep technical interviews on Wednesdays, and on Fridays, an awesome talk show for your weekend enjoyment. Find us by searching for The Change Log wherever you get your podcasts. Thanks to our partners at Fly.io. Launch your AI apps in five minutes or less. Learn how at Fly.io. What's up, nerds? I'm here with Kurt Mackey, co-founder and CEO of Fly. You know we love Fly. So Kurt, I want to talk to you about the magic of the cloud.
0:44You have thoughts on this, right? Right. I think it's valuable to understand the magic behind the cloud because you can build better features for users, basically, if you understand that. You can do a lot of stuff, particularly now that people are doing LLM stuff. But you can do a lot of stuff if you get that and can be creative with it. So when you say clouds aren't magic because you're building a public cloud for developers and you go on to explain exactly how it works, what does that mean to you? In some ways, it means these all came from somewhere. Like there was a simpler time before clouds where we'd get a server at Rack Shack and we'd SSH or Telnet into it even and put files somewhere and run the web servers ourselves to serve them up to users.
1:25Clouds are not magic on top of that. They're just more complicated ways of doing those same things in a way that meets the needs of a lot of people instead of just one. One of the things I think that people miss out on, and a lot of this is actually because AWS and GCP have created such big black box abstractions. Like Lambda is really black boxy. You can't like pick apart Lambda and see how it works from the outside. You have to sort of just use what's there. But the reality is like Lambda is not all that complicated. It's just a modern way to launch little VMs and serve some requests from them and let them like kind of pause and resume and free up like physical compute time.
2:00The interesting thing about understanding how clouds work is it lets you build kind of features for your users you never would expect it. And our canonical version of this for us is that like when we looked at how we wanted to isolate user code, we decided to just expose this machines concept, which is a much lower level abstraction of Lambda that you could use to build Lambda on top of. And what machines are is just these VMs that are designed to start really fast or designed to stop and then restart really fast or designed to suspend sort of like your laptop does when it closes and resume really fast when you tell them to.
2:30And what we found is that giving people as primitive is actually there's like new apps being built that couldn't be built before, specifically because we went so low level and made such a minimal abstraction on top of generally like Linux kernel features. A lot of our platform is actually just exposing a nice UX around Linux kernel features, which I think is kind of interesting. But like you still need to understand what they're doing to get the most use out of them. Very cool. OK, so experience the magic of Fly and get told the secrets of Fly because that's what they want you to do. They want to share all the secrets behind the magic of the Fly cloud, the cloud for productive developers, the cloud for developers who ship.
3:09Learn more and get started for free at fly.io. Again, fly.io.
3:32Welcome to another episode of the Practical AI Podcast. I'm Chris Benson. I'm a principal AI and autonomy research engineer at Lockheed Martin. And with me today, I have two guests that are going to join in the conversation. They are both from BlackBerry. One is Gregory Richardson, who is Vice President and Global Advisory CISO at BlackBerry. And there's also Ismael Valenzuela. Did I get that correct? Yes. Thank you, Chris. And I normally have Daniel for that. And he is Vice President of Threat Research and Intelligence at BlackBerry. Gentlemen, welcome to the show. Thank you so much for joining.
4:10Honor to be here, Chris. Thank you. Thank you, Chris. Really glad to have you. We're going to talk today all about security and threats and issues like that. I know that there's a blog post to get us started, and I'll let you guys kind of take it from there, that you have on the BlackBerry blog that was the AI standoff, attackers versus defenders. And I know Daniel was the first person to see it and said, we got to get these guys on the show. And then ironically, he is not able to get here today. And I know he's disappointed about that. But wanted to kind of start off and kind of can you tell us a little bit about the topic in general before we dive into the specifics and the landscape and who does it affect and why should they care?
4:58So maybe it has to do a little bit with our backgrounds as well. Right. So I cannot really say I'm an expert in AI. Well, I cannot really say I'm an expert on anything. And the more I spend time in this industry, the less you feel you know, right? But I can say my career has been mostly dedicated to cyber defense. I started on the offensive side, but then I quickly moved into the, well, not quickly, but over years, I moved into the defensive side. So I've seen both sides and I still like to, you know, pick on the offensive side to learn from it. I call that think red, act blue, right? Think as an attacker to become a better defender.
5:34So obviously, when I was writing about this, I had to bring the AI flavor to it. Is AI going to represent an advantage to attackers or defenders? And we usually get that question. So I wrote this from a cyber defense perspective, and that's what you see there. So before we dive fully into the article, what was driving the need? What are you seeing? You guys both at BlackBerry, there's clearly a need driving, addressing cyber. Tell us a little bit about how you see the lay of the world from a cyber standpoint and what it is that, you know, what's the problem you're trying to solve in the large?
6:14Yeah, let me give you the contrasting kind of perspectives, because I actually didn't know that Ismail, who I've worked with for many years now, even at different companies before BlackBerry. I didn't know that you started on the offensive side and then switched to the defensive side. I am very much the opposite, well, except for the switch. I started on the offensive side, and I remain on the offensive side. The part that I am most intrigued by and always have been is what I call, well, what's called attacker ontology. So I've always wanted to understand what makes the attacker behave like an attacker so I can better defend.
6:53But my primary areas of research and areas of work and my primary focus has always been trying to anticipate what the attacker is going to do so that I can help our clients strategize, et cetera, et cetera. It's always been like even before, and just from an AI perspective, cybersecurity has been using AI for well over 20 years. I'd say probably 30 years almost. So it's not as novel as it is to the average layperson. But even before the popularization or the democratization of AI that we've seen in the last two, three, four years with companies like OpenAI, etc., even before AI was so much in the forefront, I've been very intrigued with how we can build strategies that help customers, organizations, governments anticipate earlier what they need to be protecting against.
7:48And that's kind of where my perspective comes. So I didn't contribute to the blog. I believe it was primarily Ismail's blog and maybe Ismail and his team. But my perspective on the blog was very much how can we use AI to also help level the fields a little bit more. It's a constant battle with the feels going back and forth and kind of who's winning the race between attackers, cyber criminals and defenders. So anything we can use to help balance that out, that's always been my interest. I'm curious, before we fully dive into the AI stuff, can you describe, because we have a very AI-focused audience diversely in that area, but a lot of folks maybe have never been really addressing cyber themselves.
8:37And when you talked about that, the ontology, and kind of talked about maybe some of the motivators that, you know, what are these people out there? Who do they represent? What are they trying to do in a baseline, like with or without AI? What are we dealing with in the world? I remember, and again, I've been at this for a while, probably longer than most. I'm like your age, Chris, so I'm approaching 60 years old. Yep. Exactly. Old, curmudgeon-y. Get off my lawn. That's right. So I'm approaching that age, that scary age of 60, at least it's scary to me. So I remember a lot of things historically about the cybersecurity industry that give me perspective.
9:20One was, I want to say it was around 2010, 11, or 12, somewhere around there. It was the first time that I noticed in the FBI's threat intelligence report that they used to release every year. In that report around 2010, 11, 12, was the first time that they reported, the FBI reported, that profits derived from cybercrime surpassed, globally, surpassed profits from cybercrime. heroin, cocaine, marijuana sales combined. And for me, this was 2010, like I said, that to me was a tipping point. In my mind, I've built the narrative that right around then, or maybe a year or two, year or three before then, or after then, that's when criminal organizations focused in on cybercrime.
10:16And it switched from being the harmless hacker in the grandma's basement, thinking like a Kevin Mitnick type of a guy who kind of started off that. For those who are in the cyberspace, they know the name. He was kind of like a quote unquote harmless hacker. He was arrested. I think he might've been one of the first cases of a full-fledged arrest and conviction for cybercrime. But his cybercrime was always focused on what can I learn? What can I gain from these things that I'm illegally getting access into? It was less, if at all, it was not about what can I financially gain. Now, it is largely financially motivated.
10:58I'll let Ismail deal with this a little bit more because this is his forte. He runs our threat organization. But from my perspective, it is largely based on what can we monetize. Ismail, what do you have to add to that? Well, the first thing is I'm so happy to know that I'm the youngest one in the room. Okay. So it says me with a white beard, right? We're all showing it a little bit, but that's okay. We're on top of things, man. But yes. So as Greg says, my team, our job is to characterize the adversary and to translate that into, we call it countermeasures, right? So think about, you know, you're analyzing or your goal is to design a vest to protect law enforcement, for example, right?
11:39So we analyze the weapons, we analyze their tools, we analyze their motivation, how they operate. And then we take all of that and we use this information to design the most effective vest to protect against those bullets. But it's not just about the bullets. It's about who is using these weapons and what's the reason they're using them for. That's the motivation. That's really the key piece. And this financial motivation, as Greg has been saying, has been growing very fast. And that's why we all know about ransomware, for example. But there's a lot of other motivations, and maybe we don't talk about that much.
12:12Well, some of them we do. Spionage, nation states, the so-called APTs, advanced persistent threats, that we often see in the news, and especially right now around election times, there's a lot of talking about this manipulation of information by these nation state actors. These are very well funded, and typically they're the most advanced of all of them. But there's other motivations too. There's hacktivism. We have seen groups like Anonymous in the past, like many others, that they would target organizations just because they make money, I don't know, selling records. And they think that's evil.
12:48But at the end of the day, cyber is just a weapon. It's a weapon that can be used for good. It's a weapon that can be used for evil. Same as AI. AI is just one more tool in the arsenal of any of these people. So that's why I like to talk about the motivations because it helps us to understand what's the purpose of using a tool, in this case like AI, in this cyber world if you want. So how does BlackBerry, can you kind of layer in BlackBerry having kind of given us that landscape of what you're looking at in the world? And how does BlackBerry start layering into this? What are your interests in that capacity and what are you trying to accomplish?
13:28Good question. Well, so we have been in the world of securing communications for quite some time, right? And I think everybody remembers those Blackberry devices. We don't do devices anymore, but we do software to protect devices, not just phones, but also endpoints all over the world. and specifically my team, what we do is to, as I mentioned before, try to characterize these attackers to be able to protect customers, right? And this takes the form of products. It takes also the form of services from endpoint software to zero trust network access to high military-grade encryption to secure communications to even software to manage a crisis.
14:18It could be instant response, like the environment is on fire, the attacker is here, and we need to remediate that. Or it could be even like a natural disaster. So when we talk about threats, we just even go beyond just the cybersecurity threats. That's a high-level overview. I don't know, Greg, if you want to go deeper into that. I don't know if I'll go deeper. I might hang off of one of the branches. The side of BlackBerry that I'm maniacally focused on is really just, I want to say, purely the cybersecurity part. So obviously, BlackBerry does a lot of other things. We have our automotive and IoT section, segment that's very, very, very large, probably a billion-dollar business in and of itself with operating systems that run in any car that has anything digital in it, et cetera.
15:03The part that I'm focused on, though, is pretty much purely my area of expertise, which is cybersecurity. So what we've been doing from my side of the house is helping customers build their defenses in a way that allows them to do something that I call preemptive security. If you remember in my earlier preamble, I referred to, you know, we need to be able to predict what the attackers are going to do so that we can defend against it. I help my customers strategize around building those platforms, those tools, those combination of different tools to do exactly that. The nuance of it with cybersecurity is just because of organically how the industry has grown and VC investment and a million other reasons, we've sprawled very much into there's thousands of tools to get the job done.
15:59And there's probably thousands, if not tens of thousands, of different little aspects that need to be protected in the average organization. You might have, you know, endpoints, you know, the computers. You might have servers. You might have a network. You might have stuff up in the cloud. You might have operational technology or IoT technology. All different aspects that all need to be protected that all require completely different tool sets. That sprawl has made it difficult for customers to have a homogenous approach to how do we defend against it all. Ismail can probably talk more about one of the things that attackers do, I want to say very, very, very well, is attack the gaps between our tools.
16:46So if they detect that you have a great tool that is the foremost tool on protecting computers, your endpoints, but your network stack is a little bit weak, they're going to attack right in the middle of that network stack and gain access to the endpoints. Vice versa, if they see your network and your endpoint, rock solid, but you have a weakness over in the cloud, you're going to start seeing cloud attacks. What the industry has not been very good at that BlackBerry is trying to help resolve is how do we help customers pull all of that telemetry in to be able to get, as I said, a homogenous view of everything that's attacking them and everything they're doing about defenses across all those little silos.
17:28That's what I help my customers strategize on. And my customers vary from governments. I met with the government of Morocco a couple of weeks ago to large corporations, the biggest banks in the world, the biggest airlines in the world, et cetera, et cetera. And it just spans the range. But all of them have that problem. The most mature organizations have well-developed tools that are unintegrated. And the least, like the SMBs, which are also our targets, our customers, have oftentimes less developed security stacks. But the problem is the same. Even if they say, well, we can make an investment in this one little tool, then they have their gaps and they're not being able to ingest all of that intelligence that they have.
18:14It says something about the industry, and I'm going to kind of shoot at my own job now. It says something about the industry that a strategist at that level focused on those types of problems is even needed. Like you don't have that in the medical industry, as far as I know. You definitely don't have that in, for example, the automotive industry. Like there aren't integrators that need to help you with how to integrate, you know, your car to work properly. You go to Ford. You say, I want an SUV. They give you the whole SUV. They don't say buy the motor here and then go down the street and get four tires and go across the way and get a transmission.
18:52You glue it together and you make it work. They give you the whole thing. Cybersecurity doesn't do that. We don't give you the whole thing. So that necessitates a cross section of strategists like myself and the team that supports me to go out and actually help customers parse through this web of tools that they've built. You probably don't go to cybersecurity industry events. I do. Ismail does as well. Ismail speaks at many of them. The amount of vendors on the expo floor, I remember going to RSA 13 years ago or so. Handful of vendors. It was a small convention. Now, it's early. Thousands, 3, 4, 5 ,000 vendors.
19:3440 ,000 people last year. That's a lot. Dude, I thought it was big. I went to a conference called Jitex. holy spook almost a million people at Jitex at a conference talking about technology it was crazy insane the amount of boots I think was 40 ,000 vendor like insane that there's an appetite for all of these tools and customers are bobbling them up and it makes their environment more complex and that's where we oftentimes come in noisy too yeah there's a lot of noise this industry
20:23Okay, friends, here's what I love about Notion. And I'm a big fan of Notion. I think all the new improvements they've made recently with Notion AI built right in is just astounding. Being able to have your notes, your docs, your projects, your to-dos, your tasks, your dashboards, all the things in one single place, beautifully designed, and then add on top of that Notion AI with the ability to search, analyze, chat, and even describe to you how to build dashboards. You can ask it, hey, I want to do this. And it will help you build out a dashboard or a database or a template that makes sense for you, your workflows, your business, your orgs, or whatever.
21:02Notion really is the perfect place to organize your tasks, track your habits, write beautiful docs collaborate with your team there's just so much you can do with it and notion ai already has the context of all that work it's also connected to multiple knowledge sources it uses ai knowledge from gpt4 and claude to chat with you about any topic they can search across thousands of notion docs in seconds to quickly answer really any question you have about your context which is all of your Notion docs. They also have AI connectors. This is now in beta. Notion AI can search across Slack discussions, Google documents, Google slides, Google sheets, and even tools like GitHub and Jira.
21:45Those are coming soon. And the cool thing with Notion is it could be used by small teams, individuals, or even fortune 500 companies. It is a very scalable tool that can help you spend less time emailing, cancel more meetings, save your time searching for all your work, and reduce spending on multiple tools. And this helps everyone be on the same page. Try Notion today for free when you go to notion.com slash practical AI. That's all of our case letters, notion.com slash practical AI to try the powerful, easy to use Notion AI today. And when you use our link. Of course, you are supporting our show and we love that.
22:27Again, notion.com slash practical AI.
22:51okay so as you guys have watched the industry explode and you're and you're dealing with these things that other industries don't necessarily have to address. You talked about kind of just the sprawl of assets to defend and the gaps between them and the fact that there are so many tools addressing different components. I would imagine that's quite a challenge, which is one of the reasons I'm sure the industry has gotten as big as it is. As you're looking at that and you're starting to see these new things, and when I say new, meaning some of the more recent tools on the AI realm and stuff like that.
23:27As cyber experts, how is AI starting to layer into this ecosystem? How do you see that? What are the pros and cons, the risks and threats that it creates? Can you tell us a little bit about how those two converge? Yeah, as Gregor mentioned it before and explained really well that this is an industry that is always chasing the new shiny. right like what's the new thing that can solve all of my problems and there is no such a thing it's a lot more complex than that and every time that we try to find that single tool that silver bullet uh we often fail right because of a lack of an understanding of how all these things need to come together so we're we're in the middle of that hype and now the tool is of course ai right and i would say even more specifically llms uh generative ai because we know and you guys in this show know well that when we talk about AI, it's not one thing, right?
24:22It's a lot of different things. For example, at BlackBerry, we have been using for many years, coming from the Silence engine, from the Silence days, a predictive AI engine, right? We know we're talking about predictive machine learning, essentially. And I remember, well, I wasn't at Silence at that time, but some of my colleagues that were told me that they were at Black Hat, I think probably 2016 maybe 2016 or something like that, right? They were talking at Black Hat about this. And a lot of people were like, oh, boo, you know, that's not possible. You're selling smoke. You know, that's not the way you detect malware.
24:57Fast forward to today and everybody understands that you cannot fight malware with signatures, right? I mean, in our report, and we produce these reports on a quarterly basis, we talked about the latest increase in the last quarter. we're talking about a 53 % increase in unique pieces of malware, right? I think, I don't know if the audience is familiar with the concept of a hash or a fingerprint. You take a binary, a blob of data, and you create a fingerprint or a hash of that. And that says, okay, that's unique, right? Different hashes, different files. So we're talking about over 11 ,000 pieces of unique malware per quarter that we have seen with our telemetry.
25:37How in the world are you going to, create a database, maintain a database. It's an unscalable issue. It's not scalable, right? So predictive machine learning helps us with that. And it's been helping us for many years to have really, really good detection of these type of things. Now, LLMs can also be useful for different things. So once again, I think the summary is AI is a useful tool in the hands of defenders. It is also used by attackers, and we can maybe get into that if you want. But I would say that once we go over this hype cycle that we always have in this industry, we'll probably understand that it's just one more tooling in our arsenal and that we need to remain problem focused.
26:24Just because we have a solution to a specific thing, it doesn't mean that it's going to be the solution to absolutely everything. But of course, it helps. Yeah, I'll comment on that if I may, Chris. Sure, absolutely. Ismail touched a little bit. He kind of grazed over LLMs. And I'm glad you only grazed over it because of what I'm about to say. We think LLMs, as good as they are, and they have some excellent use cases and value, I think they contribute to a lot of the noise and the hype machines that we hear in the industry right now. I'll speak specifically for cybersecurity. I am not yet convinced of the utility, the usefulness of an LLM, particularly for its natural language ability, ability to process things via natural language.
27:12I'm not sure that that was the problem we had. I speak to psych analysts and chief information security officers literally on a daily basis. That's my job. I can't remember in the last 30 years doing this that a group of operators, SOC analysts, etc., have told me, you know what would be great, Greg? We don't know how to extract the data from our tools. If we could only say that in natural language, that would really help. That's not the problem. The people that are doing these jobs in the SOCs, etc., etc., are very adept at their tools. They don't have a problem communicating with the tools and writing a parsing command or a query or whatever to extract the data.
Read the full transcript
27:56That's not the issue. There's other things that AI and machine learning can help with. Classification is a big one. Ismail has already referred to prediction. I think that's a very, very big one that is underutilized today. But classification, how do we classify not only files and hashes, but behaviors, indicators of attack, indicators of compromise? How are we able to classify these three things that are connected together, or in the case of a cyber attack, these 50 things, these 50 behaviors or indicators we find, how can we pull them all together and say, listen, this is leading up, these all belong together.
28:34These 10 things that we found on your network and these 15 things that we found on your endpoint and these 12 other things that we found simultaneously in the same temporal window in your cloud environment, they all belong together and they're all part of one attack. That classification process, I think that's somewhere where AI can help because that's where the gap is. Taking the ton of data that comes in that swamps our security operation centers with alert fatigue, parsing through that to, quote unquote, make sense of it and kind of narrow it down to a few cases. And when I say few, that few may be thousands still, but it's an order of magnitude or more drop from the tens or hundreds of thousands of events that you get.
29:19If you can drop that down to a significantly smaller amount of cases and then tackle those cases, that's one of the problems that I see AI solving in cybersecurity extremely well. it's really interesting to hear you say that um and i wanted i just as an aside for a moment uh for our audience who you know is is going episode to episode this is a topic we talk about a lot it sounds like you're going through you know you're familiar with the gartner uh hype cycle you know it goes up over the top you know maximal hype people become frustrated it plunges down in the trough of disillusionment where they're very unhappy and they say this stinks i don't want to deal with.
29:56And then people kind of take a second look and they go, well, it's good for some things. It's not, it's not the solve, you know, it doesn't solve everything. And they find their, their plateau of productivity where it's actually useful. And it sounds like you've been going through that same process. So like, like many other industries have, um, and, and you're really practical and you also drew out another point that I'd like to emphasize. And that's that, uh, when it comes to generative AI and LLMs and such, we have a habit of forgetting that there are other techniques in the AI realm out there.
30:27Classification. Other ways. Yeah, exactly. And you guys are like, we have other tools here that are really productive for what we're doing, just maybe not the super hype-y part of it. So I'm really glad that you shared that with us because we are practical AI on the show and we're trying to get people on track. I'll just give you an example of how absurd this is getting. I saw a large vendor, and I'm really tempted to say the name, but I won't, that was showing how cool these generative AI is applied to the SOC. So the SOC at Security Operations Center, they typically use dashboards, right? They have dashboards and they're looking at, for example, number of DNS requests or number of alerts for these or for that.
31:08So there's this dashboard and there's a peak of activity at 7 p.m. So now the, yes, the LLM is like, see, I saw a peak of activity at 7 p.m. And I'm like, how much money are you paying for that, right? There's a large cost in this type of subscriptions. And I can easily train an analyst to catch that. And that person can give you even more context and have probably more intuition, more maybe even knowledge of the strategy, talking about strategy, Gregory, and even more creativity than that. So absolutely, you got to know what the tool is useful for. It's very useful for contextualization, summarization, pattern matching, generalization, hypothesis testing, right?
31:51I could go and say, hey, based on all of these reports that I have written on all of this database that I have, give me a, going to the offensive side, Greg, give me a emulation plan for emulating this threat actor, right? And it's not going to be super creative because it's going to be based on things that have already been, the data that has already been gathered, but it will save me a lot of time because I will not have to go through all of these documents myself and have to, you know, extract all of these different things. So I may iterate over that faster and get to that faster. But yeah, there's a lot of hype.
32:25One of the things that I, and again, I've been in this industry for almost 40 years. So it's pretty much the only thing I've done professionally, you know, since I came out of college. So I'm very passionate about it in case that's not extremely evident to your audience yet. Therefore, I also tend to look at myself and my industry with a really, sometimes a bit of a harsh lens. And so I'm going to say something now that might be applicable outside of cyber, but I see it from inside of cyber. And we gut ourselves. We do legit harm to ourselves by feeding, and when I say we, the vendors primarily, by feeding into the hype cycles and selling stuff that we know good and gosh darn well are absolute smoke and mirrors or have limited usefulness, but they sell well.
33:20You know, the notion of we're going to have an AI-powered SOC and you're not going to need SOC operators anymore. You know, all these analysts, you won't need them. You're going to get just less analysts because the AI is going to do all of that for you. The more we hype that up, the more you get that Gartner hype cycle where people try it. They go, this doesn't work this way at all. I still need the humans. The humans add, as Ismail said, context and awareness and situational strategy. Not to mention things like morality, which AI is terrible at. Now, can the AI do bulk volume of data processing?
33:56It absolutely can. And that's one of the places we should lead into. I've been touched on things like vision and some of the more esoteric parts of AI that we don't speak about every single day. So I'm not limiting it to prediction, classification, and large language models. But I'm just saying large language models are amazing. I use them regularly for processing anything having to do with language, whether that's code language, indicator language, or spoken read language. One of my very practical things that I do with almost every piece of content I'm attempting to digest now is I try to get the audio and I run a transcript.
34:38Send it to Whisper, send it to whatever API, give me a transcript of it, analyze the transcript for me, give me some key talking points. What are the things that I said? What are some tweetable lines that I want to broadcast out? What are some key quotes that I said? And I build my brand on social media and I flavor my other talks with that content that I've said already. I'm going to do it with the talk that I'm doing right now. That's why, in addition to as a backup, I'm also recording my own audio here so that I can extract that. And so I use LLMs. They have utility, but they're not the end-all panacea, you know, oh my God, they're great.
35:15We should throw everything at an LLM. The more we do that, I think the more we do intrinsic harm to the industry and most importantly, to our customers' ability to defend themselves. because the threat actors are not, at least I don't see the threat actors out there building a hype cycle. I see them out there efficiently sharing threat intelligence and leveraging it to build new novel attacks so that there's unique ways that they can get their objective, which is monetize weaknesses in our environment. We are not as maniacally focused on our task at hand as that yet.
36:11What's up, friends? I've got something exciting to share with you today. A sleep technology that's pushing the boundaries of what's possible in our bedrooms. Let me introduce you to Eight Sleep and their cutting edge Pod 4 Ultra. I haven't gotten mine yet, but it's on its way. I'm literally counting the days. So what exactly is the pod for ultra? Imagine a high tech mattress cover that you can easily add to any bed, but this isn't just any cover. It is packed with sensors, heating and cooling elements, and it's all controlled by sophisticated AI algorithms. It's like having a sleep lab, a smart thermostat and a personal sleep coach all rolled into a single device.
36:53It uses a network of sensors to track a wide array of biometrics while you sleep, sleep stages, heart rate variability, respiratory rate, temperature, and more. It uses precision temperature control to regulate your body's sleep cycles. It can cool you down to a chilly 55 degrees Fahrenheit or warm you up to a good nice solar temperature of 110 Fahrenheit. And it does this separately for each side of the bed. This means you and your partner can have your own ideal sleep temperatures. But the really cool part is that the pod uses AI and it uses machine learning to learn your sleep patterns over time.
37:33And it uses this data to automatically adjust the temperature of your bed throughout the night according to your body's preferences. Instead of just giving you some stats, it understands them and it does something about it. Your bed literally gets smarter as you sleep over time. And all this functionality is accessible through a comprehensive mobile app. You get sleep analytics, trends over time, and you even get a daily sleep fitness score. Now, I don't have mine yet. It is on its way. Thanks to our friends over at 8sleep. And I'm literally counting the days I get it because I love this stuff.
38:06But if you're ready to take your sleep and your recovery to the next level, head over to 8sleep.com slash practical AI and use our code practical AI to get 350 bucks off your very own Pod 4 Ultra. and you could try it free for 30 days. I don't think you want to send it back, but you can if you want to. They're currently shipping to the US, Canada, United Kingdom, Europe and Australia. Again, 8sleep.com slash practical AI.
38:49so greg that was that was great uh kind of explaining how you're approaching that you know trying to keep the ai practical trying to have the right ai in the right place and great call out for the fact that like so many other industries, there is a proclivity in your industry to also do the kind of, you know, AI and everything. You know, you said you use the phrase, you know, selling smoke and mirrors and stuff. And you guys working really hard to productively give solutions and strategies that are not built around the hype side of all this. Could you dive into a little bit more of that? and also Ismail if you could also address a bit about the blog itself that you wrote so that we can draw some draw some of our listeners into that and they can also read that as they're finishing up the episode and understand that I really appreciate that so kind of both the what are you doing in that practical sense and and what are you producing for your customers and then kind of how is the blog contributing to that do you want to start maybe with the blog and them.
39:53Greg, you can talk about the solutions we're building. Yeah. So the blog is essentially trying to address the hype that we were just talking before, right? And saying, okay, so what is AI being used for by the attackers? Let's start with that. Some people may think that, oh, attackers are crafting this malware that is autonomous, that it just goes out and finds a vulnerability like a zero day, right? We call zero day this industry, like something that we haven't found yet. It's Novell. Nobody knows about that vulnerability. Now this autonomous agent is going to exploit it. It's going to get into the company, steal the data, ransom the environment, and no.
40:32Then you wake up, right? There's no such thing. Not as of today, at the very least. I think we're talking about people around the same age. You probably remember Blade Runner from 1982. Of course. you know one right replicants there is no replicants as of today there's deep fakes that's a different thing that could look like humans that's the closest thing but uh there's no autonomous agents that can do all of these things or we don't see people that i don't know like you you are training dolphins right for your entire life and then all of a sudden now because of ai you can hack into companies and make a lot of profit out of that?
41:11Probably not. So what we see is attacker system is a tool essentially for the initial phases of the attack. And that means that they're getting a lot better at writing phishing emails. We have seen an increase in phishing emails with language that's non-English. For example, before, we would see some of these Eastern European organizations or Russian criminals sending emails in English that was like broken English. And you could quickly spot them and say, oh, yeah, this is phishing or spam. These days, everybody speaks not only perfect English, also perfect Japanese. We have seen an increase in number of phishing against Japanese companies or other languages that hardly would be used by these cyber criminals.
42:00And that's a clear use of LLMs. Now, in terms of coding, there's a lot of debate. It's very controversial, right? like, can you learn coding from scratch? Or can you just like use this to create code from scratch and we'll do these things? Probably not today. These models are getting better, but I still find out that every time I ask any of these agents to create some code for me, I still have to understand the code, understand what I'm trying to do, and being able to refine it and to tune it. Also, bear in mind that these models are crafting things based on the training that it has received, based on previous data that is already known.
42:38Therefore, when Greg maybe talks about predictive solutions and AI, that makes us also even more successful in the use of our AI because we have trained these models with everything that has been seen in the past as well. So at the end of the day, I think that AI is not going to be that much of an advantage to attackers. There's always a little advantage, but just because they're attackers, because they take the first step and you're on the defense side and you don't know if they're coming tonight or if they're coming tomorrow morning or if they're coming next month, you may anticipate that. And that's where my team does threat intelligence, which is looking at the geopolitics, looking at the weather forecast, right?
43:18What are the clouds signaling? And then based on that, you adapt your threat model. But you're always like one step behind by nature. That's what defense is about. But even though defenders may have that temporal advantage, I think when used properly by defenders, the field could be leveled and AI could be effectively used to do more things at scale, especially when you have a solid strategy. It's interesting that Ismail referred to updating our threat model, and he drew that analogy back to, you know, like the weather. You know, like you look at the clouds and based on what you see in the clouds, you react accordingly.
43:56You might pack an umbrella or something along those lines. I think that's such a propos analogy because interestingly, as a kid in the 70s growing up in the Caribbean in a hurricane zone, I remember sitting around the big box TV in the living room. I think it was even black and white at one point, because I'm old and primogeny, as I said earlier, and watching the predicted hurricane track for some storm that left the western coast of Africa that's barreling towards the Caribbean islands. My island is a small five mile by seven mile island. We could get and routinely got decimated by a hurricane.
44:36So if a hurricane is coming, you need to know those predictive tracks with the little circles and saying the storm looks like it's going to go there. Those in the 70s already were drawn and calculated by AI. It was one of the first very widely used use cases for predictive AI. So it's interesting that Ismail uses that as an analogy because that is exactly what we're doing. We're taking a use case that was well-developed with weather prediction, and that's what we're applying to attacker prediction. So you asked how we can apply this to the customer environment. One of the things that I am maniacally focused on right now is helping customers, as I said earlier, draw this all together.
45:22So I'm not going to get into product names because this isn't a sales pitch, but we've just developed something in the category called a managed extended detect and response tool set. And what's unique about our approach to that, that approach in that space is not unique at all. It's been existed. Just about every large cybersecurity vendor has something that plays in that space. What's unique about our take on it, we are heavily focused on regardless to what your security stack consists of. That's what we're going to ingest. Most of the other vendors use XDR type tool to say, listen, to get the maximum benefits out of our tool, you should really be using all of our stuff.
46:04So you should get our firewalls, you should get our endpoints, you should get our cloud stuff, and then it's going to be maximized. Our take is different. Our take is we understand that you, the customer, probably struggle with two things, a widely diverse ecosystem of security tools. And the second thing, especially for medium to smaller companies, you're probably struggling with finding the human resources to do these jobs. So we have a managed solution where our threat analysts, our security analysts, our well-trained human experts combined with predictive AI that, as Ismail said, has been well-trained on sensors and sensor data and threat data that we've been receiving for the last 10, 15 years.
46:49that's how we are able to not just ingest all of the data, classify and recognize that this is an attack that we've seen before, even if it's using novel and brand new unseen before malware, and then provide you defensive strategies against it. That's how I believe BlackBerry can help the market, the customers the most. I mentioned that I started as on the attacker side. I was never an illegal attacker. I started as a pen tester and then pivoted into reversing code and doing some other things like that. And I went from there. But most of my career was on the customer side. I proactively switched or maybe was convinced to switch to the vendor side probably about 10 years ago because I saw that gap.
47:40I saw that as a customer, I could buy all of these new widgets and toys, and it really wasn't making me more secure. So I came to the vendor side to try to influence the vendor defensive motion and product strategy to put out more products that legitimately can help customers solve those two problems, the manpower problem, the diversity of tool set problem. The amount of times I am told by a customer, Greg, we'll rip everything out and put in whatever you tell us. That's infinitesimum. It has happened. I have had a couple of Greenfield customers that said, listen, none of it's working. Take it all out and help us replace it.
48:21But that's rare. Most of the customers either have financial constraints, time constraints, or some other constraint. So they need to make do with what they have. Let's build a tool set that allows customers to use what they have and maximize the value they extract out of it. So as we wrap up here, and you've done great level setting how you guys are able to add value for your customers in this realm. This is such a fast-changing arena. You've got AI playing at some productive place in your approach, your strategy, and your solutions. But this is a fast-changing world that we're dealing with. As we wind up, do you have any thoughts from either of you or both of you about what you're expecting to see over the next few years, how you think things will change, what that outweighs a little bit looks like.
49:14Yeah, so I'll get started. I think we're going to see more deception used by attackers leveraging AI, especially with deep fakes. I think that's a very powerful application of AI to offensive capabilities. We already see a trend in the increase of volume and scale. I think that's one of the key things that AI also enables its hackers with, which is the augmenting their existing capabilities, make them scale. But that's exactly what defenders can do as well. But the main thing is starting with the definition of the problem. I think that's the most powerful question you can ask as a defender. What is the problem I'm trying to solve?
49:56Because AI, or not any other technology, it doesn't really change the mission of your organization. Are you a hospital, small hospital or a large hospital? Your goal, your mission is to protect the citizens, the people that go to have care. And you don't want this environment to get ransomed and admissions to be done by pen and paper. So people could effectively die because they didn't get admitted to the hospital. That's the kind of thing that we're looking at here, right? Or protecting critical infrastructure, protecting the school where our kids go to. So AI doesn't change the mission of your organization.
50:34AI doesn't change even the approach, the strategic approach to cybersecurity. You just need to find out where are the areas that can help you to scale and maybe cover some of the gaps that you have. And I think we talked a little bit about that, right? But improving detection and response times, disrupting attacks at specific places of the attack chain, giving you the ability to contextualize a lot of data to give you some, I'm a firm believer in the human machine teaming, right? To give you some input. So now the human can, with that information, take an action. And then also the models, the machine learning models, learning from that to effectively combine that human machine teaming, right?
51:16That Blade Runner, or in this case, the replicant, that takes the best out of both worlds. That's kind of my vision. about that. I'll chime in on that as well. The top five companies in the world by market capitalization right now are tech companies, all founded or co-founded by individuals with heavy technical background. This is very unique in this era that we find ourselves in now. This is changing leadership in a way that we, leadership, entrepreneurship, and just vision and strategy in a way that we haven't seen before. I think we're at a unique precipice to where we can maximize some technological applications that 10, 20 years ago, we wouldn't have even been having the conversation.
52:08The technology was there, was readily available, like AI that was written in textbooks in the late 1950s. The technology has been there. It's being popped into the forefront now because of that seismic shift where the biggest companies are tech companies. So my daughter, who's 15 years old, is very tech savvy. When I was 15 years old, I was an oddball because I was tech savvy. Like they looked at me like, you know, I had three heads. So what do I predict? I predict we're going to see acceleration in how those types of use cases and opportunities and candidly business opportunities are going to appear.
52:47But I also see, so there's always the positive and the negative, I see a risk, a huge risk of moral and character failures at the level of those leaders who have an unbalanced sense of high technical prowess, but potentially low morals, potentially low leadership acumen, potentially low spiritual acumen. there's an opportunity to balance that out as well. Personally, that's where my focus is. That's how I met Daniel from this podcast because we've spoken at events or met each other at events where we're trying to talk about those types of topics. How do you pull together technology and other things that are more from a moralistic perspective and help have the technology, but balance that out and vice versa?
53:40I think that's where we're going to have to be very cautious that we don't over rotate and end up accidentally, and I'm not talking about politics now at all, but end up accidentally handing the reins over to people whose gifting got them to a place where their character potentially could not sustain them. And I think we're at very big risk of that. So those are the two things that I see kind of for the future, both opportunity and risk. Fantastic insights from both of you. Gentlemen, thank you very, very much for coming on the show. It was a great conversation. I learned a lot. And I hope I can, as things progress going forward, I hope you guys will come back on and give us updates on where cyber is going forward.
54:23Love having you on the show. Thank you. A pleasure. Thank you, Chris. Thank you, Chris.
54:35All right. That is our show for this week. If you haven't checked out our ChangeLog newsletter, head to changelog.com slash news. There you'll find 29 reasons, yes, 29 reasons why you should subscribe. I'll tell you reason number 17, you might actually start looking forward to Mondays. Sounds like somebody's got a case of the Mondays. 28 more reasons are waiting for you at changelog.com slash news. thanks again to our partners at fly.io to break master cylinder for the beats and to you for listening that is all for now but we'll talk to you again next time
From the publisher
This week, Chris is joined by Gregory Richardson, Vice President and Global Advisory CISO at BlackBerry, and Ismael Valenzuela, Vice President of Threat Research & Intelligence at BlackBerry. They address how AI is changing the threat landscape, why human defenders remain a key part of our cyber defenses, and the explain the AI standoff between cyber threat actors and cyber defenders.
Changelog++ members save 10 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Fly.io – The home of Changelog.com — Deploy your apps close to your users — global Anycast load-balancing, zero-configuration private networking, hardware isolation, and instant WireGuard VPN connections. Push-button deployments that scale to thousands of instances. Check out the speedrun to get started in minutes.
- Notion – Notion is a place where any team can write, plan, organize, and rediscover the joy of play. It’s a workspace designed not just for making progress, but getting inspired. Notion is for everyone — whether you’re a Fortune 500 company or freelance designer, starting a new startup or a student juggling classes and clubs.
- Eight Sleep – Take your sleep and recovery to the next level. Go to eightsleep.com/PRACTICALAI and use the code PRACTICALAI to get $350 off your very own Pod 4 Ultra. You can try it for free for 30 days - but we’re confident you will not want to return it. Once you experience AI-optimized sleep, you’ll wonder how you ever slept without it. Currently shipping to: United States, Canada, United Kingdom, Europe, and Australia.
Featuring:
- Gregory Richardson – LinkedIn
- Ismael Valenzuela – GitHub, LinkedIn, X
- Chris Benson – Website, GitHub, LinkedIn, X
Show Notes:
Something missing or broken? PRs welcome!




