00:00:00.239 --> 00:00:01.199
Hello and welcome.
00:00:01.280 --> 00:00:07.440
My name is Diana Kelly and I am the CISO at NOMA Security and this is the Blast Radius Podcast.
00:00:07.679 --> 00:00:11.679
Joining me today is Scott Roberts, who is the CISO at UiPath.
00:00:12.000 --> 00:00:12.240
Welcome.
00:00:15.279 --> 00:00:17.839
You've had a really, really interesting career.
00:00:17.920 --> 00:00:25.760
It was really, I loved speaking to you before we even started rolling because we've been talking about what you've done at Microsoft with Blaster and MSRC.
00:00:26.320 --> 00:00:26.879
Amazing.
00:00:27.039 --> 00:00:29.440
And then you moved into a CISO role.
00:00:29.679 --> 00:00:32.799
You were Coinbase before you joined UiPath.
00:00:33.119 --> 00:00:35.439
So you seem to like the cutting edge of technology.
00:00:35.600 --> 00:00:36.880
Is that fair?
00:00:37.520 --> 00:00:39.119
I have followed along, yeah.
00:00:40.479 --> 00:00:41.359
The cutting edge.
00:00:41.439 --> 00:00:46.479
So Microsoft in the early 2000s, and the name of your podcast in a blast radius.
00:00:46.719 --> 00:00:48.159
It makes me think of the early works.
00:00:54.640 --> 00:00:55.840
That had a huge blast radius.
00:01:03.039 --> 00:01:06.640
And I joined that team right in the middle of the stage right vulnerability.
00:01:06.879 --> 00:01:06.959
Okay.
00:01:07.599 --> 00:01:09.280
A billion devices vulnerable.
00:01:09.760 --> 00:01:13.599
And so the blast radius has been quite large.
00:01:13.920 --> 00:01:19.519
As you mentioned, I went over to Coinbase Cloud, of the C Stop there, and ran all of the sticking infrastructure.
00:01:19.760 --> 00:01:25.840
So that was about 30% of the Ethereum sticking infrastructure in the world, about the same for Solana.
00:01:28.959 --> 00:01:30.400
It's a very large blast radius.
00:01:30.719 --> 00:01:31.840
Very large blast radius.
00:01:32.159 --> 00:01:34.799
And now I've been the UiPath C stuff for the last three years.
00:01:35.439 --> 00:01:35.760
Okay.
00:01:36.000 --> 00:01:43.760
Now, as you look at what UiPath does versus Coinbase, how has your thinking about the threat model changed?
00:01:44.239 --> 00:01:46.640
So in some ways it's uh it's very similar.
00:01:47.200 --> 00:01:59.120
Within Coinbase Cloud, we had our developer platform, we have an API that our developers would use, and and and in UiPath, we have a cloud stack platform product that our customers use and build on top of.
00:01:59.200 --> 00:02:02.000
But at UiPath we also have our on-premise product.
00:02:02.239 --> 00:02:06.719
And and so from a software stack point of view, there are some similarities with differences.
00:02:07.120 --> 00:02:11.360
But one of the biggest differences though is in the the attacker's intent.
00:02:11.520 --> 00:02:20.719
If you look at what a typical attacker would be uh looking after from a Coinbase perspective, you know, there's$39 billion of crypto under management.
00:02:20.879 --> 00:02:26.879
And so it's very clear generally what the attacker's intents are, and it's directed at direct to the money, yeah.
00:02:27.120 --> 00:02:38.639
Uh in the UiPath case, you know, we run uh the infrastructure for some of the largest and most heavily regulated customers in the world from uh finance, insurance, healthcare.
00:02:38.960 --> 00:02:43.199
So you look at the records that they have, the medical billing records, financial statements.
00:02:43.360 --> 00:02:51.680
So in many ways, uh uh we have more of a solar winds type of uh threat model than than we had at Coinbase.
00:02:51.759 --> 00:03:05.360
So looking at our supply chain, looking at uh at tactic attempts that might try to be very stealthy and not go after us directly, right, but use us as a conduit to get to uh our customers who are running our software in the heart of their critical enterprise.
00:03:05.680 --> 00:03:07.439
Yeah, it's a lot of responsibility.
00:03:07.759 --> 00:03:09.360
It is a lot of responsibility.
00:03:09.520 --> 00:03:12.000
And UI Path has a very large platform.
00:03:12.159 --> 00:03:16.400
So we have we have dozens of products that customers then build on top of.
00:03:16.560 --> 00:03:27.520
And so one of the other big differences from a threat modeling point of view or protection point of view is that Coinbase, we provided the security around the environment, protecting the assets.
00:03:27.599 --> 00:03:27.759
Right.
00:03:28.000 --> 00:03:43.759
Um but since we're a development platform that customers use in their own environments or in our multi-tenant SaaS environment, we actually have to expose those security controls and security features as part of the product so that they could incorporate those hard rails into their workflows.
00:03:43.919 --> 00:03:58.960
And so, for example, that is one of the areas that we work together with in NOMA, where we actually provide the AI security controls as part of an genetic orchestration capability to our customers so they can build those security capabilities in our shared responsibility model.
00:03:59.280 --> 00:04:02.000
I was gonna say this is really very much along the lines of good.
00:04:02.080 --> 00:04:16.639
We both worked at Microsoft, which is very well known for helping people understand the shared responsibility model of cloud and customers enhancing their own guardrails with the built-in tools, and it sounds like you've got a lot of that at UiPath too.
00:04:16.879 --> 00:04:17.920
Yeah, absolutely, absolutely.
00:04:18.319 --> 00:04:32.000
Customers will use our orchestration platform to build complex business processes, uh, and it's a combination of our traditional software robots from the RPA uh world now to our gentic agents, to humans in the loop.
00:04:32.160 --> 00:04:39.279
And so we have the capability of doing the best and breed in all of those areas and incorporating the security guardrails as part of that story.
00:04:39.600 --> 00:04:40.639
Yeah, giving the choice.
00:04:40.879 --> 00:04:42.879
Okay, so uh tell me if this is true.
00:04:42.959 --> 00:04:46.639
I heard that you've stopped doing penetration testing at UiPath.
00:04:46.879 --> 00:04:47.600
Is that the case?
00:04:47.680 --> 00:04:48.480
Or no.
00:04:48.639 --> 00:04:49.920
Okay, that is not the case.
00:04:50.079 --> 00:04:50.319
Okay.
00:04:50.480 --> 00:05:05.439
Uh what what you're referring to is I I've had a kind of a uh uh an interesting opinion about the the compliance-based annual pen tests that we get asked to do, that everyone in the software industry gets asked to do.
00:05:05.519 --> 00:05:05.759
Yeah.
00:05:06.000 --> 00:05:12.000
And and I refer to many of those uh type of compliance-driven uh security mandates as security theater.
00:05:12.480 --> 00:05:26.160
It provides the the appearance of security without actually providing security because those annual external pen tests are producing a certificate for a product that no longer exists at the moment those tests are complete.
00:05:26.319 --> 00:05:26.560
Yeah.
00:05:26.800 --> 00:05:30.079
You know, we've had over 500 releases in the last year.
00:05:30.240 --> 00:05:33.040
We're shipping uh daily, hourly, a cloud.
00:05:33.360 --> 00:05:37.519
Multiple times a day uh product suites in the cloud, on premise.
00:05:37.680 --> 00:05:41.759
And so we really needed to move to a model of continuous uh testing.
00:05:41.839 --> 00:05:51.360
So we've had in a you know an effective security, a red team internally, uh, but we moved the external uh pen testing to that also a continuous capability as well.
00:05:51.680 --> 00:05:57.519
So it's not no pen tests, it's just what's the point of one a year, it's not gonna give us anything we need to look at it all the time.
00:05:57.839 --> 00:05:58.319
Exactly.
00:05:58.560 --> 00:06:01.360
And and you see the industry moving towards this as well.
00:06:01.519 --> 00:06:10.959
Um if you look at the AIUC-1 security standard, you know, it actually mandates quarterly red teaming uh of your AI agents.
00:06:11.040 --> 00:06:17.360
And we were um very happy and very lucky to be you know co-founders of AIUC certification.
00:06:17.519 --> 00:06:23.199
And so it really plays into the strengths of that certification that you're doing continuous pen testing.
00:06:23.279 --> 00:06:33.360
And that's also an area where we were working as development partners with NOMA to be able to leverage your platform to do continuous pen testing of our identic agents.
00:06:33.759 --> 00:06:40.000
So you you touched on AIUC1, which is something that you know we're both passionate about, we're both on the advisory there.
00:06:40.079 --> 00:06:49.279
I was wondering if you could explain a little bit more about what AIUC1 is and why you decided to spend some of your very precious time helping to advance that.
00:06:49.759 --> 00:06:50.720
Absolutely.
00:06:51.040 --> 00:07:13.040
When we look at the certifications that are out there, if you will, um you know there is the what's called ISO 42001, which is a AI management system certification, and it really uh helped customers uh understand how we build our identic environment, how we build our agents, how we do our model training, handle the customer data.
00:07:13.199 --> 00:07:13.360
Yeah.
00:07:13.839 --> 00:07:16.399
Think of that as a build-time uh certification.
00:07:16.560 --> 00:07:23.120
There was really nothing that was looking at it from a runtime, from as we're operating it continuously, how do we know it's safe and secure?
00:07:23.279 --> 00:07:28.079
Yeah, and you like like um you know many companies are hearing from customers.
00:07:28.240 --> 00:07:30.319
How do I know that these agents are trustworthy?
00:07:30.480 --> 00:07:32.240
How do I know they're safe and secure?
00:07:32.399 --> 00:07:37.680
How do I know they're not going to hallucinate uh in my business uh process, uh, for example?
00:07:39.920 --> 00:07:40.560
Exactly.
00:07:40.720 --> 00:07:47.759
Uh and so there was really nothing in the marketplace that was helping to answer that question at a large scale and in a way that customers could trust.
00:07:48.000 --> 00:08:00.800
And and that was what so so what was so exciting about the AIUC effort is that it provides uh really uh offensive train uh testing against your agentic agents, and not just once a year.
00:08:00.879 --> 00:08:06.560
You know, working with you and and the consortium, we're constantly updating the certification for the latest threats.
00:08:07.040 --> 00:08:26.560
So for example, you know, or we're going through uh an update now around multi-agent scenarios and and throwing those adversarial prompts, thousands of them, at your agents, measuring how they respond, and then improving that baseline over time, um, I believe gives our customers a real uh strong sense of security of our GENTEC platform.
00:08:26.879 --> 00:08:27.199
Yep.
00:08:27.439 --> 00:08:28.000
Yes.
00:08:28.560 --> 00:08:38.240
So inside business orchestration and automation, uh UiPath enables AI agents to act autonomously across a customer's applications and systems.
00:08:38.639 --> 00:08:41.519
Um how do you define and enforce those trust boundaries?
00:08:41.679 --> 00:08:52.000
Because that's and I know you talked a little bit about you gave them, you exposed some of the guardrails, but can you give me a sense of what that really looks like, you know, from the customer side and and why you made the choices you did?
00:08:52.559 --> 00:08:52.879
Sure.
00:08:52.960 --> 00:09:06.159
Um as I mentioned earlier, you know, our platform as a combination of of traditional uh process automation with software, our software robots, our agentic agents, and humans in the loop where needed, and and and and looking at the best of breed of those.
00:09:06.480 --> 00:09:13.440
But for agentic agents uh specifically, there's two key buckets of security guardrails that are very important.
00:09:13.600 --> 00:09:15.039
The first one is identity.
00:09:15.200 --> 00:09:32.639
You know, there's other folks that have said, you know, identity is the new firewall, uh, uh identity is the new perimeter, and and absolutely believe that in the agent context of uh that every uh one of your agents you know has uh not a shared identity, you know, a very specific provisioned identity with a set of permissions that are granted.
00:09:32.879 --> 00:09:35.200
And those permissions should be very bounded.
00:09:35.360 --> 00:09:42.159
In a customer workflow, uh, for example, you might have an agentic agent that uh processes customer invoices.
00:09:42.879 --> 00:09:50.080
So it should have permission to read invoices, for example, but should it have permission to read invoices uh across every system that customer has?
00:09:50.399 --> 00:09:57.919
Or or a specific system for a specific period of time, even so it should be time bound and and then uh then renewed.
00:09:58.320 --> 00:10:02.240
So think of that again as kind of the build time or the configuration of the agent guardrail.
00:10:02.559 --> 00:10:09.679
But then at enduring operation, while that agent is behaving, we want to make sure uh that it is also hardened.
00:10:10.000 --> 00:10:20.559
And we want to make sure that, for example, things like prompt injection, uh data extraction, you know, they in the operating of those agents, we want to make sure that they're operating in a safe and secure way.
00:10:20.960 --> 00:10:38.480
And you know, this is another area where we're partnered with NOMA on where customers can can use NOMA's capability during a workflow and have it evaluate the prompt for prompt injection, uh, jailbreak attacks, data extraction, data poisoning, um, all of the common vectors uh that we might see.
00:10:38.559 --> 00:10:42.720
So so when I think about guardrails around our agent platform, those are the two big buckets.
00:10:42.960 --> 00:10:43.120
Okay.
00:10:43.360 --> 00:10:49.759
Um and then kind of the third one that that uh is important is making sure that you know, as we as we say, log all the things.
00:10:50.000 --> 00:10:50.240
Right.
00:10:50.480 --> 00:10:50.639
Right?
00:10:50.879 --> 00:11:05.039
So what was the prompt, uh, what was the evaluation, what was the thinking, what was the output, and you feed all of that uh into your tracking systems or your sim systems uh for later forensic capabilities so you can actually be able to reverse engineer what happened after the fact.
00:11:06.320 --> 00:11:22.320
Within UiPath with the customers, when you anytime you have a shared responsibility model where the customers can make some choices, even when you give them guidance, even when you give them tools, both your own and you know others from third parties like NOMA, sometimes they don't make good choice.
00:11:22.559 --> 00:11:24.879
How do you help them make good choices in that case?
00:11:25.039 --> 00:11:33.039
And and what happens if you see them maybe not getting in and putting enough guardrails and enough controls around the agen take actions?
00:11:33.759 --> 00:11:40.720
The the the first category of things that we want to do is to make sure that the safe thing is the easy thing for customers to do.
00:11:41.120 --> 00:11:49.919
There are platforms that are out there that you almost have to have a PhD uh in configuration management in order to figure out how to make it safe and secure.
00:11:50.320 --> 00:12:00.639
And so, you know, similar to you know SFI from Microsoft and make safe by default, safe by operation, um, you know, we have a similar philosophy uh in terms of our controls.
00:12:00.720 --> 00:12:03.840
And so, you know, we generally have the least privileged uh default.
00:12:04.000 --> 00:12:11.679
Customers have to take very specific actions to uh allow the workflows to have access to um particular data uh in the environment.
00:12:11.840 --> 00:12:17.519
But as you say, they you know they're they're uh you know they're humans like everyone else, they make mistakes, they leak keys.
00:12:18.240 --> 00:12:29.759
And so uh just like the the hyperscalers, you know, monitor what happens inside of their environments and within virtual machines, and uh we also operate uh uh uh monitoring in in our customer environments.
00:12:29.919 --> 00:12:39.919
So all of a sudden, you know, if all of us uh you have a customer environment where their billing in now has just jumped by 10x and the utilization is off the chart, there are patterns in practice as well.
00:12:40.240 --> 00:12:44.879
It looks like you might have you know exposed yourself to uh crypto miner uh inside of your environment.
00:12:45.279 --> 00:12:46.480
Should know very well from Coinbase.
00:12:46.799 --> 00:12:50.000
Because we know very well from Coinbase and some time at AWS.
00:12:50.080 --> 00:12:56.960
Uh of all of a sudden the customer went from the smallest instance type to the you know the 32 CPU instance type, 100% CP utilization.
00:12:57.279 --> 00:12:58.399
Data center's very hot.
00:12:59.360 --> 00:13:00.639
Probably some bad things happened there.
00:13:00.879 --> 00:13:04.399
And we should call the customer and talk to them and understand uh what just happened in their environment.
00:13:04.639 --> 00:13:07.120
So we have those kind of uh controls as well.
00:13:07.279 --> 00:13:10.720
Uh but you know, this is you know classical sort of multi-tenant architecture.
00:13:10.799 --> 00:13:22.799
You know, we we we do make sure that that even in those scenarios where you know some things have gone sideways, so we say, within the customer environment, that that is completely isolated into that particular customer's environment.
00:13:23.039 --> 00:13:25.840
It doesn't touch any other customer environment or control plane.
00:13:25.919 --> 00:13:27.759
We try to be abstracted from all of those things.
00:13:28.240 --> 00:13:28.879
That makes sense.
00:13:29.519 --> 00:13:36.639
And as you've seen more agentic use by your customers, how has your office at the CISO changed?
00:13:36.720 --> 00:13:45.440
Have you had to hire, have you had to get new uh expertise in, and have you noticed similar changes with any of your customers or different changes?
00:13:46.799 --> 00:13:51.519
Well, security has always been a you know a substrate of the UiPath offering.
00:13:52.000 --> 00:14:01.919
We are the trusted enterprise partner and we have all of the certifications that our most you know critical customers want for their environments from Lima to Hitrust to FedRamp.
00:14:02.480 --> 00:14:04.799
So it's always been an important part of the substrate.
00:14:05.120 --> 00:14:16.639
But as as we said earlier, uh in the agentic world where things may be more non-deterministic, our customers wanted to understand how we can actually uh take advantage of this in a safe and secure way.
00:14:16.879 --> 00:14:17.039
Right.
00:14:17.279 --> 00:14:31.519
And so you know having that very um um uh easy-to-use platform with very good guardrails and be able to walk customers through exactly here is is how uh to it to develop the platform in a way that is safe and secure.
00:14:31.759 --> 00:14:35.600
And and here is maybe what your threshold is where you need to get a human in the loop.
00:14:35.840 --> 00:14:49.840
So, like for example, if you're building a refund process, maybe you have guardrails around up to a certain dollar amount that the agentic agent could automatically approve in terms of the refund, but over at a larger amount, maybe you need to get the humans in the loop.
00:14:50.000 --> 00:14:50.159
Yeah.
00:14:50.480 --> 00:14:52.879
And and you can uh build those into your workflows.
00:14:53.440 --> 00:14:56.399
And have you had to add people to your team?
00:14:56.480 --> 00:15:02.960
Does if you look at the office of the CISO two years ago before the agentic explosion, because you've been in enroll for three years, right?
00:15:03.039 --> 00:15:03.200
Yes.
00:15:03.600 --> 00:15:06.159
Have you had to expand the office?
00:15:06.320 --> 00:15:08.080
Have you had to hire new skill sets?
00:15:08.240 --> 00:15:09.519
What does that look like for you?
00:15:10.000 --> 00:15:13.120
So uh you know, I would try this again.
00:15:13.840 --> 00:15:20.720
Okay, yeah, no, and I I don't mean to be, I'm just sort of a lot of people are the reason I'm asking this is a lot of people are saying, do I need to hire?
00:15:20.879 --> 00:15:22.240
What kind of person do I need to hire?
00:15:22.399 --> 00:15:37.279
So since you've got a you've got a mature office that's been kind of ahead of everybody in agentech, I think they might really learn from did you have I'm not trying to say like you don't have enough people or whatever, but just really as you look at the that sort of the head count, like because this is something people are struggling with.
00:15:37.440 --> 00:15:38.240
Should I hire more?
00:15:38.320 --> 00:15:39.519
What kind of people should I hire?
00:15:39.679 --> 00:15:40.320
What should it look like?
00:15:40.480 --> 00:15:45.279
So you could even abstract it out to recommendations, but that was and you don't have to answer it if you're not confident.
00:15:45.600 --> 00:15:46.480
No, no, no, it's fine, it's fine.
00:15:46.559 --> 00:15:46.639
Okay.
00:15:46.799 --> 00:15:47.519
But that's what I'm saying.
00:15:48.000 --> 00:15:48.879
That's what I was asking.
00:15:49.440 --> 00:15:49.600
Yeah.
00:15:50.240 --> 00:15:52.240
Okay, we're gonna I'm gonna kick off the answer here.
00:15:52.639 --> 00:15:52.960
Okay.
00:15:56.159 --> 00:16:04.480
As I've looked at evolving my team over the last three years, the you know, the number of customers that want to have deep dive conversations uh around security has increased.
00:16:04.879 --> 00:16:08.960
And and I think that's very natural and it's and and I think it's very expected.
00:16:09.440 --> 00:16:12.799
And we have done kind of two key things in my organization.
00:16:13.200 --> 00:16:19.600
One is that we've really focused on uh the enablement of our of our sales and our our field organizations.
00:16:19.840 --> 00:16:20.240
Oh, okay.
00:16:20.559 --> 00:16:29.840
So from from training, from material, from collateral, uh, we've issued a very detailed security white paper uh that answers kind of everything a security team is gonna want to know.
00:16:30.159 --> 00:16:31.679
You're living build security in.
00:16:32.000 --> 00:16:33.279
We're trying to, we're trying to.
00:16:33.519 --> 00:16:33.600
Yeah.
00:16:33.840 --> 00:16:38.559
And and create those scalable um sort of mechanisms for customers to even self-service.
00:16:38.879 --> 00:16:46.960
So we have a trust portal that we put online, customers can come and grab all of this information, there's uh agentic chatbots that they can ask questions to.
00:16:47.200 --> 00:16:47.360
Okay.
00:16:47.519 --> 00:16:52.480
Uh but then we've also built out our human uh field-facing organization as well.
00:16:52.559 --> 00:17:03.200
So we've stood up our field CISO organizations here and internationally so that we can then interface uh directly with security teams that that need uh that direct sort of uh uh hands-on.
00:17:03.919 --> 00:17:04.559
That partnership.
00:17:04.799 --> 00:17:06.400
So yeah, you're you're partnering with them.
00:17:06.480 --> 00:17:12.880
Here's a field CISO that can help you and your team to do this in a way that will be most effective and appropriate for your company.
00:17:13.119 --> 00:17:13.359
Exactly.
00:17:13.519 --> 00:17:13.680
Okay.
00:17:13.839 --> 00:17:23.119
But it was very important for me for that field CISO organization, though, to report up to the security team so that we are uh a check and balance, if you will, to our go-to-market organization.
00:17:23.599 --> 00:17:24.400
All right, I love that.
00:17:24.480 --> 00:17:30.079
So, yeah, making sure everybody is staying on the same the same path, the same security path.
00:17:30.319 --> 00:17:32.559
Um incident response.
00:17:32.880 --> 00:17:34.960
This is something that we get a lot of questions about.
00:17:35.039 --> 00:17:39.039
You know, how has incident response changed in the era of agentic?
00:17:39.440 --> 00:17:45.839
And there's a lot of recommendations to go back and make sure that your incident response plan is ready for the agentic era.
00:17:46.240 --> 00:17:48.720
What does that really look like in practice?
00:17:49.839 --> 00:17:50.960
That's a great question.
00:17:51.279 --> 00:17:56.000
You know, I think there's a time dilation effect that is occurring uh in the marketplace.
00:17:56.240 --> 00:18:00.720
Back at Microsoft, uh, you know, we used to joke it was patch Tuesday and exploit Wednesday.
00:18:01.119 --> 00:18:02.000
Yes, I remember that.
00:18:02.400 --> 00:18:06.799
And we saw very quick acceleration uh of uh exploitation.
00:18:07.039 --> 00:18:16.000
And now you're but you're now you're seeing that even with zero-day discoveries from autonomous uh uh uh agents that are finding vulnerabilities and then immediately exploited them.
00:18:16.160 --> 00:18:21.839
So that that time dilation has even gotten um you know uh even quicker uh than years past.
00:18:22.079 --> 00:18:31.759
And you know, in our work with AIUC Together, yeah, you you know, we also did recently uh issue a white paper uh in terms of the three things that uh you know CISO needs to be looking at.
00:18:31.920 --> 00:18:33.920
And number three was defend at machine speed.
00:18:34.079 --> 00:18:34.160
Yeah.
00:18:34.640 --> 00:18:37.119
Defend at the speed of AI in that.
00:18:37.359 --> 00:18:54.720
And we've taken that uh to heart inside of UiPath because we have looked at all of the agentic sock solutions uh that are out there, and and the failure pattern that I was seeing was a quicker triage to get an alert to a human for the human to go respond to it.
00:18:54.880 --> 00:18:58.160
And we've built those automations on top of the UiPath platform.
00:18:58.400 --> 00:19:05.519
Uh we've saved in uh you know thousands of hours in our agentic sock capabilities and we provided those tools available to customers.
00:19:05.599 --> 00:19:05.759
Yeah.
00:19:06.000 --> 00:19:08.240
But for me, that was just that was just the first step.
00:19:08.319 --> 00:19:08.480
Yeah.
00:19:08.640 --> 00:19:21.279
Um where instead of taking four hours to triage you know some alert that's gone off, we can now do it in 90 seconds with a full forensic understanding of the logs uh that have occurred on top of our platform.
00:19:22.000 --> 00:19:27.759
Um but then uh that it that still requires uh if you stop there, then a human to respond.
00:19:28.079 --> 00:19:42.160
And so taking it to the next step, um, as we've seen with the recent uh uh attacks from OpenAI and Hugging Face uh incident, you know, you know, Hugging Face was breached on uh in one second in terms of a particular vice.
00:19:42.480 --> 00:19:43.039
Machine speed, yeah.
00:19:43.359 --> 00:19:43.759
Machine speed.
00:19:43.920 --> 00:19:44.079
Yeah.
00:19:44.319 --> 00:19:50.559
And so uh you know, being able to quickly triage something and get it to a human is no longer gonna be sufficient.
00:19:50.799 --> 00:19:57.519
We are actually gonna have to take the next step and enable limited autonomous uh response and defense uh as well.
00:19:57.759 --> 00:20:01.599
So if you start to see something happening, then we have to be able to respond.
00:20:01.759 --> 00:20:11.839
And a lot of the the agents and the tools that are out there, for example, in uh the Kubernetes environment, Linux environments, are operating on EBPF read-only uh sensors.
00:20:12.240 --> 00:20:14.400
And and that's now insufficient.
00:20:14.640 --> 00:20:26.079
And because we need to be able to have um endpoint controls that can take corrective actions, that can terminate processes, that can stop lateral movement, yeah, and um and define the guardrails around that.
00:20:26.160 --> 00:20:28.960
So that's where our we're heavily investing in terms of our next step.
00:20:29.359 --> 00:20:33.039
Yeah, yeah, the green, the green teaming, the response, the reaction.
00:20:33.279 --> 00:20:33.440
Yeah.
00:20:33.759 --> 00:20:48.000
Yeah, you had mentioned the three things from AIUC, and I was wondering over though, if you were speaking to, if I come to you and I say, I'm a CISO, we're about to deploy agentic solutions for a variety of mission critical use cases, what should I be thinking about?
00:20:48.079 --> 00:20:49.839
What are the first three things I should be thinking about?
00:20:50.000 --> 00:20:53.759
Would it be the AIUC 1-3, or would you have your own twist on it?
00:20:53.839 --> 00:20:54.720
What would you think?
00:20:54.880 --> 00:21:10.079
Well, specifically in you know, in a scenario where you're looking at deploying a new agentic solution, I I would go back to some of the earlier points that we made around you know identity management for the agents, uh contextual awareness and filtering for what's going into the agents.
00:21:10.160 --> 00:21:14.000
You know, you really want to build a great sandbox uh around that agent environment.
00:21:14.400 --> 00:21:27.200
And then as we've seen again in the open AI attacks, you know, uh extreme monitoring around that environment would be something that we everyone probably needs to go back and take another look at in light of the recent uh discoveries.
00:21:27.759 --> 00:21:28.799
Yes, yeah.
00:21:29.279 --> 00:21:44.400
Okay, and the the last question is is there a metric that you used to find helpful as a CISO, but now that we've entered the agentic era for real, that that's not the right metric, and what metrics are you focusing on instead?
00:21:45.279 --> 00:22:03.119
The the the canonical metrics that it that if you go back and look at what CSO is reporting to boards you know five years ago, you know, it might have been uh the number of vulnerabilities that we have discovered, the number of vulnerabilities that we've patched, and how many vulnerabilities are not patched and you're you're burning them down and and and and those kind of things.
00:22:03.440 --> 00:22:03.920
We lived by that.
00:22:04.319 --> 00:22:05.279
We've lived by that, right?
00:22:05.839 --> 00:22:19.519
Um you know, or another a good one would be you know the NIST CSF maturity uh scale and where you're at on that, and we're gonna move from a 3.1 to a 3.5 this year, and um and those are those are all now uh kind of table stakes.
00:22:19.599 --> 00:22:27.680
Like it for me it's yes, we're doing all of those things, but uh when I when I work with my board, they want to understand the business impact of these things.
00:22:27.839 --> 00:22:36.400
So translating um those sort of geeky metrics into actual uh impact to the business uh is what I really want to focus on.
00:22:36.559 --> 00:22:42.880
So when we have um a security event, you know, um what was the the business impact of that?
00:22:42.960 --> 00:22:56.160
You know, how long were we down for, what was our business continuity, um, you know, our recovery, our mean time to recovery, uh for example, those kind of metrics um are much more useful, uh I think to the to the board.
00:22:56.640 --> 00:23:15.039
Personally, one of the things that I've uh uh also added to my my own board deck uh would be the things that our external security researchers uh reported to us through our bug bounty program that I legitimately feel my team should have caught.
00:23:15.440 --> 00:23:15.759
Okay.
00:23:16.079 --> 00:23:25.839
This is where I want to hold myself sort of vocally self-critical, where I have an offensive security team, we looked at that component, we looked at that code, and we didn't see it.
00:23:26.079 --> 00:23:44.319
And and an external uh researcher in partnership with us reported that, we addressed the issue, and so we do a full retrospective on all of those, and I report that out to the board of yeah, this this quarter, you know, you're here's how many issues that that I feel like we should have been able to catch, and we did not.
00:23:44.480 --> 00:23:46.880
Uh and then what are we doing about that for next time?
00:23:47.119 --> 00:23:47.519
I love that.
00:23:47.599 --> 00:23:57.119
So you sort of do an after-action report on an external finding and then go back and optimize so that hopefully you'll find it again next time or something.
00:23:57.519 --> 00:23:57.759
Exactly.
00:23:57.920 --> 00:23:58.160
So yeah.
00:23:58.400 --> 00:24:03.200
And sometimes it's education, sometimes it's uh control, sometimes it's observability.
00:24:03.599 --> 00:24:07.200
Uh and so it's it's really helped to kind of raise our game on a continuum basis.
00:24:07.519 --> 00:24:09.119
Wow, constant optimization.
00:24:09.359 --> 00:24:11.759
That's that's the that's the that's the learning loop, hopefully.
00:24:12.000 --> 00:24:12.480
That's it, yeah.
00:24:12.559 --> 00:24:13.279
Oh, love it.
00:24:13.519 --> 00:24:15.519
Thank you so much, Scott, for sitting down with me.
00:24:15.599 --> 00:24:16.799
I've really I've learned a lot.
00:24:16.880 --> 00:24:19.440
This has been a fantastic conversation, so thank you so much.
00:24:19.680 --> 00:24:20.960
Well, thank you for the opportunity.
00:24:21.039 --> 00:24:26.880
Uh I appreciate the the chance to come and chat with you and talk about you know the blast radius of uh our our data line.
00:24:27.920 --> 00:24:32.559
All right, thank you, and thank you everybody for joining us on this episode of the Blast Radio.