Navigating the Future of Cybersecurity: Insights from Industry Leaders at AIE 2024
Transcript
Hello, everybody. My name is Doug Levin. I'm an executive fellow at the Harvard Business School, and I sit on the board of directors of a number of different companies, one of which, uh, the CEO is here, uh, on the panel.
And, uh, that's Reversing Labs. And I'm also an advisor to many other companies, one of which is here, which is, uh, ec. But we'll go into the details of our panelists in just a second.
I just want to give you an overview of, uh, the panel that we have, uh, assembled today, and the, um, and the subject matter. Uh, today, everybody knows that cybersecurity is a leading topic that boards of directors have, uh, uh, concentrate on and, um, address as well as operating companies, um, you know, dedicate many, many resources to in the enterprise. Uh, the, uh, the attacks have been numerous, uh, daily and, uh, challenging and they become ever so challenging as a result of the advancement of technology, the use of open source and the use of, uh, artificial intelligence that we'll refer to on this panel.
As ai, it's important to note that, uh, the attack vectors have changed over the years, and of course, they've gotten, uh, they've gotten larger. The number of attack ventures have expanded, but also the complexity of these attack vectors have, um, have also expanded. Today.
We've assembled a panel of guys who have been in the industry, um, for a, a long time, and they will give you some background on themselves. But first, um, uh, let me, uh, introduce them. Um, Mario Volson is the CEO and founder, co-founder of Reversing Labs.
He's based in Boston. Mario, say hello. Hello, Doug.
Uh, looking forward to our conversation. And secondly, uh, uh, we have Tal, uh, yif, who is, uh, based in Israel, uh, however, he's a world traveler, and, uh, he is the, uh, co-founder and CEO of, uh, uh, reset. And, um, how you doing, man?
Great to see you guys. Thank you so much, uh, for your time. Okay.
So what I'd like you, what I'd like each of you to do is spend one or two minutes just providing us with a little bit of background and then, uh, a little bit of more information about how your company addresses Attack Vectors. Mario, please go ahead. Thanks.
T um, everyone, um, Mario Von, uh, CEO and Co-founder at, uh, reversing Labs, a company that I've been now leading for about 15 years. Uh, a company that have started, you know, after, uh, a good, you know, four year stint, you know, at a company named Bit nine, which eventually grew, uh, uh, to be a, a carbon black. Uh, and, you know, some of you know it as, you know, one of the products of, uh, VMware, uh, today.
Uh, why is that sort of, you know, important? You know, uh, you know, from my, uh, trajectory is that, you know, I've been focusing, you know, on, um, uh, software resilience, uh, cyber protection, uh, in, uh, organizations for now. What is it?
You know, you know, almost, you know, uh, 20 years, uh, and, uh, uh, I have been, uh, very much, you know, focused, you know, on understanding, uh, the limits, you know, to which, you know, the cyber securities, uh, cybersecurity solutions, uh, uh, can, you know, push, uh, uh, uh, uh, different strategies, um, for all of you, uh, it shouldn't be a big, you know, uh, surprise that, you know, the, uh, cybersecurity, uh, is not a science, uh, is not a silver bullet. It's actually a practice. It's something that we continually need to work on, get better, learn from what's happening, uh, in the world, uh, uh, learn from, you know, other human beings, you know, are, uh, using to exploit our systems, to take advantage of our, uh, environments and try to do, uh, better At traversing labs.
You know, we have, you know, decided, you know, that the, uh, so-called payloads, you know, or, uh, uh, binary, uh, um, elements, uh, that could be, uh, ranging anything, you know, from executable files to documents, uh, to configuration files, you know, all the way to actually AI models, uh, uh, uh, could be, uh, vectors, uh, for, uh, infection or could be things, you know, that could bring down, uh, entire, uh, cyber infrastructure, uh, down. So, as we were building, uh, reversing labs, you know, we, um, uh, built, uh, extremely deep, you know, understanding of, you know, uh, different, you know, binary, uh, frameworks from a perspective of, you know, looking, you know, for, uh, unwanted, you know, implants, payloads, uh, understanding anomalous behaviors, uh, all the way to looking, you know, for, um, uh, evidence, you know, of, you know, open source, you know, or, uh, third party, uh, software supply chain, uh, malfeasance. So, uh, over years, you know, we've certainly, uh, seen, uh, tremendous amount of, uh, scrutiny patients, especially by very advanced, you know, actors, uh, to exploit, uh, vectors, you know, that, you know, would give them, you know, very, very broad, uh, access, uh, to, uh, our, uh, governmental institutions, uh, to our, uh, corporations.
And many of you, uh, will, you know, remember, uh, what happened four years with, you know, SolarWinds and subsequent, uh, uh, uh, noise, you know, around, you know, uh, colonial pipeline attacks, and similar, uh, where, uh, broad, you know, software supply chain attacks, uh, are, you know, capable of, uh, uh, damaging, uh, uh, uh, public, uh, trust, you know, into, uh, uh, our form of government. Perfect. Tal, how about, uh, a little bit about your background?
Sure. So, I've been the CEO of ec, uh, for the past, uh, six years. EC is a cyber company providing complete prevention of malware threats at the organization's gateway, which means between the threat and the organization, we provide complete prevention of known threats, as well as unknown threats.
So, zero days are fully covered, and what's very unique about us is that we're able to get to this level of security while maintaining full usability at the organization's level. I joined EC in a very unique hat. Uh, I actually am a partner at Pico Venture Partners, an early stage venture fund out of Israel.
Uh, Pico was, uh, the seed investor in ec, and I stepped into the CEO hat, uh, from, uh, the investor side. So coming in from Pico, which is more of a private equity play than traditional vc, uh, but very much part of Pico's DNA. What drew me to reset, and, and this is with perspective of sitting on multiple cyber company boards, was really in listening to the customer and understanding a couple of things.
One, that detection solutions are simply not enough. And again, and again, what we hear is prevention. How can we really prevent, but with it, the limitation and understanding that when you're trying to use prevention technologies, you will have negative impact on the organization's usability.
And here enablement was a massive issue. And, and what I've learned in, uh, Mary and Doug, I'd love to hear your perspective on this later on, but what I've learned more than anything is that usability and enablement bother the chief information security officer, at least equally as security does, for obvious reasons. They have to maintain the business.
And, uh, that is the number one concern for the organization, organization. Um, so that's a little bit about me and, uh, and, and my background. But again, what drew me to Ack is the ability to balance between the, the two, security with usability, not one or the other.
And I think, uh, that has been extremely relevant, uh, to where the market has trended towards in the last couple of years. Um, Mario, spend a a moment on, uh, an attack vector that you're familiar with, and, uh, give us an example of it, perhaps, and how would, uh, and how perhaps, uh, technology has resolved it. Um, so I have, you know, moment ago I mentioned, uh, a subject that's really, you know, close to my heart, and that's sort of, uh, ident understanding, identifying, so-called, you know, software, uh, uh, uh, supply chain, uh, uh, attacks.
Um, it's, it's interesting because it sort of, you know, falls in those, you know, high-end, extremely lucrative, you know, attack vectors, you know, that, you know, we are all very much, you know, worried, you know, uh, uh, about today. Of course, there are a lot of other, uh, uh, attacks. Uh, we're gonna talk about, you know, AI in a bit, you know, and how AI can sort of, uh, accelerate, uh, the efforts, you know, of, uh, those with a fewer, uh, resources like different crime gangs, you know, uh, uh, especially those based, you know, out Russia.
Uh, but you know, when it comes to software supply chain, uh, uh, today, uh, we've seen, uh, uh, a steady, uh, interest, you know, and focus, uh, by, uh, uh, nation state actors, uh, uh, solarin, you know, by, um, uh, by, uh, uh, uh, Russian nation state actors, xxi by likely, uh, you know, uh, Chinese, you know, nation state actors still, uh, undefined. Uh, and then suddenly we have seen, uh, uh, uh, north Korean state actors, you know, focusing on a lot of, you know, open source, you know, implants, uh, hoping to get a very broad access, uh, into, uh, FinTech, you know, uh, industry. Now, uh, why is that super interesting for me is that, you know, these attacks are very, very difficult to identify track, you know, monitor when successful.
They're extremely, extremely powerful, more powerful than, you know, what you've seen with the traditional, uh, a PT or adv, advanced persistent attacks from, uh, about 10 years ago. I'm sure all of you, uh, have read, you know, those, uh, a PT one and other reports, you know, that, uh, Kevin mania, uh, uh, um, has brought, you know, forward and that, you know, were covered, you know, broadly by, uh, New York Times, wall Street Journal, Forbes, you know, and, and then, then the other, uh, publications. Um, in both cases, uh, uh, we are dealing with, you know, other, sorry, that is persistent, that is not, you know, you know, going to give up.
It's not heist. It's not like, you know, uh, let's, you know, get some, uh, uh, outcome, uh, and, you know, disappear. Uh, but, you know, rather, you know, let's continually, uh, provide, uh, uh, access or, uh, pin, you know, our, uh, advantage, you know, against the adversary for a long time to come.
And when we are talking with such strategies, we are so far away from sort of, you know, the cyber crime from early days, you know, where it was in a nuisance, uh, annoyance or potentially, uh, uh, you know, the, the, the financial, uh, again, now we are talking about something that could at any time destroy, uh, uh, I mentioned earlier our way of life. You know, if you know any of the critical, uh, organizations cannot make what they're, you know, what they're doing. If we lose, you know, access, you know, to medicine, to, to food, to energy supplies, and these are not, you know, some, uh, uh, uh, lofty, uh, uh, uh, uh, threats, you know, they have certainly, uh, lots of, you know, uh, actual, uh, examples, you know, out there today.
Um, if that's what we need to worry about, you know, then we really need to, uh, uh, figure out and what are those, you know, long game strategies that we, uh, should be focused on. That was a thorough an, uh, answer. Um, tal if you could, uh, give us some examples of, uh, the attack vectors that reset addresses.
Uh, you set out the hub, so you see a lot of email, for example, which is the, uh, the means by which, uh, phishing attacks and malware come into many companies. Can you give us a perspective on, uh, that attack vector? Sure.
And, and I think something fascinating that, that Mario said early on, the amount of attack types are, are simply endless. Um, and the truth is that all of them are a big concern to the organization and not necessarily by size. Um, many of our customers at ec, uh, often we're surprised to hear that a relatively simple attack is what concerns them the most, simply because of the volume that they have to, uh, watch over.
And you, uh, Doug, you, you referred to phishing attacks, uh, and that's exactly that. So, phishing attacks very often, not overly sophisticated, and the damage may be smaller in most cases than than others, but are massive concerns simply because of how simple they are to, uh, to go after, in terms of the attacker, um, going after the organization, and how simple it is to bypass existing solutions or the end user who simply makes a very, uh, innocent mistake in clicking the wrong link. So, one, I would say more than anything, uh, an organization today has to be worried about almost everything, uh, and to give different weight through different solutions in order to cater them.
With ec specifically, we chose to look at file-based malware attacks, and I'll combine my answer into two. Number one, malware has always remained a top priority. It's been around for ages, has now gone anywhere.
Ransomware has taken front and center, uh, for everyone's benefit, 500% year on year growth since 2019 in ransomware, 30 billion in damages last year alone and growing rapidly. Uh, and the reason is simple, it's working. And with reset, we chose to look at file-based threats because they've become the number one source of such attacks.
And 95% of the attacks are starting with a document, uh, for those wondering why actually fairly simple, massive usage of documents, which is on the rise with, uh, digital transformation and very simple to insert payload and hide payload in these, uh, uh, these documents. So many of our customers, Doug, are concerned about, uh, the main sources, the main attack vectors for these types of, uh, malware. And those are usually email and, uh, uh, web downloads.
But with that said, we see customers very concerned about what we would, uh, consider kind of off, uh, the beaten path type of vectors such as removable device file transfers very much an issue. There's usually exception lists in organizations. Um, API very much like AI as a, as a new, uh, application, uh, has been a very big concern.
Different web applications, transferring files, uh, from different sources, and of course, shared folder of all types, if it's, uh, SharePoint, Salesforce, and so on and so forth. And that's what we've chosen to focus on. Very good.
Well, we've talked about attack vectors. They are both pathways as well as methodologies and technologies, which have found their way into the enterprise. Um, let's talk for a moment about, um, how, and, and you both have referenced this at, at some point, uh, which is how, uh, enterprises are dealing with these, uh, with this onslaught today.
And so, um, you know, you, you can't help but, but, uh, discuss kind of like, uh, uh, this in terms of a war where this is a kind of wave of, um, you know, attacks which occur, and, and volume as well. So it's not just a series of small waves, it is just a, uh, it is volume. Maybe Mario, you could, you could spend a moment on some of your experience with, uh, customers, and then t you could, uh, spend a moment, uh, with your experience.
Um, well see, you know, you mean, you, you mentioned sort of the interesting, uh, uh, you know, the, the, the, uh, the word, you know, very geopolitical current, you know, and so, uh, uh, you know, cyber, uh, is in increasingly, uh, uh, being, you know, referred, you know, you know, uh, as adjacent to, you know, cyber war, you know, type of, you know, uh, concepts, you know, and historically, uh, cyber implants, malware attacks, you know, were, uh, uh, considered, you know, as, uh, sort of weapons, uh, uh, you know, that, you know, wield, you know, different kind of destructions and, you know, such, you know, there are sort of, you know, the, there are sort of basic, you know, uh, basic knives, and then there are daggers, you know, there are, you know, more, uh, efficient, uh, uh, uh, tools, you know, tools, you know, that, you know, can provide, you know, a tremendous amount of, you know, destruction. And, you know, as in, you know, the, the conventional, uh, uh, uh, um, the warfare, the more time, effort and money you put in, uh, into, uh, destructive payload. Uh, so it's proportionate, uh, potential effect.
Of course, everything can go wrong, you know, at any, uh, at any time. And when it comes, you know, to do, uh, uh, cyber attacks, uh, things go wrong. You know, in a daily, most organizations are subscribing to, uh, one, uh, form or another of a layered, uh, uh, uh, uh, security approach, whether they do it internally or they, uh, engage, uh, external, uh, uh, uh, party with parties who managed, you know, outsourced, uh, uh, uh, uh, services, uh, uh, in, uh, both cases.
Uh, is, is that, uh, uh, different, you know, regulations or, uh, you know, the corporate responsibilities drive, uh, uh, teams, you know, to try to, uh, anticipate, you know, different, uh, attack factors and do something about it. Uh, of course, uh, uh, every, uh, every, uh, defense mechanisms has its weaknesses, just like, you know, any tank, you know, has a protective and, you know, weak, you know, points. So do, uh, defensive, uh, technologies themselves.
And by studying, uh, what's on the other side, you know, uh, the attacker can have, uh, uh, advantage or the ability to bypass, uh, those, uh, those vectors and hence, sort of, you know, do this in a layered, layered form, uh, in the industry. Uh, a lot of people have been using, uh, uh, uh, cyber kill chain for, you know, for, uh, uh, uh, many years. There are other frameworks, you know, for, uh, trying to, uh, uh, insert, you know, as many obstacles to eliminate, you know, as many potential, uh, uh, uh, attack, uh, uh, techniques.
Uh, now, uh, what, what, what that leaves us, you know, is, you know, within a constant understanding, you know, that, you know, the landscape will be changing, that, you know, the evolution of where warfare will be changing, uh, you know, from the, uh, days, uh, days of, you know, king David, you know, to the days of, you know, drones, you know, and nuclear, uh, weaponry a lot, you know, has, you know, changed, changed in the, in, in the history of warfare. And a lot will change in the history of, you know, cyber, uh, uh, attacks. So, uh, you know, without, you know, sort of, you know, doing, you know, that, you know, very painful, uh, very expensive research and understanding of what attacker could do, you know, we will not, you know, have a effective, uh, uh, techniques.
And you should sort of, you know, assume, you know, as Taal mentioned, some things are really rather simple, but sometimes to get to that in a simple text, you know, takes, you know, a lot of effort. And that should be our, you know, greatest, uh, uh, uh, uh, uh, fear Taal. Yeah, first of all, I, I agree with everything that, uh, that Mario said.
And, uh, while the, the war analogies, uh, is spot on, allow me to deviate from it being in Israel right now. Um, I, I'll share more than anything that I think the, the cyber playing field is very much like a soccer playing field. This is not as a soccer fan.
I'm actually, uh, an ex, uh, basketball player. But, um, really a simple analogy. If you have a great goalkeeper, you're not gonna leave them alone in the field.
You'll still want the 11, the other 10 players, uh, being out, uh, in different layers, some in the front, some in the middle, some in the back, trying to stop the ball from getting to that goalkeeper. Uh, and that is a good analogy, in my opinion, to describe a full layered security poster, which is what I see most organizations doing, and that's a, a very, very wise move. So, solutions at the gateway, uh, or things trying to eliminate anything coming into the organization, solutions at the endpoint, trying to find anything that has come in and prevent the attack.
Um, and then solutions within the network, uh, or in network security, trying to eliminate the spread if something has already been breached. And we're seeing a lot of solutions there, micro-segmentation, and so on and so forth. Um, all of our customers at Resect take a full security poster approach.
The smaller organizations have, I would say, 20 to 30 cyber solutions in place. The larger ones, 80 to 130, something like that, that extensive. Um, it does mean that it's very difficult to manage such a poster, but I think it is necessary as a very senior inexperienced, uh, CISO of a large casino, uh, said to me a while back, he said, in email security, if you are buying less than two solutions, you're just a dummy.
If you are buying more than three, you just feel like getting confused. And, and I loved that, that answer, but it's the truth. Uh, most of our customers for every single attack vectors have multiple solutions.
Uh, they wish they had one, but they can't get to that. Uh, too many solutions are covering different angles, and with the evolving attack surface and with, uh, the different styles, forms and, uh, um, and techniques of the attackers, it's almost inevitable to look for the new greatest thing that, uh, can actually, uh, address something that a very large provider today's probably not touching or doing well enough. So, that's what we've looked at.
And, and again, most of our customers are, uh, using a myriad of solutions, and in order to make that efficient and make their their day better, I think security vendors today have to play extremely well with one another so that they're actually efficient, and so that we eliminate overlaps unnecessarily overlaps and inefficiencies on the customer side. Well, tal that was a great answer, and thank you so much for giving us a new analogy in soccer or, uh, what's referred to as football outside the United States. If I heard belt and suspenders another time, I was just gonna, uh, I was just gonna call off this whole panel and, uh, you know, retire to, uh, I don't know, to, uh, some desert island.
Uh, but, you know, the soccer analogy really, really works. Um, it's, but let's go on and really talk about this. Uh, you know, one of the main concepts that brought us together, which is, um, and technology too, uh, which is ai, it's the latest buzzword, and we, and there were all kinds of variations on it, but it's gotten great deal of attention in large measure, because almost 2 billion people have tried or currently use chat GPT in one form or another.
And these large language models are a way of not only, um, you know, doing things which are, which are different and, and more AI like, than, uh, search engines, but they also, uh, have coding capabilities. And those ca coding capabilities have enabled, um, the bad actors to code up, um, uh, forms of attack in the, in the form of codes coding. And, um, so AI has opened up a whole new world of, uh, not only, uh, types of attacks, but also, um, areas to attack, meaning, uh, the technology there are new, there are new, uh, forms of attacks.
And then, uh, separately, uh, there are new, uh, types of attacks. So, uh, the types of attacks, for example, uh, for, I, I heard recently about an attack on, uh, one of the larger, uh, blockchains. And this was done, uh, affected through ai.
Um, uh, because of the automation capabilities of ai, um, bad actors can, can send many different bots and many different, uh, uh, types of attacks to, uh, different locations. So, um, uh, in, in some respects, uh, the bad actors have become more productive as a result of ai. And I just wanted to get, uh, first your, um, both of your, uh, perspectives on how AI has either embolded or expanded the capabilities of, uh, the bad actors.
And then we'll talk about, uh, the customer response. Mario, you want to, uh, kick it off? Sure.
Uh, so, um, we sort of mentioned, you know, earlier, the, the, the nation state actors sort of, you know, what is the nation state actors? So it's a, it's a country with, you know, multiple, uh, uh, intelligence departments, multi multiple military departments, you know, working directly through universities, you know, shock companies and, and, and such, effectively, uh, we are talking about, you know, type of entities that, you know, if they were not doing malicious activity, there would be just like any other user of, you know, AI today. So they're effectively looking, you know, for, uh, using AI for all the good things, you know, that we want, you know, to use in AI today, uh, productivity for one.
Uh, how do we do things, you know, faster? How do we be more efficient? Uh, uh, how do we, uh, uh, summarize data if, you know, that's the sort of, you know, in the type of a usage you of AI that we want, you know, how do you, uh, uh, uh, write, you know, code and, you know, that code, you know, could be malicious, you know, it could, you know, you may leave the malicious payload for the malicious rider, but you know, right, in all the extraneous, you know, code, uh, uh, around that, you know, you know, malicious attack, you know, for, uh, the, the, the lack of, uh, of additional resources, uh, just like, you know, any company, uh, even, you know, malicious actors and nation state, you know, uh, organizations, you know, have, you know, lack of, uh, uh, uh, capable, um, uh, uh, individuals, uh, that, you know, can, you know, perpetuate, uh, some attacks.
So AI is, you know, very, very critical and important, uh, in, in, in, in that, uh, uh, regard. So, uh, if you're looking for something uniquely, uh, nefarious, it's just a matter of, you know, how that data, uh, is, uh, being utilized, you know, and whether, you know, if you're using RLMs, you know, is there their data that, you know, shouldn't be, uh, uh, able to be, uh, leveraged, you know, for, uh, uh, uh, you know, negative purposes, but that then becomes sort of, you know, very, uh, uh, philosophical, uh, uh, argument, you know, around, you know, uh, uh, you know, where is the, uh, uh, uh, uh, compass, you know, uh, uh, within, you know, AI Paul? Yeah, sure.
Uh, I'll, I'll jump in. I think it's, uh, it, it's a fascinating discussion around AI in, in general right now, simply because of how early it is and how much attention it, it's driving. But I think if I have to summarize or try to simplify, I think the discussion around AI right now resembles very much what we've seen before around machine learning and other technology advancements that have brought, uh, two sides of a coin.
And one is the benefits of that technology, um, making things simpler, better for us, and many different levels. And on the other side of it, also making things simpler for the bad guys, right? Um, uh, taking advantage of this, um, I, I've seen an endless amount of, of examples.
And what I find right now is that organizations are still at the exploration phase of trying to understand what their biggest risks are and where they wanna place solutions to address this. I'll give just a couple of examples. Uh, um, I ran into a, a, a new startup still in stealth mode.
And what they're trying to solve for is the easier access of an organization's employees through GPT on the organization's data to get access to information that they should not have access to, and then their ability to actually, uh, um, get that information out of the organization, whether by intent or, or not, um, how big is that risk? I asked the, the founder, he said, we're still working on it. Um, we've had customers of, uh, of, of reset, uh, existing end prospects reach out and say, Hey, can these bad guys now create new documents automatically through AI with commands to bypass traditional solutions?
It's a great question. Uh, first of all, the answer to that is yes, and that's something that we've seen some demand for. We're not, uh, prone or susceptible or with any risk to that because we're not looking for what's known.
We're eliminating what's unknown. Um, so with research specifically, we would completely eliminate that attack. But I, I'm mentioning that to say there's an endless amount of possibilities here.
And Mario touched on some, I think all our concern. And I think just like every technology advancement and every trend that we've seen, I think at this stage, security professionals are trying to assess what are the highest priorities? Where are we, uh, the most concerned through which attack vectors, and then which solutions do we need to bring in, um, in order to cover these, or obviously preferred our existing solutions already catering to that.
And I think it'll be a mix of both. Yeah, interesting to note that chat, GPT is actually an attack factor. It's a means by which, um, uh, companies can get to data and can can, uh, program in, um, uh, you know, like a malware attack, um, and, uh, uh, a number of varieties of applications there.
So, um, let's spend a moment on the response that vendors, uh, software developers such as, uh, EC and Reversing Labs, um, are undergoing right now. Um, just from the, from a top level view, uh, there is analytics, there's automation, there is, uh, greater efficiencies in software development. There are, uh, all kinds of, uh, new techniques that AI can be applied to with respect to data.
Um, it can also facilitate the, uh, uh, it could, well facilitate is one word, but also accelerate the, uh, the functioning of various, uh, uh, functions within the, uh, with, within the, uh, solution. So why don't you both spend a moment about what your company, how your companies are using ai? Mario, I'll, I'll, I'll start here if you don't mind.
Um, sure. Both as CEO and as an investor, I believe in substance and not so much in, uh, writing a buzz. Okay.
Uh, uh, and I'll, I'll explain specifically, I'm not gonna throw AI just for the sake of throwing out ai. Um, with reset specifically, we've had many, uh, in-depth discussions of how we want to play in this field, if at all. So our first question was, is this introducing something that we absolutely have to join in?
And the answer was not necessarily. I mean, we're catering today for easily the number one source of attacks in the vector that we chose to protect from. Uh, and we're seeing a high rise in demand because of it.
However, we're trying to look further down the line, and we saw multiple links that are very relevant. One, like I said before, the, the growing concern by organizations of AI generated documents. So really very much in our playing field, and a big concern that we can address.
We don't need to use AI for it, but we need to use our solution in order to solve for an AI risk. That's one angle. Um, on the flip side, we saw other advantages of AI that we wanna bring into the solution that we think will actually make us, uh, better and more efficient for customers.
So on the technology side, what we want to do is actually, uh, bring in AI in order to crunch a lot of the logs we that we have behind the scenes, which actually analyze anything and everything that comes into the organization in the document. So giving better visibility and insights for our customers. And on the other end of it, as we're growing and trying to, uh, be smart in how we, uh, we, we spend, we're looking at a lot of solutions that are automating SDR services through ai, some extremely efficient, and we wanted to utilize those.
I actually interviewed someone on that, uh, just this morning. So, um, just to summarize, we're not looking to ride the buzz. We're trying to fit in our solution where needed, and we're trying to deploy AI where we actually feel that it'll really have value for us and for our customers.
Great. Mario. Um, so I'd say just, just like every other organization, uh, uh, uh, you know, everybody's very much interested in sort of, you know, participating in the buzzword, but, uh, uh, you know, depending on how you slice the sort of, you know, what a AI is, you know, and, uh, uh, uh, what are the first, you know, evidence, you know, for, uh, uh, you know, first manifestations, you know of it?
Uh, I can probably say that we've been doing ai, you know, for the last seven and, uh, 10 years, uh, specifically, uh, around, you know, machine learning, you know, algorithms, you know, uh, identification of, uh, different, you know, file format, you know, anomalies, you know, identification, uh, of, you know, uh, threats. So ML and deep learning have been for security industry a long, you know, uh, uh, you know, uh, longstanding commitments. They have, you know, their, you know, uh, uh, special, you know, cadences, uh, cardinality and, you know, blocks of, you know, you know, specific, you know, issues that are much different, you know, from, you know, uh, uh, chat, you know, GBT, uh, it really sort of boils down to, uh, uh, use cases in what makes lots of sense.
And other than sort of, you know, mundane sort of, you know, you know, support chat bots, you know, sort of, you know, the, the, the, you know, sales outreach, you know, sort of reversing labs, uh, reversing labs and security companies are just companies like everything else. We do have, you know, a lot of other, uh, angles, you know, where AI is, you know, uh, especially salient, and that's sort of, you know, combining the, the power of, you know, l lms, some of them, you know, the public models, you know, have, you know, some knowledge about security, generally not, you know, but, you know, there will be future LS LLMs built that will be more knowledgeable no matter what. You know, they all will have to understand, you know, how to deal with, you know, private, uh, data or, you know, customer owned, uh, data.
Uh, I think, you know, many organizations, uh, uh, here, you know, have, uh, uh, started, you know, fielding, uh, customer requirements, you know, that, you know, prohibit, you know, any usage, you know, of customer data for, you know, ai, uh, uh, training. And, uh, there will be that sort of, you know, giant divide, you know, for, uh, uh, good, you know, uh, time, you know, to come. So finding way how to merge that, you know, finding way how to, uh, uh, get, you know, sort of, you know, predictive, you know, the, the, the, uh, summarization, uh, features of, uh, uh, of, you know, ai, uh, applied, you know, across, you know, the, uh, the generated, you know, uh, and, you know, locally, uh, prevalent data, uh, uh, will be a very, very important, you know, uh, item, you know, for, uh, for any solution.
And given the tra diversing labs, you know, uh, you know, is, you know, focused, you know, large amounts of data for us, you know, anything you know, that, you know, provides, you know, the, the, the better productivity, uh, eligibility, uh, um, understanding of what we have is, uh, hugely, uh, uh, important in our element. Very good. Um, for me, uh, I will, um, let me just add one more perspective, which is enterprises are gonna learn a great deal about attack vectors and individual attacks.
And its, and its after effects and, uh, through the capabilities, uh, that are built into ai, um, not only from a a from a statistical and, uh, analysis standpoint in conjunction with Python, uh, and other tools, but also from a predictive analytics standpoint, and to be able to, um, uh, you know, do anomaly detection and very specific, um, uh, other things the vendors working in conjunction with, uh, enterprises will provide hopefully over, over time, much more insights into what's happening by way of, uh, attacks and, uh, in, in their various forms. And as, um, both of you have kind of referenced in, in very, you know, these kind of attacks have, are not gonna go away, but they're gonna continue, continue. And so the smarter and smarter, um, that enterprises and users become about this, uh, the, the better off they will be and the easier job it will be for vendors to, um, to, uh, supply the tools that'll be necessary to fix these, uh, address these challenges.
Um, I want to, uh, uh, ask a concluding question of our panelists, which is, uh, how do you see the coming years, um, you know, say, look out over the next two to three to five years about, um, you know, how tools will evolve with ai, how tools will evolve relative to attack vectors. And, um, make a comment about your, uh, your companies and how your companies will evolve. Um, won't tall, don't you start off by, uh, providing us with an insight.
Yeah. I think, um, generally what we'll continue to see, I don't think it'll be anything new. What we'll continue to see is consolidation in the, um, in the security market, consolidation in the form of larger players, uh, acquiring smaller ones, um, in, in different sizes, of course, in order to build a complete suite for their customers.
Um, for anyone thinking that that will mean that a large organization will use five solutions, I don't think that will ever happen. Uh, what we're seeing exactly to this question about ai, um, every uh, every couple of years we'll see a new trend, a new threat, a new issue popping up, and with it, a large amount of solutions that are coming up to address that threat. And they'll always be faster and more innovative, uh, than the larger players at, uh, a great scale.
And so I think we'll see consolidation, we'll see less solutions, but probably by 20, 30% less, not as dramatic as some people think. I think, um, with ai, we will have greater focus. We'll understand what solutions, what are the real risks, what solutions are there to address those risks, and we'll see, uh, some emerging leaders in, uh, in, in that space.
And I wouldn't be surprised if there's, uh, a new buzzword that we're talking about in, uh, in a couple of years that is, uh, the next gen AI or the next gen of something that is, uh, concern to all of us, and we'll have a similar panel to, uh, to address those then. Very good. Tom Mario.
Um, so I am, uh, I'm sure that, you know, AI is, you know, come to stay there. There are lots of really, really useful and very valuable, uh, uh, advances, you know, that, you know, will, uh, allow us, you know, to, uh, upscale our employees, sort of, you know, to, to get the most, you know, out of the human factor. That's, you know, uh, on the other side, you know, of the, of the paradigm.
Now, uh, what, you know, we need to expect, you know, for AI to, you know, to solve in the future are really sort of, you know, the technical, uh, aspects, you know, so weaknesses, you know, of the AI today, and, you know, that's, you know, uh, uh, uh, concepts, you know, surrounding time, uh, after all in the knowledge is, you know, multidimensional and it changes over time and means different things depending, you know, on its context, you know, that, you know, is not yet, you know, anywhere close to satisfactory, uh, uh, for us. You know, at the same time, you know, AI needs to, uh, understand how it's going to handle, uh, incorrect, you know, uh, scientific data. And, you know, with security, you know, there is, you know, all sorts of, you know, de in deliberately wrong data, uh, uh, broken items.
There's all sorts of, you know, uh, uh, uh, elements, you know, that, you know, uh, make, you know, any training set or any data we rely on, you know, completely or partially, uh, uh, incorrect, you know, uh, that will need to be addressed, you know, uh, in a way that's significantly stronger that what we have today. And it's, you know, not, you know, much different than the challenges that, you know, different medical, legal, uh, ai, uh, uh, um, uh, uh, solutions, you know, uh, uh, need to overcome as well. Great.
Well, um, you have provided Bo our panelists have provided us with, uh, uh, a broad, um, set of insights into, uh, not only solutions, but also the challenges. And, um, it's important to note that, um, from what we've learned today as what we, uh, as well as what we know from the operating environment, that things are complex and, and that, uh, these attacks, uh, attack vectors, these, these individual attacks, these tech, these technologies that the bad actors are, have developed and are unleashing, um, they're not gonna go away. And so it's important to gather information about, uh, not only the bad actors and, and their technologies, but also what vendors are doing to, uh, counteract these, these attacks.
I think we've learned a lot from, uh, this panel. I want to thank, um, Mario and Tal for, uh, their contributions. And, um, what we'll do is now go to a live session.
And, uh, with that, I want to thank you all for, uh, attending this, um, this vi the video portion, and, uh, look forward to interacting with you on the live portion.