20 Years of Hacking: Why AI Changes Everything for Cybersecurity
What does a veteran hacker with over 20 years in offensive and defensive security think about the AI revolution? In this episode of Techstrong TV, Alan Shimel sits down with Joe Cortese, Pen Test Director at A-LIGN, to explore how AI is fundamentally reshaping the cybersecurity landscape for attackers and defenders alike.
Joe shares his journey from the US Intelligence Community to leading a team of 40+ pen testers at A-LIGN, a cybersecurity compliance firm specializing in SOC 2, ISO, HITRUST, PCI, FedRAMP, and penetration testing. He explains why compliance is just the ground floor and what organizations should be doing the other 11 months of the year.
From lessons learned under Bell Labs engineers about continuous monitoring, to the concept of an AI poverty line that separates organizations willing to adopt AI from those falling behind, Joe delivers a no-nonsense perspective on what it takes to survive in today’s threat environment. Whether you’re in compliance, pen testing, or security leadership, this conversation covers what it really takes to stay ahead of modern threats.
Transcript
Hey everyone, it's Alan Shimel. " I'm happy to introduce you to my next guest. His name is Joe Cortese.
Joe is a pen test director at a company called Align. We're going to hear all about that. Let's hear all about Joe first, though, right?
Pen test. Look, pen testers were always a bit of the bad a***s, right? In security back when I first started going to Black Hat, when it was the shizzle, in 2004 and '3 and '5.
And before it became RSA in the desert. " How are you, man? I'm doing great.
I echo that same feeling about how Black Hat and DEF CON both have changed over the years. Yeah, a little bit. Yeah.
I've had the luxury or the curse of being a hacker before it was cool. So we're talking about pre-2000s. " Mm-hmm.
Things were very immature back then. Pen testing meant something different. Security meant something different.
It was a very immature industry. I started in the US intelligence community, so I worked for a startup that was creating data collection systems and tracking- Mm-hmm ... systems.
So the mindset of being a hacker back then was pretty novel, right? So you're working for the intelligence communities, and you're looking to create systems, create actual software and hardware, we did both, of data collection, so you had to think like a hacker back then, right? So that's really where I started.
I really learned how to question everything. And I've had the luxury again, or the curse, of working in both offensive and defensive security. I ran a security group, a global SOC as well, for a global jewelry company.
I will leave the name out of this, but that was a pretty interesting, let's just say, experience with defending against attacks after about 10, 15 years of creating them. Yeah. But that was the beauty of DEF CON back then, because it was where the feds came to meet the hackers, and where they did a lot of recruiting.
I wouldn't be surprised if maybe you didn't get recruited there. But it was a pretty special time and place. Not that it sucks now necessarily.
I'm not saying that. I'll be there again this year. We'll be doing video from Black Hat and so forth.
But this is back when, and you know because you were there then, too, it was in Caesars Palace, and the whole exhibit floor was in the hallway outside the rooms- Yep ... where we're doing the briefings and Barnaby Jack's making the ATM machine spit out dollars. And so- Yep ...
those were good days, man. I loved it. But look, here we are.
It's a different world. But in its own way, it's equally as exciting, right, Joe? This whole thing with AI and AI vulnerabilities and writing exploit code and ransomware code and wow.
At some level, it was a simpler time back when you were doing this, right? It was, I don't want to say more innocent, but it was somewhat more innocent. You're right.
Not as- You're right. You know what? Phishing didn't really exist to the degree that it does- Yeah ...
today. And here I am saying the degree of today. Look how crazy AI has transformed phishing.
It's changed the narratives. It's empowered the attackers. Speed.
It's able to bring up a stack in record time and ready to go, templates and all. Give me the most believable phishing narratives now, and it'll do that. So yes, you're right.
It was a very innocent time, and now look at what AI has done, and it's changing every day. I feel every day I look at my news feeds because I'm very deep into AI. I run local models.
I have three Mac Minis next to me that you can't see. So I do a lot with- We're in the same movie. Just for the last month, mind you.
You can't get your hands on a Mac Mini anymore. They're all sold. Though I got them in Costco.
They didn't have max memory. And you know how the Mac Mini is, you can't add memory, per se. Yeah.
But you could still get them in your Costcos. Interesting, because I was looking for at least another one. I have some pretty serious ones here.
I got 64 giga memory. Right. And I got a studio with 256 giga memory that I run with- No, the studios are nice ...
all the time. We have a few people running them, too. Yeah.
But we have a mix. We've got some people running Claw on the Mac Minis. We've got other people running Perplexity Computer and other people playing with other things.
Yep. That's the world we... It's an exciting time, let's face it.
But Joe, let me... Because I could talk to you about history and this stuff all day, and no one will want to listen. It's just you and me.
Let's talk a little bit about Align, the company. Tell us about it and what you're doing there, and what it does, what the mission is. So we are a cybersecurity compliance firm focused on cybersecurity audits.
We do SOC 2, ISO, HITRUST, PCI, FedRAMP, and pen test. So my magnifying glass is solely over pen test. I've been in this role for seven years now.
We've grown and scaled the team fromLet's just say single digits to now we have a team of over 40, and we do a lot of cool pen testing, and it's not just for compliance. So if a client is getting SOC 2, an ISO, HITRUST, we're doing their pen testing work, but we also do what I like to call vanilla pen testing, which is you care about your information security. I'm not saying people don't care, but you care about your information security, and you want extra pen testing or non-standard from compliance.
You want a larger scope. You want something more targeted in nature. You want a different narrative.
So those are the things that we do within Align Pen Test as well as the- I love it ... now, the majority- Yeah ... of what Align does is audits.
Absolutely. And you know what? Look, I've been in security a long time, Joe.
Back when I was doing companies, not sitting on this side of the camera. Look, I've always felt compliance is lowest common denominator security, right? That's where you need to check the box to get your cert, pass the audit, move on, make the board happy.
But that doesn't necessarily mean you're secure, right? At any given moment in time. And you should go beyond.
Of course, we live in a world where just getting people to do the minimum feels like a gargantuan task. But we should go beyond the minimum. And, of course, look, I got to assume AI's been a bit of a...
It's probably been a huge help for you guys as well, right? In terms of getting pen testing done and maybe expanding the coverage, or not. We were very guarded at first to open Pandora's box.
I know a lot of organizations that we've audited, actually, implemented AI before they really had policies and things that you really should do, you should think about. The data sources that are being ingested in this and everything in between. But AI has accelerated a lot of work we do, and it also has brought a lot of risk, right?
Back to what you said about compliance, compliance is definitely the ground floor. That is a great starting point. But as I always say, what are you doing for the other 11 months of the year?
You should be doing something continuous in nature, and we're going to get to that later. You should be doing something continuous in nature to understand how your threat surface evolves and how your compliance deviates. And that's critical.
And again, yes, compliance is the baseline foundation. That's the ground floor that you should be doing at a minimum. Absolutely.
Agreed. Hey, for people who want to get more information about Aligned, because it's in your title underneath here on the screen, people are seeing, but how should they go about it? Where do they go?
You can reach out onto any of the contact me on the actual Aligned website. Feel free to reach out to me directly if you have any questions. But the best actual way is go on our website, go to our contact, and there's some specifics there that you can actually get more specific answers on for being contacted.
So that is the best way forward. Again- The URL for the website? I'm sorry?
The URL for the website? I am all for the website. I am.
No, no, the URL, the URL. Oh, the URL. The web address.
It's a- Sorry ... com. com.
That's what I was looking for. Yes. Thank you, Joe.
I appreciate it, man. All right. Hey, let's pivot into kind of inside the hacker's mind, if you will.
Right? We've kind of started touching on these things. Ransomware-as-a-service, the phishing, which is coming.
Phishing was the primary front door for a long time, but I recently saw a report that no more, now that they're finding more web app vulnerabilities that are letting people go in and inject ransomware into this. But AI-driven attacks, of course, they're all over. Third-party vulnerabilities, which in spite of the mythos and the glass swing and the clutching of pearls, we haven't really seen a lot of people address that issue as it applies to this new way, the avalanche of vulnerabilities we might be finding.
How the hell can... I always said the problem with security is there's maybe 50 companies in the world that have enough wherewithal to do it themselves and do it well. The rest of us are SOL unless we partner up with people and companies.
How are you supposed to stay on top of this, Joe? It's a mouthful, and I think everything that you touched on is spot on. The attackers are faster.
They have a lot more things to accelerate. We're looking at web app vulnerabilities, which are increasing. We're looking at accelerated phishing.
There's just so much going on. Now, there's one thing that remains universal. Now, I've been talking about this probably for 20 years, and part of it was, I had the luxury of learning under Bell Labs engineers in the early 2000s at this government startup when they were laying off a lot of...
There were a lot of layoffs at that time. I got to work at a government startup with all Bell Labs engineers. And the number one thing they used to say is, "If you're not monitoring, you know nothing.
You're flying blind. You need to understand what's going on. " Now, that was a different context back then, but it still holds true.
It's almost universal. So if you don't know what's going on within your environment, your systems, your third parties, and just everything in between, you can't identify an attack, and you can't even identify anomalies that can indicate an attack. Forget about identifying attacks.
When you look at everything that's gone on today, there's attacks that have blended into the noise. How do you even catch- Yeah ... those now?
So the way is-You need to have your logging and monitoring to such a point that you can detect anomalous behavior, because that's where we're going in this age. That's what's going to save us. I hope so, man.
I hope something could. So how does one reach this nirvana, Joe? What do they do?
So, I would say that it's critical to at least understand your environment and start enhancing the logging and the monitoring that you have. Okay. So is it application level?
Is it network level? Now, security tools help you out because a lot of the security tools and agents can produce visibility and produce logs that you can do something with, and that's critical. Right?
And I think part of it is understand your specific environment, understand your gaps, use security tools as you need to, to enhance coverage within those gaps. But you need to understand a central logging strategy that's going to pull all of that together to give you that holistic visibility. I love it.
I know what people will hear saying when they hear this, though. "But I don't have the money. I don't have the resources.
" What do you say to them? AI doesn't care. AI's coming for you.
AI doesn't care. It's a hard world that we're living in. Look, I get it.
But here's the good news. AI can help you with that, right? I think you can leverage AI, too.
A friend of mine, Wendy Nather, years ago, came out with this idea of companies living below the cyber poverty line. Right? Companies that just didn't have the resources to stay out of poverty, cyber poverty, let's call it.
Yeah. I think we have an AI poverty line, too. But it's not a big question of money.
I think it's a question of willingness to use the tools to get you above that threshold, that poverty line. Yeah, and you know what? I actually have an example of that now.
I have some really, really good friends that I work with in the government, and they went on to extremely large healthcare companies, and they created their mobile apps, and banking and created their mobile apps, like that we use today are created by some of the people I worked with. And they're resistant to jump on some of the AI bandwagons and AI enhancements. And I've asked them, I'm like, "Have you used Claude?
" That is the mindset you don't want to have. Exactly. If you don't have the budget for it, you still need to dive in headfirst into this before you get too far behind.
Right now, there's so much available that's open source and free that you can use to accelerate everything you're doing. It's going to multiply you times 10, your skills, your speed, the same thing the hackers are taking advantage of, right? Absolutely.
Skills and speed. So I think that the biggest deficiency is going to be exactly what you said. A lot of organizations are not going to adopt these things, for whatever reasons.
Maybe it's a skill gap. Maybe it's a talent gap. I'm not sure, but what I do know is that- Maybe they're just afraid of losing their jobs, because that's my experience, that's what I see, Joe.
Yeah. People, "Oh, no. If I bring the AI in here, I'm not special anymore.
" There's that fud of that, and I can guarantee you how you lose your job. Don't use AI, right? And then we'll lose your job to someone who does.
Exactly. And I think that people that haven't used it really don't know how good it can be. I'm not saying it's the best thing in the world, right?
No. But I'm saying it makes an already smart person really sharp. And that's why I was yelling at my buddy.
I was saying, "You need to use this. " It's life-changing for you, yeah. Exactly.
Yeah. You're one of the best devs I know. I see it.
Joe, it's people like you and I, who've been around the block, who can leverage this to 10X ourselves. I see a lot of younger people, and I'm not banging on younger people. Let's say less experienced people, who are hesitant because they do fear it could replace them.
And they don't communicate as well with it. They don't embrace it. They kind of resist, and I'm afraid for them, honestly.
Right? And I'm afraid for the organizations they're working at. Because sooner or later, it's going to bite you.
We've seen this before, though, Alan. Right? We've seen new technologies come out, and people are always skeptical, right?
And they say- Yeah ... "Oh, I'm not going to jump on that. " And next thing you know, it's not a bubble.
It starts really expanding, and now it's difficult to get in. It's difficult to jump in now. Right.
Now you got to get on that moving train. Yes. Yep.
Yeah. I hear you. Hey, Joe, we're about out of time.
I feel like I could sit and talk to you for the next hour or two, but I got work to do, too, as I'm sure you do. Thanks for coming on here, giving us a little bit of a rundown on where things are and what's happening, and more importantly, what people can do. Right?
And like everything else I've ever seen in security, so much of it is common sense, too. Right? You don't necessarily have to read it in a book.
Right? There were no college university programs for cyber, for InfoSec when I was coming up. Right?
You could learn this stuff if you put the time into it, and organizations need to do that across the board. Anyway, hey, just a quick reminder. com, right?
Yes. Joe, this has been great, man. Thanks for coming on here.
I hope to speak to you soon. Alan, thanks for having me. Hey, we'll be at Black Hat this summer, if you're coming.
I'll see you there. All right, man. Joe Cortese, pen test director at A-LIGN, here on Techstrong TV.
We're going to take a break. We'll be back in a moment.