Adaptive Security CEO Brian Long on Combating AI-Driven Cybersecurity Threats
Adaptive Security CEO Brian Long dives into what is required to protect organizations from cybersecurity threats that are leveraging artificial intelligence (AI) following a recent investment in the company made by OpenAI.
Transcript
Hey guys, thanks for the throw. We're here with Brian Long, who's the CEO of adaptive Security, and they're focused on helping us fight the fight against deep fakes and other threats against AI models. And they just picked up some investments from their friends over at OpenAI.
But Brian, welcome to the show. Hello. Thanks so much for having me, Mike.
Thrilled to be here. And if you would kinda walk us through a little bit for some of the folks who may be a little less initiated than others is, what makes threats in the age AI different? I mean, when do we need to think through a little bit that we're not kind of really cognizant of just yet?
And 'cause when I look at it, it seems like the list keeps growing day by day. Yeah. The list is, is unfortunately definitely growing day by day.
You know, first off, we are seeing a lot of growth in social engineering attacks, uh, since Chad GPT came out. So, you know, in the last couple years we've seen a four x, uh, increase overall in phishing attacks and more sophisticated attacks. Like DeepFakes grew 17 x from 2023 to 2024 with over a hundred thousand attacks in just the US alone last year.
So it's, it's growing really, really quickly. So it already seems like there's a, a large number of platforms and tools out there that have come out to address this issue. From your perspective, what might differentiate one of those things from the other?
Yeah, so there are lots and lots of cybersecurity tools, uh, in market. You know, last time I I heard it, I, I, I thought that there was something like 4,000 different, uh, cybersecurity companies that had raised some sort of funding. So there's definitely a lot of tools out there, and it's really hard to be a CISO right now in sort phish from foul, uh, specific for our company at Adaptive Security, what we focus on is next generation security awareness training.
So we are focused on how to do phishing simulations as well as security training for your company in order to protect you from AI powered attacks. So getting the workforce ready for things like deep fakes and generative ai, email phishing and voice phishing and SMS phishing that are all growing at a tremendous rate. So that's really where we differentiate is our focus on helping protect organizations from this next generation of threat.
Some folks are a little dubious about training of end users, and especially in the age of AI because they're basically saying, these things are so sophisticated, it's impossible for humans to detect, but are we just now fighting fire with fire and using AI to detect AI threats? Yeah, look, I, I think that there are two key buckets that I would, I would think about as an organization preparing for AI threats. You know, number one would be controls, uh, and number two would be awareness on the control side.
You know, a lot of companies are still even adjusting to an era where a lot of the workforce is remote, right? So you kind of have this combination of remote plus AI that's causing a lot of strife for companies. You know, historically they may have controls around things like wire transfers, but they don't have controls around a lot of new things.
Like, for instance, hiring people. Uh, one of the biggest attacks we see right now, Mike, that that's growing really quickly is someone impersonating, uh, an individual in order to get a job at a company and then get insider access in order to cause havoc. So that, that's a big area that that organizations are really focused on, on the control side, making sure they meet someone in person Number two, on the awareness side, you know, a lot of people don't realize what AI's uh, you know, capable of, you know, people that are, that are living it every day, like you and me.
You know, we may understand some of those capabilities, but the average employee does not. So it's just really important that we educate employees right now on how quickly the AI technology is moving and how good it can be at impersonating people, not just voice and like this, but also lots of information around who the person is to make an extremely sophisticated attack. Mm-hmm.
So what exactly is the relationship with Open ai? I get that they invested in you, but is there also gonna be some go-to-market relationships? How does that all come together?
Yeah, so look, we, we obviously have an investment relationship with the OpenAI Fund. Uh, we raised 55 million with OpenAI. Um, and, you know, we are super, uh, super happy to partner there because look, they've, they've seen what we've seen, right?
They've seen this increase in the last couple years in the volume of phishing attacks and you know, how people are using these tools. Um, in addition to that, there's, uh, a whole bunch of elements of our product that are leveraging open AI technology. So, just as an example, Mike, we wanna make training that employees actually love that they actually, uh, like taking and, and learn from.
And in order to do that, what do you need to do to make it like that? You know, number one, you gotta make it relevant for them. So we need to figure out, you know, how can we make a training that's specific to your role, um, and your organization and make it relevant to you?
So we have this training creator that allows us to create trainings specific to the company and even to the department and the individual, so it speaks just to them. Mm-hmm. To your point about that, and correct me if I'm wrong, but I always felt like a lot of the end user training tools that were out there prior to this was roughly the equivalent of going to traffic school and nobody paid much attention to what they were doing when they were there in the first place.
You know, I would say it's, it's actually worse than traffic school because, because I think in, in traffic school, you know, you wanna make sure that you pass the test and you certainly don't wanna get in an accident afterwards because it affects you so much. Personally, I think that historical trainings have unfortunately been really boring. Uh, a recent, uh, study I saw said that 77% of people zoned out of their, their traditional security training.
And it's kinda wacky because it's this thing that, um, you know, look, first off, everyone at the company needs to take it anyway, right? You're gonna have to take something because it's required under compliance if you're, uh, you know, a large enough company. And then, you know, number two, it is the number one way that the average person at the employee understands the security posture of the company.
So I, I think that we need to take a step back and say, look, how do we make security training really great? And I think the key is making it super personalized to them. Um, if it's saying things that are relevant to you in your role as an individual, um, as well as at the company, so I can say things to you to protect your family, protect your loved ones, um, then I'm gonna get your attention.
So how does that work exactly? Is there some sort of LLM that's going out there to find out information about me and then crafting an attack about that and then that's what gets my attention? Yeah.
Yeah. So we do a couple different flavors of it, um, for the entire company. Um, we can create trainings based on, you know, as simple as a prompt, like, Hey, you know, I wanna make a training on DeepFakes as they pertain to our company.
And what we do is we take that prompt and we also pair it with a whole bunch of OSN data that we pull, um, on the company in order to create a personalized training anywhere from three minutes to eight minutes long, um, specific to that company. And, you know, we custom make images and animations and audio narration and all this sort of stuff, but all to fit specific to that organization. Um, so that's one thing we do.
Another thing we do, um, is we also create dossiers of highly credentialed individuals, you know, people like executives, someone who runs security, et cetera. And we create those dossiers by looking at all the data that's available on someone in the large language models, of which now there's, you know, millions of open source ones on hugging face and in other places, um, as well as looking at things like data brokers and, and, and other sources of, of publicly available information, um, in order to figure out all the information on, you know, you Mike or me or whoever it is. And then we put that information, uh, into, uh, a stable LLM and say, Hey, based on all this info, how would you attack Mike?
Um, and from those outputs, we're able to understand both of the security team level as well as the individual level, what that person should look out for. What's your best advice to cybersecurity folks who would love to do this, I think, but they always find it a challenge to get this up the priority list a little bit. 'cause they have so many different things that they're supposed to be funding and everybody's gotta pay for their existing infrastructure.
I, I still got the firewall bill or whatever it may be, but how do I kind of get the business leaders to kind of wrap their head around this is a priority? Yeah, I mean, look, I think that there's a couple things that, that help make it a priority, right? Number one, um, this is gonna have one of the largest blast radiuss at your company.
You know, uh, we still find that social engineering plays a part in about 90% of successful attacks, right? So it's gonna be a component of most attacks. Uh, you know, number two, it's gonna have a lot of executives and people paying attention to it, right?
So, you know, if someone is impersonating your executive team or it has something to do with, you know, executive protection, um, they're gonna care about those things. So it's pretty easy to, to raise that up the flagpole and show to them and have it be something that, that they pay attention to. And then number three, you know, you, you can't think of A-A-C-E-O or someone out there right now who doesn't say, you know, I wanna make sure we're on top of the latest and greatest on, on AI things.
Well, if you wanna make sure you're on top of that for security, um, and, and making sure you're training your whole company on that for security, um, then this is a great solution. And then finally, I would just say on the training side, yes, we cover everything for security. We also can do compliance and we can also make trainings on anything you want.
You know, so we have like major hotel chains that use us in order to train new employees on, you know, hotel policies. So you can use the tool for other things beyond just security, um, if you want as well. Mm-hmm.
I feel like, and correct me if I'm wrong, but are we once again kinda chasing after an emerging technology and thinking about the security after the fact? Or do you think we're closing that gap better than we have historically? Uh, unfortunately I think we are a bit behind right now.
Um, you know, i, I I think that we, uh, we are not ready for how quick the technology is moving right now, and I think attackers are moving a lot quicker, um, than than large organizations are, uh, in the us. And I think that goes from, you know, everything from, from governments, uh, you know, federal and, and local to, um, you know, nonprofits to, you know, fortune 5,000 companies. So, um, we are seeing a large increase in the volume of companies that have seen, um, successful, um, AI and, and deep fake powered attacks.
You know, I talked to over a thousand CSOs in the last year, um, when I would talk to folks a year ago, it was probably one in 10 that had seen, um, that type of sophisticated attack. Now, uh, you know, like with DeepFakes and AI personas now it's about half. So that's growing a lot faster than, you know, awareness and controls are to deal with this issue.
Alright. I'm sure you've talked to some folks and you've definitely been around on this AI front, but is there something you're seeing people doing today that just makes you shake your head a little bit and go, folks, I wish we can be a little smarter than that? Well, you know, the number one tip that I would give our audience is if it's still your voice, uh, on your cell phone voicemail, uh, change it to the robotic voice because all we need in order to make a, uh, voice sim of anyone is just to call their cell phone number, which we can get for over 97% of people hear their voicemail, and I just need three seconds of audio on the voicemail in order to make a copy of your voice.
It's very easy for anyone to index that, to call that, to get that, you know, you don't have to, you don't have to know anything or dig in anywhere. Um, so that would be the number one thing I'd tell people to do. Yeah, I don't understand.
People leave me voicemails. I'm like, you have my number. Just text me.
What's the issue? Well, look, that's, that's, that's certainly another, uh, tricky vector is SMS that's been growing like crazy. Um, we, we've seen in particular a lot, a lot of attacks, um, you know, coming from overseas now targeting SMS very big.
Um, so that's another area that you need to make sure you're, you're safe on. And, you know, people say, well, I would never reply to an unknown number. Something that we see them doing now is they will actually send an audio voicemail with the text, and the audio voicemail will include, uh, like a deep fake voice in the audio voicemail from, you know, a trusted colleague.
And, uh, and then, and, and it'll say, Hey, give me a ring, or, you know, uh, write me this note or something. Um, so really effective way to to, to get into someone. Um, so I would also be aware of, of SMS more than ever before.
Hmm. So to your point, or, and maybe we should have been here before, but have we finally gotten the point now where we don't trust anything unless we can get it verified somehow or other, and is that where we should be at this point? Yeah, I mean, it comes back to my earlier point on controls.
You know, I, I think that, um, you know, a lot of companies are not ready, um, for, uh, what AI is changing around, uh, voice-based authentication. You know, uh, a couple months ago, um, Tim Altman was, was speaking at the Federal Reserve and said, it's unbelievable that a lot of banks today still use voice auth, um, as the means of confirming, you know, major transactions. Um, I actually just heard an anecdote too, um, of a major defense contractor where they had a, uh, voice deepfake attack.
And the only way that they actually were able to stop it is that a bunch of the, uh, sort of high-touch executives at the top, um, had a military background and as a result, were using code words, um, to approve certain things. And, uh, the, uh, the deep, the deep fake did not know the code word, and that's what stopped it. So, uh, you know, these are, these are really happening now, and I think companies need to, to take a close look at those controls.
Um, you know, look, you don't have to to question every single person that talks to you, but if they're asking you to do something important, they're asking you to, uh, uh, go, go through some process, you know, that's where you need to, to fall back and really question, All right folks, and as usual, the bad guys are being clever and definitely a little more innovative these days. And the issue then becomes, well, how are we gonna respond and what are we gonna do to keep everybody safe? Because, well, maybe it all starts with training.
Brian, thanks for being on the show. Hey, my pleasure, Mike. Have a great one.
All right, I'm back to you guys in the studio.