AI Collective Defense Changes Cybersecurity Economics
AI Collective Defense Reshapes Cybersecurity
Alan Shimel talks with Sachin Jade, Chief Product Officer at Cyware, about why AI is changing the economics of both cyberattacks and cyber defense. Jade explains that attackers can now find vulnerabilities, plan exploit paths and launch campaigns much faster. That shift lowers the cost of attack and puts more pressure on defenders to respond with the same speed.
The conversation focuses on AI collective defense as a way to help security teams work together at scale. Cyware’s approach centers on operationalizing threat intelligence, improving collaboration and helping organizations share relevant security insights across trusted communities. Jade says defense should be treated as a team sport because attackers do not follow rules or operate in isolation.
Threat Intelligence Becomes More Actionable
Jade describes how Cyware helps teams manage the full threat intelligence lifecycle. That includes gathering data feeds, deduplicating information, normalizing intelligence, prioritizing risks and deciding what action to take. The goal is to move beyond collecting threat data and turn intelligence into coordinated defense.
The episode also explores how industries can collaborate through groups such as ISACs. When one organization sees a threat, others in the same sector can benefit from that knowledge. This type of AI collective defense can help organizations adjust controls faster and reduce duplicated effort across the security community.
AI Moves Defense From Reactive to Proactive
Jade explains that AI can help defenders shift left by testing software before it reaches production. Adversarial AI models can look for potential weaknesses earlier in the development lifecycle. Runtime monitoring can also help identify unusual AI agent behavior and trigger controls such as kill switches.
The discussion closes with a look ahead to the rest of the year. Jade says the hope is that AI-powered defensive capabilities, industry alliances and smarter regulation will scale quickly. The concern is that attackers may move faster if defenders do not act now.
Transcript
Hey everyone. Welcome back here to Techstrong TV. My next guest is Mr Sashen Jade.
Sashen is the CPO, chief product officer, over at Cyware. Let's say hello. Sashen, welcome.
Thanks for coming on Techstrong TV. Thank you so much, Alan. It's a pleasure to be here.
My pleasure. Sashen, I always like to give our audience a sense of who they're watching. I mentioned you're the chief product officer, but fill in the blanks.
Give us your journey. Yeah, great question. I'm a customer-obsessed product individual.
What I mean by that, and I'll give you a context of my history as well, anything that the customers are solving, they want a product that enables them to solve that equation, so to speak. So that's who I am. My background being in the security business, cybersecurity risk space for most of my professional career in one way, shape, or form.
2006, 2007 onwards, I started to build my own product firm in the cybersecurity space. For about nine years, we got exited, acquired by one of the Big Four's. Was there for a couple of years as my golden handcuff.
Then drove into more PNL, product growth at big corporates, and then two years ago, joined Cyware as their chief product officer. My mandate out here is kind of threefold. One is being the customer ops individual I am.
Go talk to customers, see what they're facing, especially in today's day and age with all AI, et cetera, and so on. What is necessary for them? How do they solve it, et cetera?
Second mandate is how is the market evolving, what should we bring into the future as product set, how do we price it, level, all of those things. And last but not the least is making sure that it provides real benefit for the customer. So one of my philosophies is I want my customers to literally bleed the product, which means that anything that they're spending time on, they're taking time out from somewhere else, which means it has to be beneficial and meaningful for them.
That's who I am. I am based out of the Northeast United States, and love it. Good for you.
Thank you. That's great. So you've been doing this for a minute, huh?
That's correct. Yeah. Good for you.
Sashen, I know Cyware, but I don't know if everyone else out here is familiar with Cyware. How would you describe it? How would you describe the mission problem it solves?
Yeah. So our core philosophy, and I'll go with the philosophy, then the vision, and then the actual products themselves that enable our customers. Core philosophy is defense should be a team sport.
Make the defense in a collective basis because attackers don't play by rules, by definition. So which means if the defense has to scale very effectively, we have to collaborate with each other to make a holistic defense perimeter, so to speak. So that's the philosophy.
What that translates into vision is two fold components. One is the actual core platform that enables you to operationalize threat intelligence, and the second is how do you collaborate with other entities, other peers, ISAC groups, et cetera, and create that entire holistic network, so to speak. So philosophy, this is the vision, and what it translates into product is we've got two product sets.
One is, which as I said, which operationalizes the entire life cycle of a threat intelligence, all the way from getting the data feeds that you need to running deduplication, normalization, prioritization, risk scoring, how do you act upon it, and also the acting itself, whether you block some of the firewalls based on the IPs that need to be blocked, et cetera. And the second part, or the second product set is where pretty much all the ISACs use, which is a collaboration platform on alerts, advisories, what kind of threat defense mechanism should we have, et cetera. Example being, let's say, an FS-ISAC.
All the members of FS-ISAC will leverage that platform along with FS-ISAC to say, "Hey, these are the banking sector threats that we need to be aware of. What are the defense techniques? What are the recommendations?
" If certain things that happen to a particular financial services institution, they can collaborate with another one, message, interact and figure out what the necessary steps are, and so on. So that's who Cyware is, operationalizing threat intelligence at scale via collective defense. Excellent.
I love it. Thank you for that great recap of it. Sashen, for all the years that you've been in cyber, the last two, three months have been crazy.
My background's cyber as well. Started a couple of security companies, helped start. It's crazy what's going on the last few months, even this last week with the hugging face open AI.
Look, that's certainly a cyber issue, but I don't blame the AI, I blame the people for not locking it down correctly. Poor hygiene, poor planning, poor architecture. However, there's no denying that all of this AI-ing and vibe hacking has turned this...
The cheese was moved is the best way I could put it. We've moved the cheese in cyber. I heard someone say today, if you use Mythos or something Mythos-like and you find a vulnerability in your software, assume someone else found it already too, because the bad guys have it, the good guys have it Everyone has it maybe but you.
So how does this change the game? And remember, it's great to be altruistic. Just as I was saying before you came on, I was talking to the guy from the Eclipse Foundation.
It's a not-for-profit foundation, and they're really serious about cyber security. But at the end of the day, it's a business. It's the economics of this.
It's about risk, risk management. What's your view on all this? Yeah.
Fundamentally, you hit it on the nail, which is the economics of a attack has shifted, and the economics of defense has to shift. Yeah. And we are lagging behind, so to speak.
What used to take weeks, months to figure out the vulnerabilities, how do I attack, what should be the attack pattern in a cyber kill chain, do I compromise this part first, then I do a lateral movement, where are the IAMs, which provisioning, which privileges, et cetera. Now it's taking a matter of minutes figuring out what the vulnerabilities are and to start building out the exploit techniques around it. So which means the attack, the incremental cost of attack, has significantly decreased, both for one of the mill attackers, if you want to call it, and also some of the experienced skill set individuals.
From a defense landscape, to your point, because it's a business, and this is where we hone in on our collective defense mindset, which is thinking of the analogy that I'll give is you are in a neighborhood, quote unquote, where you have your security cameras, you have alarm bells, all those things that you can use. It would be great if you know that, hey, two streets down the road, there was an incident that was probably happening, and that message came to your front door as well. Quote, unquote.
Based on that front door, your security guard rails, parameters can automatically adjust appropriately without me having to take care of it by myself, which means we have amortized the cost of defense now. So the economies of scale has to be done in a different way, which is based on the collective defense and amortization of cost of defense. So that's how it starts to permeate.
" And so that's how a six-year-old thinks, which is like, okay, I can just dream about it. I can write a few comments or write a few quote unquote prompts and something will happen. And the low-skilled hackers have taken that to heart saying, great, you know what?
I don't have to spend a dime. I don't have to spend a minute more than I need to. I'm going to give the needs, the objective, and let the AI figure it out what it needs to do.
So the economy of scale from your perspective on this discussion as well, it's completely shifted and the defense has to do it in a different way, using every single technique at our disposal within the guardrails of legality and compliance as well. I don't disagree for a second. Now, the other complication here is, a lot of cyber attackers, a good percentage of them are motivated by economics.
But there's also the hacktivists, the terrorists, nation-states doing it for global dominance and so forth, strategic advantage. Is it becoming impossible? Look, in security, I've always felt it's a cat and mouse game, and we're the cats, and we're always a step behind the mice anyway.
But is it becoming just so hard? And then you ask yourself, okay, it's hard. What could we do to keep pace?
What could we do to get even, even if not stay ahead? Well, the only answer I see is we got to use AI ourselves, right? 100%.
So what does that mean for Cyware? Yeah. Fantastic question.
And so I break it up into three areas. One is what happens in today's day and age, which is you get a word, there is a software that got released. After the fact, there is a vulnerability understanding, which ones has vulnerability software, et cetera.
Okay, somebody has now found it, and we can exploit it. Very reactive measure, which means the defense then says, "Oh, somebody found it. " So even before it goes into production, the complete shift left mindset has to come in.
So that's from an AI perspective. The second is now when you're deploying it in runtime and certain things are happening within runtime. Security is still a very much of a mindset.
Tools help, AI absolutely help. But security, the hygiene concept is still a mindset so that you know that there's an enterprise AI risk registry. When you deploy it, you know what are the different models that are getting used.
What is the objective of the agents that have been deployed? What are the guardrails? Is there an audit trail, et cetera?
Because what you can do then is as soon as a, quote unquote, change from the behavior of the agent happens, there's another AI observer which basically does a kill switch of that particular in runtime. So you have that capability to box it. Second is the entire concept of doing your classic scenario model, 24 by seven scenario modeling, and this is where AI really starts to help for the defense personnel as well.
Which is because you know the different parameters based on your own context, your own internal assets, et cetera, and what your other counterparties and peers are doing. You can develop scenarios that you can predict, quote unquote, from a probabilistic standpoint and actually prevent from happening as well. So now you move from a reactive mindset to a proactive mindset.
And this can be done very effectively and strongly via AI. Now think about the very small companies now. They don't have the technical skill sometimes.
They don't have the bench strength. They don't have all the capability to secure themselves. But the larger ones do.
So when you build all of these scenarios and so on, wouldn't it be awesome if you can now send this information across to those smaller entities saying, "Hey, this is the scenarios that can happen. Oh, and by the way, these are the defensive techniques that you should be employing, number one. And number two, I'm sending you an agent that will actually defend it and take that action as well," which is what Cyware does.
And so not only have you now created those scenarios, but you've helped the ones who typically are most vulnerable because they don't have the budget, they don't have the wherewithal, they don't have the technical built, et cetera, to protect themselves. So the entire attack surface is getting protected more and more by leveraging AI as a defensive technique. I love it.
So we're sitting here, we recorded this, today's the 28th, July 28th, right before Black Hat. Sachin, if I have you on by the end of the year, what's changed? I am hoping.
There's a hope for one change, and then there is the other thing that might be happening. The fear of the other . Yes.
The hope is that with some of the alliances that are being happening as well, what NVIDIA announced and some of the other folks who are now participating, and even at the national, at the federal level, that we also participate in those discussions. The hope is that AI at defense will start to scale up very quickly as well. And so you have the regulations also trying to now enforce appropriately in terms of the visibility of what the vulnerabilities are and so on, and the action that can be taken.
So defensives capabilities with AI at scale hopefully grows very nicely and quickly, and that's what I'm hoping for. Which means that the scenario modeling, the distribution, the agents for the last mile actioning, et cetera, can happen very nicely. The fear is that, yes, that tries to take some time, and there are more incidents that might happen based on the adversary attacks that might be occurring over the path.
Whether it's a nation state actor, whether it's just somebody financially incentivized actor, don't know, but yet that's the fear. As counterintuitive as it sounds, I think the more sort of malicious attacks that we see with this are going to drive more of the world to join these alliances, to get serious about this issue, to come up with not just point solutions that any one company, no matter how big they are, can do, but to really have industry-wide kind of response here that moves us to this next level, as you say, could be really good or it could be bad. We've got to keep pushing for good, right?
100%. Yeah. 100%.
Because I think we have a short window where we can drive these things. Yeah, no, there's no doubt, right? The time for sitting on your hands and pontificating's over.
We've got to act. Sachin, I want to thank you for coming out here today on Techstrong TV. Continued success with Cyware.
Let's be back by the end of the year, and we'll see where we are here to there, and hopefully it'll be better. Absolutely, Alan. Thank you so much, and I look forward to our December conversation.
Absolutely. Sachin Jad, CPO Cyware, here on Techstrong TV. We're going to take a break.
We got more Techstrong TV coming, so stay tuned.