Behavioral AI Beyond Email Security
Behavioral AI security is expanding beyond email. Mike Britton, CIO of Abnormal AI, joins Alan Shimel to unpack this week’s launch of Identity Detection and Response, AI Security and Infiltration Prevention. Furthermore, Mike explains why identity is the new perimeter and how baselining works even better on non-human identities.
About Mike Britton
Mike joined Abnormal AI five years ago as its first CISO. Consequently, he now oversees corporate IT, threat intel, cybersecurity and compliance as CIO, with 30 years in the security trenches.
Inside the new behavioral AI security lineup
Abnormal AI started in 2018 with a bet on behavior. As a result, the company redefined email security by baselining what normal looks like and flagging everything else. Meanwhile, that same approach now extends to identity, shadow AI and hiring fraud.
In addition, Identity Detection and Response expands account takeover beyond email, AI Security surfaces shadow AI usage, and Infiltration Prevention plugs into email and ATS systems to stop fake applicants before they ever get onboarded across your team.
Why behavioral AI security matters now
Meanwhile, an organization with 500 employees can carry 5,000 non-human identities in the agentic AI era. Consequently, machine and agent identity baselines get simpler in one way, because agents never travel, get sick or take vacations.
Explore more cybersecurity coverage and the latest Techstrong TV interviews. Furthermore, early access is open now with general availability on August 3, and the Abnormal team will be at Black Hat with booth demos and meeting spaces. Learn more at abnormal.ai and stop by the booth if you are on site.
Transcript
Hi, everyone. " My next guest is Mike Britton. Mike is the CIO at Abnormal AI.
" It's great to have you on here. Thanks for having me. My pleasure.
Mike, before we jump into Abnormal, and you guys just did a big announcement this week, let's hear a little bit about you, how you came to be the CIO over here at Abnormal AI. Yeah. So I've been at Abnormal for a little over five years now.
I started out as our first CISO and then a couple of years ago moved into the CIO role, where I oversee all of our corporate IT, threat intelligence, cybersecurity, compliance, and probably a few other things. Very cool. That's a much more common path than we used to see.
I'm in security 25-plus years myself, and look, I remember before we had CISOs, but we're seeing a lot of CISOs become CIOs. Like a combined one person holding both titles and both responsibilities. You don't see it much going the other way, right?
CIO becomes CISO, but you do CISO to CIO. So you came into Abnormal as the CISO, basically? I did.
So I've been in security for 30 years now, and my last company, I was in financial services. I was the CISO of that company. I was there for 16 years.
So I've been a CISO for about a decade, and then I've been CIO for the last two years. Love it. Mike, we were talking off camera, I would say a lot of our audience has heard of Abnormal AI.
The company's been around a couple of years, more than a couple of years. But I think a lot of people have heard the name, but they yet may not be totally familiar, and then others may not have even heard of Abnormal AI. So if you wouldn't mind, share with our audience, what's the Abnormal story to you?
Yeah, I think it's a couple of things. So first, we're known as an email security company today. The premise behind the company when it started in 2018, was that attackers had changed their methods and methodologies when it came to attacking organizations through business email compromise, phishing, and really a lot of the tactics and techniques that attackers had used previous generations, the secure email gateway, the legacy email security companies, had done a good job of stopping.
So as always, attackers pivot, and they change their techniques. And that's where Abnormal came in. They decided, hey, let's look at behavior as a key component to stopping attacks.
Let's leverage AI and baseline what normal behavior is, and then stop everything else that's not normal. I love it. Hence, Abnormal.
Absolutely. Very cool. Mike, before we jump into this week's announcement, how can people get more information on Abnormal?
What's their best route? ai. That's our website.
We have an incredible website that has a lot of information. It's got videos. It's got information on our products, the company, the leadership team.
All of those things are right on our website. Cool. All right.
So this week, you guys made a big announcement, right? Expanding beyond email, behavioral AI, full identity surface. These are words we're hearing, but attach meaning to them, Mike.
What's really behind the announcement? Yeah, I think when you look at the announcement, and I'll go back all the way to the company's founding. The two founders came from ad tech.
They're AI guys. And the whole premise around ad tech is understanding human behavior to deliver targeted ads. And when they created Abnormal, obviously, email was the first problem to go solve.
But really, it was more around just how do we understand behavior? How do we solve cybersecurity problems? How do we solve business problems, understanding behavior?
Email is the natural launching point, but we're now at the point in our company and some of the problem sets we've heard from customers, that we're expanding that behavioral AI approach to other problems to stop. Email is still a huge problem, but you often hear identity is the new perimeter. We've seen problems with everybody's in some form of AI transformation, and we also have this massive problem with remote hiring, where fraudsters and cybercriminals are leveraging that vehicle to gain access to companies as well.
They certainly are. Some of the stories you hear are just crazy. But let's get specific about this release, right?
There's three new products within this announcement. Can you go over each one with us? Sure.
To start with, we have our identity, detection response product. Really, we've had an account takeover product, which is an identity product for several years now. And really, this is expanding that beyond just email account takeover.
So if you think about it, most organizations leverage SaaS. They have an identity provider. Attackers They're not breaking in, they're logging in, and really this is an expansion of that existing product to solve a lot more use cases.
On top of that, part of this product is also looking at the posture management of your identity. It's great to detect bad things happening, but we also want to be preventative in nature and help the customer make sure that their identity provider, their identity system is locked down and properly secured. So that's the identity product.
Like I mentioned, AI security, every organization is using AI today. We dealt with this problem of shadow IT for years in security, and now it's moved to shadow AI. So, I've lost track of the number of new AI software companies that pop up every single day, and the barrier for a user to sign up and use these products is minimal to none.
And so as a security leader, I have very little control over what users are in my organization, are signing up for new services, what data is going over there. So this tool has helped to get some control over that, get visibility into what AI solutions your users are using, get control over the proper way that they're using the sanctioned AI tools. It's just really giving you that visibility and behavioral approach when it comes to AI.
And then finally, infiltration prevention. Like I mentioned earlier, North Koreans, they're not the only actors, but they're the ones dominating the news right now with the remote IT worker. And really our goal here is to plug into your email and your ATS, your applicant tracking system, and help your recruiters, help your security team identify those fraudulent and fake applicants before they ever get onboarded into your organization.
I love it. Mike, all three are available now? Early access for the infiltration prevention and then the remaining ones will be available, the other two will be available August 3rd, so next week.
Very cool. That's not coinciding with Black Hat, is it? It might just be.
Okay. We'll be out there, so maybe we'll cover it while we're out there. If you're out there, we'll say hello.
I'll be out there as well. So if you're already an Abnormal AI email customer, is this a separate type of product line? Yeah, these are additional modules and products.
As with the traditional Abnormal email product, it's super easy, lightweight to turn on and do a proof of value. And they'll be available starting next week. I think that's one- Very cool ...
been one of the more powerful things about Abnormal is you plug it in, turn it on, and it shows results- It works ... almost immediately. So the same can be said of these products as well.
Mike, I want to return to something. We got a few minutes. I want to return to something you said a little bit back about identity being the new perimeter, and of course this plays into this whole full identity surface thing.
Look, I agree with you. I really thought identity and access management was the killer cloud security app for the cloud. Right?
I grew up, if you will, in the age of perimeter and moat and castle defense security. Cloud security kind of changed it, and identity became the whole, that was the front line, if you will, the new front in the war. With AI now though, we're seeing identity kind of stretched.
It's not just human identities, right? It's machine agent identities. We already had sort of machine identity, human identity, now we have agent identity.
How does the Abnormal product line kind of acknowledge, if you will, this is the new reality and work within that? Yeah, so obviously the human identity piece is still core. Yep.
Humans are subject to social engineering, they're subject to those type of attacks. But you're 100% spot on with now in agentic AI, an organization that may have 500 employees could have 5,000 non-human identities. And what's harder is, at least with the human identity, there's something a little more tangible.
You can see it, you can touch it, you can easily model it. With non-human, it's a little bit more nebulous. It's a little bit harder to see, harder to understand.
One would also say that it's also much easier to baseline and understand normal patterns and behavior because it should operate in a similar fashion each and every time because it's programmatic not human in nature. So your non-human identity is not going to take a vacation, it's not going to travel, it's not going to be sick. So in that aspect, understanding it and baselining it is a little bit more simple, in that regard.
Absolutely. Hey, Mike, for folks who, a lot of our audience is going to be at Black Hat. Stop by the booth, they could maybe get demos and peeks into all of these things?
100%, yeah. We have a booth, we have meeting spaces. Would love to see everybody there next week.
We have demos right at our booth. Come on and come check out all of the products and if you're not an Abnormal customer, come check out our email product as well. Absolutely.
And at least it'll be inside in the air conditioning and not 115 degrees there. Yes. We'll be there.
I'm going to stop by and say hello. But anyway, Mike, it sounds like Abnormal is, as it's always been, moving forward, right? Offering protection against the latest threats.
And I'm happy to see this. I'm interested to see how these three pan out in the market. I want to thank you for coming here on Techstrong TV today.
It was great. Thanks for having me. All righty.
Hey, Mike Britton, CIO for Abnormal AI. Moving beyond just email security into full identity surface with behavioral AI. You're watching Techstrong TV.
We'll be back in just a little bit.