Beyond the Perimeter: Darren Williams on why Anti-Data Exfiltration is the New Cybersecurity Standard
As traditional network perimeters dissolve, the “castle and moat” approach to security is failing against modern threats. In this interview, Darren Williams, Founder and CEO of BlackFog, joins Alan Shimel to discuss the shift from legacy Data Loss Prevention (DLP) to anti-data exfiltration. Williams shares insights from BlackFog’s State of Ransomware 2025 report, highlighting a 47% surge in attacks and how AI is enabling hackers to launch hyper-targeted reconnaissance against high-value sectors like manufacturing and retail
Transcript
Hey everyone. Welcome back here to Techstrong tv. I'm really happy to introduce you to our, my next guest.
His name is Darren Williams. Darren is the founder and CEO of a company called Black Fog. You might have heard of them, if not, not to worry.
We're gonna bring you up to speed. But first, let's welcome Darren. Darren, thanks for coming on Techstrong tv.
It's great to have you on here. Thank you, Alan. Pleased to be here.
All right, so Darren, I, I mentioned you are the founder and CEO of Black Fog. Why don't you give our audience a peek behind the curtain of who they're listening to? How did you, what, you know, no one wakes up one morning and says, yes, it's a good day to start a company.
Right? We, there's something that's drives us as, as someone who's co-founded a bunch and founded a bunch of companies myself, I know this, right? You're driven, you, you're passionate.
Tell us a little bit of your story and where this passion came from. Well, I've always been interested in computers from a very early age. And, you know, I remember building my first computer when I was like 12 years old back in the day, right?
The IBM, xts and all that sort of stuff. So I was always interested in computers, but, you know, my education took me another direction actually. And I ended up becoming, I ended up getting my PhD in pharmacology of all things.
But one of the things I did on the way through was I always did software on the way through. So I always did a parallel task in medicine and then a bit of computer software. And I realized that, uh, I was actually pretty good at, um, software engineering generally, and wrote a few algorithms, put that in my PhD, et cetera.
And then I remember finishing my degree, was ready to get, do a postdoc. And my professor come up to me and he said, Darren, I'm gonna make a couple of observations here. 9 outta 10 computer scientist, and I'm just gonna leave that with you.
So he left that with me as a, as a thing. And I sat, sat on that probably for like nine months to a year. And then I said, God damnit, he's right.
And so I decided, and I went down that direction, and then everything changed for me. Basically, I ended up becoming the, um, director of the multimedia, um, faculty in the University of Melbourne. Um, and that sort of started my career.
And then I ended up going commercial after that. Uh, started my first company, uh, got funded really quickly. That was down in Australia.
And then from there, um, I ended up selling it within the first two years at the peak of, you know, the market to a company called Quest Software based in, uh, Irvine, California. Sure. And then basically then after that, uh, after about a year with those com, that company, I decided, decided that, Hey, I'm bored.
I need to go do something else. So started my next company, which this is how it gets into cybersecurity. But basically we, I got, um, I started a company called Lifetime Software, and it was acquired by a company called Absolute Software, which was a cybersecurity company still is actually.
Mm-hmm. And that gave me the, uh, concept actually originally for Black Fog as it stands today. We were, so it is interesting, absolute software as a company, they were really all about, um, uh, bios, persistence.
So they had a technology, which is pretty cool, where it sits in the bios and was able to protect your laptop from theft. And we thought that was a really good idea. They are quite our company.
And then while we were there, we think it's interesting that no one worries about the data. Everyone's just worried about the theft of these very expensive assets. And so instead of ensuring them, they would buy the software, which would protect the laptop.
And then we thought, why doesn't anyone worry about the data? Because really that's all people really care about if you boil it down. And so I sat with that for a while, and then after my transition, they're there for two years.
I said, why don't we investigate that concept? And that's how we come up with Black Fog. So it was all about anti data exfiltration or stopping data flows off the device.
'cause traditional cybersecurity is defensive based technology where it's always about the data coming into the device. You know, you see a bad guy coming towards you, you try and take him out from, from the front. But honestly, most of the techno, most of the attacks and ransomware we see, it's all about taking data out.
That's what they used to extort you, that's what they do to steal information generally. And so that, and now, and now with shadow ai, it's a whole different concept altogether. So that's how, how Black Fog started effectively.
Great story. You know, I, I think what you described, I I've seen it firsthand myself. We, we, and not just security, but almost the whole tech stack focused on the platform, right?
Mm-hmm. Yeah. Form factor platform.
Then it focused on the app. It was all about how can I break into, how can I prevent someone from breaking into my app, whether that app was on my local device or in the cloud buffer overflows script, you know, it was about breaking into the app and, and for a long time we, we forgot that it's all about the data. Stupid, right?
The data is the crown jewel, the data is the value, and, and then Correct. Sometime around COVID, I think we started seeing a, a reemergence of emphasis on protecting the data. Not, not the app, not even the platform, the data.
And, and, and you can separate the data from the platform and the data from the app, right? And, and, and try to try to do that. But, you know, Darren, back in, in the day, and I, I've been in security 30 years, there was this whole concept of what we call DLP, data loss prevention, right?
And, um, quite frankly, it never worked so good, right? I mean, a lot of people, a lot of people have thrown their hat in there that yeah, a lot of people feel their In. Yeah, we talk that a lot And A lot of interesting because the concept though is actually good, but Oh, yeah.
No, but what we find in practice is I've never come across an organization that's implemented it successfully because it's too difficult. Now, the concept is great, but in reality, what happens is nobody has the manpower or resources to staff the amount of data classification that needs to be done to make these things work. Yep.
And it also sits on the edge of the network. So what happens when I go home or in a, in a hybrid work environment, which everybody is these days, it doesn't really play out, Right? What, what, well, with the death of the perimeter, right?
Remember the old olten castle kind of thing? Exactly. There is no, no perimeter, you have no edge, you have no DLP.
Exactly. So how's Black fog difference? How's bewa different?
Yeah, so, so we lo we always appreciated the concept and the theory behind DLP, and we thought, wow, it's interesting. Why haven't, why hasn't anyone solved all of the major problems? And first of all, it needs to be on the end point itself.
That's where the game has played. That's where the data is stolen from. Why don't we do that?
Why don't we auto classify the data to begin with? And what we are doing is working at the packet layer, watching the data flow off the device, and we're using a lot of ai, you know, and, and ML algorithms to actually monitor that data flow. So without actually having to go inside the packet, which is a breach of security in its own right, we're able to actually see the intent and the, and doing the intent analysis on that, where it's going, what it's doing, and why it's doing it.
And effectively, that's what we do at Black Fog, and we stop the data, the unauthorized data league in the device. So we've able to solve all those problems of DLP, basically. Excellent, excellent.
Um, And the management becomes easy too. And is this sold? So is it like an agent that goes on the device?
Is it sa Yeah, It's a piece of software that sits on your device. Exactly. And the other, the other important concept that actually is often overlooked here is that we do everything on the device.
We do all the algorithmic detection on the device. We don't send it up to the cloud. Like there's most EDR vendors that you'll come across these days.
They're all sending it back over to their cloud. So you're losing your data. So where's the attack vector now?
The attack vector is actually looking at where the data is. There is no coincidence. Let's just say that VPNs are the most attacked vector these days, because guess what?
That's where all the data's flowing. So they're, all the attackers are always gonna look for those, um, places to expose. So we're able to minimize that effort by doing it on the device.
And we only show you when we block something, then we send that to the cloud and say, Hey, look what we just did. Got it. So that's how we just Ourselves.
So minimizing the attack surface as well. Exactly. And that's what we're all about.
And it's also about privacy too. I mean, I don't really want to be under all these other, well, there's a lot of governance laws that are still being implemented, don't want to exposure private data. We don't really care about it.
Frankly, what we care about is stopping the bad guys. Ultimately, we don't wanna see all your data. It's a lot of data.
We're gonna manage it. So there's all sorts of problems associated with that too. So it allows us to go into highly secure environments like government and, um, finance without the problems associated with saying, Hey, we have your data.
How are we gonna ma manage and handle your data? We don't have to deal with that either. Sure.
So, excellent. Good for us too. Excellent.
Darren, for people who maybe want to get a little more information, what's the, your URL for the black fog site? com, as just as it sounds. So it's pretty easy to get the data.
Yep. All let us, let us kind of pivot, if you will. And you guys recently released your state of ransomware 2025 annual report.
Correct. Look, we're coming into the RSA season RSAs in about another month, month and a week. I'm sure we're gonna see a bevy of reports right.
On breaches and ransomware and vulnerabilities and everything else. Mm-hmm. If you don't mind, give us sort of, you know, the key findings of, actually before we get into the key findings, how long have you been doing this report?
Why do you do it right? What, what should people take outta that? Uh, we've been doing it for 2000 and since 2020.
So we've been doing it for quite a long time before anyone was really doing these types of reports, actually, specifically on ransomware. Actually, the reason we did it was actually we doing it for our own internal research purposes anyway, because we change our algorithms dynamically based on what we see out in the, in the world. And so that's why we produce these reports.
So we decided, well, why don't we just publish this so everyone can get benefit out of it and sort of share back to the community if you will as well. Because a lot, there wasn't any, um, really recording of these stats before us. And so there are people that are now trying to replicate this, but we've got the historical data, we've got a lot of data points on this as well.
And we like to see the trends. We like to see what's going on in the glo, you know, macroeconomic view of the world, if you will. And that's why we publish 'em.
So onto the report itself, I mean, some of the, we've seen the dramatic increase in, in attacks as everybody has every year, but this year we saw, you know, 47% increase over 2025, which was a record in itself. Um, so the attacks have gone up, but, um, I mean, everyone's sort of used to that these days. But what are some of the bigger trends we're seeing?
I would say it's really the focus on industry specific targets or sector specific targets that we've never seen before. And we sort of attribute that to the use of AI and the reconnaissance that is able to be done. That wasn't possible before.
So in the old, the old mechanism was basically just attack as many as you can, look for the weakest spots and extract the data and extort them for the, you know, for the, for their information. And now we're seeing a concerted effort by these attackers to go after industries, which are very well resourced and have a lot of money behind them and go after specific targets. Manufacturing's a great example this year.
So this year we've seen a concerted effort to attack the manufacturing sector. And, uh, we've seen that with the great examples, um, like, um, the, um, marks and Spencer attack, uh, in the retail sector as well. So there's been some really, really big breaches, and these have been devastating.
We've, we saw that also with Land Rover, the Range Rover attack. That was a really big one as well. So really targeted.
And the reason they're able to get in a lot of the time is they can easily use AI to really do some reconnaissance work on targeting individuals themselves. We know you're interested in cars, or you're a pat guy, whatever it happens to be. And we will know you'll click that link, which will generate the payload that we need to really go in and attack that organization.
So that's one of the other big things. And then the general use of ai generally, people often think about AI for how we can use it to make our company more efficient, but people fail to realize that the bad guys also have access to this technology. And they're utilizing it really well by developing really great new algorithms.
So we're seeing some really efficient attack vectors that we've never seen before. And what they're doing is they're analyzing the code bases of all the stuff that's been effective and consolidating and into centralized, um, code, which can be deployed for attack purposes. And we're seeing bigger and bigger trends like that every day.
And I think we'll continue to see that throughout the year. Yeah, I mean, look, I, I think as you mentioned, ransomware really started to pop onto our horizons around 2020 COVID, right? All of a sudden it, it really just took off, blew Up, Blew up.
And then, you know, we've seen some interesting things happen to ransomware over the last five, six years. First of all, cyber insurance companies, you know, for a while there was sort of the primary, uh, negotiators, if you will. I will, I'm trying to get ransom data back.
And, but they also became the people with the big stick, right? Who, Hey, if you want us to ensure you, you're going to need to have a black fog. You're going to need to have correct some anti somewhere.
It's still, yeah. And, and that was, you know, it's not a bad thing. Sometimes you need a big stick to get people to, to do things mm-hmm.
To do the right things for themselves. Um, but then on top of that, of course, we've seen ai, right? And ai, uh, uh, you know, just increases attack surfaces, make, makes this thing at scale.
The bad guys use AI as well as we do. And it, and it just, it blows that up. But the other thing, and this, I guess a good thing is that people are understanding, hey, with ai, not, not just with ai, with ransomware, I, it's imperative that we have a clean data set somewhere that it can't be reached, you know, through our regular network.
So that worst case scenario, we're not, we, you know, we, we can't just throw it out and start over again without that clean data set somewhere that's really insulated. And I think more and more people have done that, right? They, they are, I, I hope they are.
Anyway, I wonder if that comes out in your, in your, uh, report and in your surveying and, and research. Are people making sure that they have a, a clean quote unquote clean set of data that is untainted or would be untainted in a ransomware, uh, attack? Um, we're seeing mixed, I would say, I think it's still very early days as far as AI goes in general, you know, corporate America, I mean, we are seeing some significant investment by CEOs.
We're saying, we are hearing things like this. We CEOs know and they've got the message, AI is the future. And so they're saying, you know what?
Here's $3 million. Let's go implement some AI inside the company and get that 30% efficient so I can get the top line revenue growth. And so that's what's going on.
And so with that, what happens is that we're seeing very broad rollouts in all sorts of departments because they've got access to money to go and buy some new tools, for instance. But they're bypassing the security department and the CISO's office and director of IT. And they're saying, and the CEO saying, I don't care.
I want 30% growth. My investors are asking for 30% growth, go work that stuff out for me, right? So while in the meantime the racehorse is out and they've gone and implemented stuff and they're trying to pick up the pieces.
So as part of picking up the pieces, I think your point is valid that people should be looking at clean rooms and, and really protecting their data, but they have to try and protect what's actually going on in their org and have some visibility. Because frankly, most of these people don't know what's going on inside their business. They don't know how many people are using board versus chatt PT versus office, you know, the, the copilot stuff.
It's a, it's a real minefield out there. So we're seeing a lot of trauma in IT departments because of what the top level executives are doing to the organization. And if you then extrapolate that, now we're only in the very early stages of this phase, but things like, um, OpenCL are a great example, right?
OpenCL is the, um, a, a AI agent that people can download to their laptops and actually automate their entire life. They can say, you know what? I haven't spoken to Alan in about three weeks.
You probably should send him an email. Would you like me to do that for you? Oh, and let's, maybe we should have a beer session tonight.
Could you, can I organize that for you? And so, but what you're not seeing here is that yes, it sounds like a fantastic tool, but what it's doing is opening up channels of communication to all these LMS out there that, and is basically connecting all the data to all the other data on your laptop and then placing it in an open folder on your, on your computer somewhere, which attackers can actually access. So there's all these MCP architectures out there, which is their API protocol that they talk between each other is being totally exposed.
And so we are not there yet. I'm not saying that you need to worry today, but I would say in six to 12 months, this is gonna be probably the biggest thing we deal with. So it's interesting area.
Absolutely. Uh, we're, we're running low on time, but there was one other metric I saw in the report that I wanted to bring up, and that is that 86% overwhelming majority, eight, eight outta 10, almost nine outta 10 of these ransomware attacks went undisclosed. Yeah.
We're seeing more and more of that, Alan. It's a really good pickup. Um, we, we used to think that was going to go down.
So you'll remember about y two years ago now, the SEC put out a regulation which said that there was mandatory reporting Yes. If you had an attack. And so all these public companies started doing that.
But then what happened was there was an increase in volume of attacks, and then all these small businesses that aren't under those, uh, guidelines decided that it would be better to save their job than disclose that we had an attack. Because then there was all these repercussions for these IT executives to say, it doesn't, I don't want it to be on my watch. And so they weren't disclosing, and it's still not disclosing as a result of that.
And so I think there's that undercurrent going on that we're not actually seeing, um, that's why we measure these numbers in the first place, actually. Uh, people are just trying to protect their jobs. And if they can hide it under the map and maybe pay these guys off, then maybe we don't have to tell anyone it ever happened in the first place.
And that's what those numbers reveal to us. Got it. Got it.
It's scary, but that's what's happening. It's a scary world, my friends, you know, it's, it's not a time for, uh, unfortunately, it's the world we live in, in many, many different ways. Darren, we're about outta time.
com is the website for the company mm-hmm. Off the front page. Maybe they can get to this report.
Yeah. For, it's on the header right in the below the first, uh, pa first section. So Yeah, for sure they can just click on it and, uh, download the report.
I love it. Hey, keep up the great work. You know, sometimes, sometimes toiling in cybersecurity feels unrewarding, right?
'cause you get these numbers, 49% more attacks, a hundred, you know, year over year kind of, and, and you just, you feel like sometimes you're shoveling sand against the tide. Right. But There's always a new company, Alan.
Every day we see another one, so well, right. Well, there's someone who's right. Who thinks they've got a better mouse chop.
Exactly. But The mice keep, keep kick us. Getting smarter too.
Does, you're doing exactly right. Good point. And, uh, but you know, it keeps us honest.
And, um, you know, I wouldn't be doing anything else. I enjoy getting outta bed every day, and that's all you can hope for. Better than the alternative to her.
Exactly right. Thank you. Come back on and keep us posted.
Okay. Will do. Thanks Alan.
Thanks for your time. All right. Darren Williams, founder CEO of Black Fog here on, uh, tech Strong tv.
We're gonna take a break. We'll be back in a moment.