Brian Long – Fighting Deep Fakes Becomes a Frontline Cybersecurity Challenge
Following an additional $81 million in funding, Adaptive Security CEO Brian Long outlines why deep fakes have emerged as a growing threat in the age of artificial intelligence. As AI-driven impersonation attacks become more convincing and easier to scale, traditional security awareness and controls are proving insufficient. Long argues that cybersecurity teams must adapt quickly by combining technology, training, and process changes to counter increasingly pernicious deep-fake-driven attacks.
Transcript
Hey guys. Thanks for the throw. We're here with Brian Long's, the CEO of adaptive Security, and they're in the whole business of training end users to recognize phishing attacks and all kinds of other good training things.
And they recently picked up $81 million in additional funding from the folks at Well among others, Bain and Nvidia, and the Open AI fund. But we're gonna jump into exactly what they're doing and how they're planning to do things. Brian, welcome to the show.
Hey, thanks so much for having me, Mike. Good to be here. All right.
Um, some folks are kind of skeptical these days in the age of AI about what we can do to help employees recognize these types of attacks 'cause they're getting more sophisticated. So from your perspective, what is the state of the art these days? What can we do for employees and, and, and how can we win this thing?
Yeah, so for the state of the art, um, I think it's deep take personas. So being able, you know, ai, being able to impersonate an individual with voice and likeness, but also with open source intelligence, uh, about that person, you know, what they do, where they're located, their family members, their job, all that information so they can really, you know, easily mimic that person, uh, in order to, you know, accomplish whatever the nefarious goal is of the attacker. Um, and, you know, in terms of what we can do, you know, number one, I think we need to make the, uh, workforce aware of what this threat is capable of and how quickly it's changing.
I think most people, you know, if you kind of live in the, the security bubble and you see these things over and over again, uh, you know, you, you get a little overexposed and kind of assume that everyone knows about the threat and, and understands it. Um, but, you know, the average person has no idea what the capabilities are, and it's gonna take a long time for us to continue to educate them as that threat changes. So, you know, number one I think is awareness.
Uh, number two is controls. You know, most companies are still adjusting their controls for the remote work world that, uh, you know, still a lot of companies offer, um, and, uh, aren't even beginning to adjust their controls for, you know, things like artificial intelligence and DeepFakes and stuff like that. So I think number one, awareness, number two, controls.
Do these new attacks that are getting more sophisticated have any tells that people should be looking for? I mean, when you're training folks, what is it you're hoping that they can identify? Yeah, look, I, I think over the last couple years, you know, we have seen tells, but, you know, the models have gotten smarter and smarter to get rid of those tells.
You know, it, it used to be things like, you know, look for the eyes or look for irregular, repetitive movements, um, you know, things like that. But the models have gotten better at getting rid of, uh, some of those issues. Um, I, I think if it's a, a prerecorded video, um, it's, it's gotten really good at it for real time generation of video.
It still has some quirks. It's probably 85 to 90% there, but IIE even if you're looking for those quirks, you know, I think in the next 6, 9, 12 months, those are also gonna, you know, kind of disappear. So, you know, I think number one is, you know, going back to process and controls, you know, if someone is asking you to do something that breaks the process, you really need to, uh, think twice and not do it.
Um, you know, number two I think is, you know, when you're asking someone is asking you to keep something secret, uh, you know, or, or, or do something urgently again, um, the, those are kind of the, the telltale signs of an attack. Mm-hmm. Are there things that we can do with AI ourselves to recognize these AI attacks?
And is that gonna be kind of a compliment to the training? Yeah, we, we can look at, at, at Adaptive we try to think like the attackers. So what we'll do is, number one, we will analyze the organization, uh, in order to understand where the greatest threats potentially lie in the organization based on public data that's out there.
So, you know, we'll find everything that's out there on you, Mike, and, uh, across the different large language models, you know, other public sources of data. And then number two, we'll put those into the same large language models that attackers might use. Right.
And from that, we'll see, uh, what the potential ways are that, uh, someone could be, uh, attacked, right? And then number three, um, is we will, uh, then take steps to, you know, either, uh, run simulated attacks, um, you know, using AI in a, you know, safe and secure manner and ensuring all of the data is properly secure, um, and see if someone, you know, falls for one of those simulated attacks. And then that, um, helps us understand where the controls break down and where the organization either needs to train that individual or adjust their controls.
So even in the age of AI investments, $81 million is nothing to sneeze at. What are you guys planning on doing? What's your strategy or what's the area of focus for that investment?
Yeah, look, we've just seen such, uh, huge growth in the, uh, AI based social engineering attacks. So things like deep fakes, deep fake attacks grew by 17 x from 2023 to 2024 with over a hundred thousand attacks just last year. And this year we're seeing, you know, over half of the, uh, conversations we're having with CISOs, we, we hear that they have experienced one of these type of, you know, deep fake attacks.
We're, we're also seeing them grow a lot over new channels like voice, uh, and SMS, you know, outside of email where they may not even have monitoring and things like that. So all of that has, has led us to say, man, we, we need to move faster on our side to protect organizations, and we're gonna invest, you know, that, that new capital in adding people to our, um, r and d team, so we can try to stay, uh, as, as, uh, as ahead as we possibly can. Although, you know, it's an arms race and sometimes you feel like you're ahead, sometimes you feel like you're behind.
Um, but you know, you try to go as fast as you can. How easy is it to generate the deep fake these days? I think early on people were thinking, you know, it require a significant amount of skill, but we also see historically the rise of things like ransomware as a service.
So, am I gonna see maybe, or maybe we already are deepfake as a service. Yeah, look, I, it's, it's so easy now. Um, you know, it can really be done by anyone from, you know, a young kid, an 8-year-old, or an 80-year-old.
I mean, it doesn't matter. Anyone can do, uh, DeepFakes now, and you don't have to be technical, you know, you can make 'em in, in just, uh, a few minutes putting some things together, um, to, to generate them. You know, we have tools in our own platform that allow, you know, people to, to run these sort of simulations, um, with just three seconds of audio and a single image.
So, you know, how you can think about that in your own life is, um, you know, Hey, is your picture out there anywhere? Do you have a LinkedIn picture? And then number two, you know, if I call your cell phone, it's gonna be your own voice on the voicemail.
If it is, then I have everything I need to make a deep fake of you. What is your sense of how proactive are organizations being about these particular threats? Or is it something that they kinda wake up to one morning when they've already been attacked and then they go, we gotta do something about this?
I mean, um, you know, I'm hopeful that maybe we're being more proactive, but historically that's not been the case. So what's happening this time around? Yeah, I mean, I, I, I think that we do see unfortunately, um, a large growth in these types of attacks.
And as a result, you know, we, we, we do deal with folks that are coming in, um, you know, sort of to, to get their medicine. That being said, um, you know, we have seen over 500 customers, um, just this year, um, add adaptive, you know, to their, their set of protection tools because, you know, over, I think over like 80% of them have not, you know, currently had a, a significant incident, but, um, are, are trying to get ahead of it. So I, I do think organizations are recognizing the need to, to get ahead of this quickly, and, uh, we're gonna continue to see that, you know, I I think unfortunately grow, uh, tremendously next year because look, the, the big factors here that, that drive this, number one, it's getting a lot cheaper to run these attacks.
The models are getting significantly cheaper. And then number two, um, it's becoming much more available. com, which is a, a leading provider of large language models, you'll find over 2 million different models that you can access now over 2 million.
So there's a ton of models out there, it's really cheap to run 'em, you could even run 'em on a smartphone these days, right? It used to think, oh, I gotta get, you know, the, the newest and fastest chip and I've, it's gonna take me 10 minutes and then I'll get it. No, a lot of these things run instantly now, and they're really cheap.
Mm-hmm. Um, so what ultimately differentiates adaptive, because there's a lot of players in this training space already, but, you know, if someone comes to you and say, you know, why should we go with you guys? What are you telling 'em?
Yeah, look, I think number one, um, is on the training side, our focus on protecting organizations from these type of AI powered threats, right? So with our platform, you're gonna be able to access hundreds of different trainings that address this next generation threats. Number two, our trainings are extremely specialized by vertical, by role, and by organization.
So you can change anything that you want, uh, within our, within our trainings instantly based on your own organization's needs. Or we also have this really cool tool that allows you to create net new training content in just a couple minutes with ai. So you can say, Hey, I wanna make a new training on, you know, deep fakes for hospitals in this region, you know, four nurses, um, that's three minutes long, and it, you know, and then just a couple minutes later, it'll make a training with all of the custom generated images and videos and animations and audio narration all specific to that audience.
So it just makes it very, very tailored, uh, to the individual organization. And then number two, we also offer phishing that utilizes these next generation channels. So we do realtime deepfake phone call, phishing, um, into help desks into individuals, uh, into voicemails.
We also can do SMS based, uh, phishing simulations that will drive two to three x higher failure rates, then, uh, email. And then we also do generative AI email simulations where it uses more personalized conversational messaging within the email, um, to, you know, sort of test the, the organization's wherewithal that that can often get around traditional email security vendors. Yeah.
So what's that one thing you see people encountering over and over again? It just makes you shake your head a little bit and say, Hey folks, maybe we should be a little bit smarter about this. Well, I mean, you know, where to begin, uh, within, within the security world, but I, I, I think probably the, uh, the, the biggest thing that I, I shake my head a little bit over is when you ask the, uh, you know, a security person sometimes and you say, okay, you know, I understand we're focused on, on an email security and you know, we, we will talk a lot about email security, but what about, you know, the realtime voice or, or SMS, they say, you know, people don't have corporate phones at our company, so we don't need to worry about that, right?
Um, you know, we, you know, people bring their own devices and what they do on their devices is up to them. And that's not my job, right? My job is just to, to secure corporate owned, uh, you know, items.
And, you know, to me, I, I shake my head a little bit at that because I think, look, the, the job, and I look, I think the security people at companies are heroes and, and, and are incredibly important. And, um, I, I think it's, uh, uh, a really, really, uh, important thing at the organization. But I think that security extends beyond just corporate email, right?
I think it extends to really try to protect our team in every channel that they may be, uh, encountering these types of threats. And the reality is that the attackers are surging in SMS voice. And just because it doesn't belong, you know, that that cell phone doesn't belong to the company, that doesn't mean our, our defenses should stop there.
Folks, you heard in here, the attackers are getting not only more pernicious, but they're getting clever by the day. And well, these deep fake things are here, whether you like it or not. Hey, Brian, thanks for being on the show.
Hey, Great to be here. Thanks again, Mike. Take care.
All right, and back to you guys in the studio.