How CISOs Should Plan AI Budgets for 2027
AI security investigations are reshaping how CISOs plan their teams and budgets. Alan Shimel welcomes Dov Yoran, Co-Founder and CEO of Command Zero. Furthermore, the two longtime friends discuss AI adoption, resourcing and what 2027 planning should look like.
Three decades of building security companies
Dov started at Riptech, one of the first MSSPs, which Cisco acquired in the late 1990s. In addition, he helped launch the Cloud Security Alliance and co-founded ThreatGRID, also acquired by Cisco. He later co-founded Polar Security, an early DSPM company that IBM acquired. Consequently, Command Zero is the latest stop on a long founder journey.
Two camps of CISOs
Dov sees one camp moving tier one triage to AI and shifting budgets fast. Meanwhile, the other camp is cautious and leans harder on human judgment. Therefore, he argues the right answer is a planned mix of both. AI handles the volume and the mundane work, while people focus on judgment and creativity.
He also warns against deploying AI aimlessly. As a result, teams should measure investigation speed and response times before and after any pilot.
Planning for 2027
Dov expects hiring to grow in some roles and shrink in others. In addition, he warns that cutting tier one teams could leave no bench for future senior investigators.
How Command Zero speeds AI security investigations
Command Zero pairs a knowledge base of investigative questions with a federated set of data sources. Consequently, every lead gets run down in a consistent, structured and governed way. Furthermore, the platform removes toil like timelines and reports for in-house SOCs, MSSPs and MDRs. Leads can come from security alerts, HR cases or threat intel. As a result, teams get faster, more predictable and more consistent outcomes.
Leaders weighing AI security investigations should start with structured pilots and clear metrics. Explore more cybersecurity coverage and the latest Techstrong TV interviews.
For more information please visit commandzero.ai
Transcript
Hey everyone, welcome back here to Tectron TV. I'm really happy to have this next gentleman, and I use that term loosely, my friend Dov Yoran. I know Dov now, I don't know, five, six, seven, ten, I forget how many years, but a long time.
Dov is a long-time player in the security cyber space, as we call it now. We used to call it security. And he's started companies, he's worked at companies.
He has a great background. You're going to hear all about it. But let's say hello to Dov Yoran.
Dov, it's great to see you. How are you, my friend? Oh, I'm doing great, Alan.
Thank you for having me. Finally made it happen, so I'm excited to be- Yeah, we were talking, and we weren't quite sure how the both of us, being as incompetent as we are, were able to get together on a calendar, and then we found out someone else did it for us, so it's all good. Dov, before we jump into Command Zero, and we're going to talk about CISOs and AI adoption and resourcing and so forth, let's talk a little bit about Dov.
I kind of said you've been in security, you've started several companies. Give people a sense of your journey. Yeah.
So yeah, the last 30 years, I kind of grew up in this space. Early on at Riptech, one of the first MSSPs in the late '90s. I remember.
So known as Black Badger. Oh yeah, it was a blast. Mm.
Worked with family and lots of friends. Acquired by Cisco, spent a few years globalizing a lot of the operation, go-to-market activities. Then ran an incubator back in New York, so did things like helping launch Cloud Security Alliance and a number of other startups that had good, successful outcomes.
I then had two itch to do the operator thing again. I had two startups. I co-founded ThreatGrade, which was a sandbox on steroids.
What could happen if you could automate reverse engineering, creating a lot of threat content from large dynamic analysis? We were acquired by Cisco. Spent half a dozen years at Cisco.
It was an amazing outcome, really sort of the keystone to the whole portfolio. And then another startup I co-founded, Polar Security, which was an early DSPM, data security play, that IBM acquired. And then a little under five years ago, about four years ago, we started Command Zero on this latest journey.
So it's been a little while. Has it really been 30 years, Dov? Yeah.
Well, late '90s, yeah. It's quite a while. I always thought of you as the younger one.
I am the younger one. Now we're all getting older relative and- I guess so, it's all relative, man. Wow, that made me feel older than I am.
Anyway, talk to me. Let's hear about Command Zero. You say it's been about four years now.
Yeah, super excited. So we raised a good seed. We have an awesome group of investors around the horn, knowing Dries and Horowitz on down, a number of angels that have participated.
But basically, it's now the time. What could we do if we automate an investigator, an analyst? And in this modern day of agentic workflows and AI and LLMs, the volumes of attacks are obviously increasing with sophistication and maturity.
But now there's finally tools that can help the defender move forward and sort of combat a lot of these offenses. So we've built an investigation platform that thoroughly runs down, in a consistent way, all of your investigations and those needs and then sort of frame it up in a repeatable format. So we're really excited to have a few years of development and then go to market and super excited to share the story and grow from here.
Absolutely. Hey, let me just get it out of the way. Command Zero's website?
ai. ai, okay. Just wanted to make sure we get that out because I'll forget.
So Dov, you've got AI in the domain name. Four or five years ago, were you thinking AI when you were putting Command Zero together? We weren't thinking the name AI, but we were doing very much thinking AI things and sort of leveraging and pushing the envelope around ML.
" The light bulb went off, and we were able to sort of refactor that early thinking. It was definitely a big swing and a large play that we were gunning for. Right.
And so very much so that vision has played out. What could happen if we can leverage agents in and around the environment? And we called it some things that are slightly different back then, but exactly on par with how it's evolved.
So yes, couldn't have been happier with the progress. Excellent. Since that ChatGPT moment, as you called it, what was that, like November '23 or something like that, I think it was.
Yeah. About a part of '22. There's been a lot of AI water under that AI bridge, right?
Every day, and believe me, it's my life here. We report on it, we video on it. Every day, it seems there's more and more around AI.
And an interesting thing is, once again, security finds itself right in the middle of the mess, right? Yeah. But so much of what's going on in AI represents, as you mentioned, real threat.
In the wrong hands and with the wrong instructions, it's a problem. It's an existential problem, perhaps. But at the same time, I'm the optimist who always thinks that the glass half is half full.
It gives us tools and capabilities we never had before either, right, at AI scale. This is where we are at this moment in time. We've got CISOs out here, and they're looking at also the glass half full, the glass half empty.
What do you say to them, Dov? It's both. AI is an incredibly powerful tool if harnessed correctly.
It can be incredibly wasteful if just kind of thrown at it and completely allowing it to run itself, so to speak. Right? So it really is, in my mind, both.
" It's both. AI is powerful for the volumes, for the mundane. We're looking at large datasets.
Supporting those monotonous tasks and enabling the human judgment and human creativity still rings true as a powerful combination. So I see it as really as a combination of both, planning between the two of them, how the two of them can fully leverage each other. Yep.
Someone once said, not about AI, but there's two kinds of people in the world, the people who this and the people who that. The same can be said about CISOs in AI. There's two kinds of CISOs in AI.
They fall into two different camps. If I had to ask you to describe what those camps are, what are they? Well, a little bit from kind of just what I've mentioned around those that are fully adopting it, right?
They're moving tier one triage in AI. They're shifting budgets over, right? They're all in on that.
Right? And the other camp is probably a little bit more cautious. Right?
They're practitioners looking to sort of hold back on not only full deployment, but on leveraging that human aspect to it a little bit more strongly. And it's looking at both, right? I don't know if headcount is the right unit, or is it more thinking about planning, right?
Planning the work. Like which decisions need a human aspect to it, and which decisions or which tasks need an agent to run through that? And I think that's fundamentally what I think is the strongest ...
element, right? Funding AI for those repetitive works, those investigation tasks, keeping the people, leveraging them, and potentially redeploying them or expanding their scope in the things where they do have impact, right? Pointing them at the judgment elements of the work and being able to tackle that.
So, I think that's the, in my mind, that's the right framework to think about it. And in my mind, you can't be a little bit pregnant, right? I really feel, look, a healthy dose of skepticism is a good thing, right?
We shouldn't blindly just go with everything AI claims to be able to do for us, or, but I don't think this is a time to be passive or half-measured. I really think that, look, this is a train that left the station. The question is, is it a runaway train or not?
But the train left the station. Yeah. And if you think you're going to still leave some resources back at the station, those are wasted resources.
That's where I sit in my opinion. It is true, but running down the path of just deploying it aimlessly is also counterproductive, right? The speed without having a proper evaluation.
I think Gartner talks about 15% of SOC pilots with AI agents will see measurable gains, but without structured evaluations. Right? Yeah.
So, aligning in sort of a SOC perspective, an operations perspective, right? How quickly they're completing investigations. Your mean time to detect, mean time to understand and respond.
Measuring these things before fully understanding how you're deploying AI and making those repeatable and structured, and then sort of measuring your post-pilot and seeing if it measures up and you're seeing the benefits. Because not all, quote-unquote, AI deployments are the same, right? There's lots of ways to leverage that within the environment.
And our solution has elements of AI, incredibly so, but it's how we deploy it and the intent around our investigations that make it less confusing, less noisy, and kind of drive to the answer quicker. So let me dive into this here with you. So here we are.
It's October, right? It's going to be October, let's say September. For sure.
People are planning for 2027 right now. Budget meetings are starting to happen. Plans are starting to be laid.
As the CEO of Command Zero, what's your advice? I don't care which bucket or which camp these CISOs are in. The go slow or the full speed ahead or whatever you want to, however you want to characterize them.
What's your advice to them in planning your resources and budgets and so forth for 2027? I think it's being able to properly plan the teams, both headcount needs, the workload needs, with what the expectations are for the business, and sort of making sure you're allocating the right resources. I actually think there's going to be an expansion of hiring for certain roles and- Mm-hmm ...
a contraction for some others, right? Leveraging AI, sort of finding and utilizing the volumes around pen testing and red teaming, but still leveraging the human aspect around scoping and valuing the findings and chaining attacks and sort of reiterating continuous testing. Similarly, around security engineering and red teaming, right?
These are kind of new categories, more testing prop injections and agent tool abuse, right? And modeling data leakage, right? So leveraging those kinds of elements together.
So a lot of folks on the security operator side and the CISO side are thinking about shrinking their teams, right? Their tier one teams in their SOC. They're looking at the data analysis and how they can escalate alerts and triaging from that, right?
I think those roles can potentially evolve than going away, right? How do you better empower those teams to continue to grow them? Because one funny thing I always think about is down the line, five years from now, where are your more experienced investigators going to come from?
Right? Right. Your tier two or three bench, if they don't have that training ground and the proving ground in the earlier part of their career.
So it's an interesting dynamic to see how those play out. Let's get Command Zero specific. How does Command Zero help me with this?
So what we do is we have a knowledge base of investigative questions, and we have a federated ecosystem, if you will. So we have access to different data sources, and we have this preempted knowledge of questions that we want to ask those. And an investigation, whether it's a traffic accident or a cyber investigation, it's always at the root the right question at the right data source, right?
What happened, who, what, when, where? And so from our standpoint, it's, yes, that alert triaging from all your security products could be one lead. It could also be leads coming from human or HR or other kinds of human-generated investigations, or it could be threat indicators and threat intel.
Wherever that lead comes from, taking that lead and running that to ground zero in a consistent structured framework so that you have predictability with your AI. You have a governance model. You have a system of record in defending why you took certain actions and why certain conclusions were made.
So for your tier one team, right, guiding them, training them, educating them on how and what they can do to, and the right types of questions to ask on these different data sources to prove that model and to prove that investigation. For your more experienced team members, right, getting them out of the toil of collecting datas and information, creating timelines, generating reports, the bane of everyone's existence, right? Reducing that time to understand, but more so making a fully comprehensive action out of it, including not only threat hunting and being proactive, but also remediation next steps.
So all of those things can be combined in helping the investigation team, the SOC team moving forward. And by the way, whether you have a SOC fully in-house and you have the luxury of employing dozens of analysts to a smaller portion of just two or three folks that just look at escalations, and you're outsourcing to an MSSP or an MDR, they're both leveraging and can leverage that benefit to get to faster, more predictable, and more consistent outcomes. So we're pretty excited about not only deploying AI, but deploying it wisely and as part of a bigger goal, as part of a bigger platform that we offer.
Excellent. I love it. Hey, Doug, we're over our 15 minutes, but that's okay.
Okay. I enjoyed just having you on here and talking.