Hyperautomating Security Operations – Leonid Belkind, Torq
Torq announced a powerful evolution of the Torq security hyperautomation platform: Torq Socrates, cybersecurity’s first tier-1 analysis AI agent. Torq Socrates is designed to transform security operations by using AI to hyperautomate key security operations activities, including alert triage, contextual data enrichment, incident investigation and more.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
Um, I have a first time guest on with us today. His name is Leon. Leon need Belkin, and I hope I, I pronounced it right.
Leah, need is the co-founder and CT over a company called Torque. And you may or may not know Torque, but Leah need's gonna tell us all about it. But first of let's hear a little bit about him.
Hey, Leah, need, welcome to Tech Drunk tv. Thank you, Alan. It's a great pleasure to be here.
It's our pleasure to have you. So Leah need, you know, I kind of, I set the table for you. Go run with it.
Tell us about you and tell us about Torque. Wow. Um, where to start?
No, I'm just kidding. So I'm indeed, uh, torque's Chief Technology Officer and, uh, co-founder. Torque is a security hyper automation company.
And in a moment I'll explain what it is all about, uh, about me. You know, I would like it to be more original, but it won't. I'm in the cybersecurity industry for the past 20 something years.
Worked for, um, checkpoint software technologies during their dominance of the network security era. Uh, for 14 years, established my previous company in the field of Zero Trust Network Access that was acquired by Symantec. Spent some time there being chief technology Officer responsible for zero trusts.
And now Torque is, uh, the next company I co-founded. It's already almost four years old. We are close to 150 employees headquartered in New York.
That's security, hyper automation, by the way. That's probably what people are wondering about, right? Yeah.
So what did, what's behind the words? So, uh, the, I don't think that any of our viewers will find the notion of automating processing of security events is something entirely new, right? The idea of, wow, our attack surface is expanding.
Organizations go digital and an amount of events, we all need to pro that. That's not new. The question is how do we go about it?
And the previously, uh, available paradigm called Security Orchestration, automation and Response, SOAR existed for, yeah, six, seven years in the market focused on incident response automation in particular around security operation centers, sox. We are very familiar with this discipline, and when looking at it, we felt that a, despite the huge promise, most of the organizations adopting SOAR are still in a state where only a few of their processes get automated. They are still very much reliant on manual operations, very much dependent on the talent that they have and the talent that unfortunately they cannot grow easily.
And, uh, that leaves an opportunity for a change in a state of mind. Hyper automation is defined by Gartner, happily, not a term we invented as a systematic process where an organization accepts the reality that the events are too many to handle and you just cannot solve this problem by throwing headcount at it. And then you start systematically choosing vetting and automating away all kinds of processes.
These could be indeed traditional incident response things such as in soar, but it could be all processes related to user onboarding, system onboarding, requests that you handle on a daily basis, things that happen way before the incident even has a chance to occur. Uh, in the shift left operations, anything that people do more than once, hopefully repeatedly time after time, could be automated away so that humans do what they do best. Ingenuity, fostering innovation, coming in with strategic oversight, and machines do what they do best, which is go over tons of information, process it without any sort of like thing falling, uh, uh, between the chairs, et cetera, et cetera.
That's the notion of hyper automation. And we've been delivering a system that allows organizations to enable it with low code, no code and s code paradigms, something that can be adopted at a huge scale, something that can be adopted by multiple teams. Organizations that work with us anywhere from Fortune 200 companies, all the way to modern scale up change the way they think about their security operations by thinking about it as an engineering problem rather than human operational one.
If it makes sense, You know, the, the lot in there Leah need, let's, let's unpack it a little bit. Um, so first of all, look, our audience coming from cyber and DevOps and Cloud native is not a stranger to automation. Absolutely.
And you know, automation is probably one of the key drivers of that whole movement, but you know, what we've seen in real life practices, automation generally quickly leads to faster than humans can keep up. And, and, and, you know, that's, that's the, the, the flip side of it, right? We automate and once we start automating it, it usually the scale and speed is beyond the capacity of, you know, a normal human based team to, to Right.
Stay with it. And it, and it's not just in cyber, frankly, right? This is in anything C D C I, pipeline, software, you know, software security certainly.
But testing, uh, observability, e you know, everything we do is, and that's the speed of the internet, the speed of business. Now the, the problem, and like you Leon, I, I've in security 25, 27 years, right? Starting also with checkpoint firewalls.
I didn't work for Checkpoint, but we, we offered managed checkpoint firewalls 19 97, 98. It was very early. Beautiful.
Yeah, it was, well, it wasn't so beautiful. I look back now and think, what was we, what were we doing? But anyway, um, you know, one of the lessons I've learned in security is everyone wants to go faster, right?
Everyone wants to do more, faster, better, but as soon as you start using that a word that automation word, people are like, well, wait a second, wait, I gotta make sure we're not blocking good traffic. I gotta make sure we're not cutting off the CEO's email or, or something that's important, right? And, and you know, I had this, I, I started a company when I d s was moving to I P s, and then another product we had was, you know, we moved from just pure vulnerability scanning to applying fixes, right?
Not to remediation, right? Not just necessarily patching, but remediation. And, and at each stage we ran into resistance from people who were like, yeah, I I, I wanna go faster.
I'm just not ready to, you have to pry those reins outta my cold dead hands. I'm wondering what you guys are running into here and talk on that. So a couple of points on that.
Um, one of the things that recently, you know, what even not that recently changed is that unfortunately a security owner in the organization has to secure an estate, let's call it. Yeah. That by itself gets constantly changed by automation.
You mentioned continuous integration and continuous delivery pipelines. So if you are a chief information security officer or head of security operations in an organization that uses these, your IT and your r and d are rolling out new assets, new data repositories, new externally facing network services, et cetera, with automation, you can expect yourself to keep up with the pace of your own organization rolling out new cloud assets, right? And doing this manually, this option has just been taken off the table.
And if you go ahead and let's say, try to slow down the speed of business line applications being rolled out, you will become a blocker. And there is a natural tendency of a security in recent years to become an enabler rather than a blocker, right? Everybody's probably familiar with this.
Sure. So, so that's point number one. Unfortunately, unlike in the past, you just can no longer control the pace they will keep on rolling these cloud-based assets.
They will keep on sharing these documents over Microsoft OneDrive. They will keep on pulling up these SaaS business applications and putting corporate data there. If you lock this thing down, you are hurting the business and your competitors will gain an upper hand.
So what do you do now? So one of the comments to the really valid challenge you brought up is you don't have a choice. Now, second point around it is that you know people when when you say the word automation, people indeed think that, ooh, it's something that happens over a fraction of a second, and I have no involvement in it.
And that's not entirely true. We see a lot of automation that first of all involves what we call human in the loop influence points. Think about, uh, for example, you mentioned remediating vulnerabilities.
Remediating vulnerabilities is anyway, not a fraction of a second process. It is something that needs to involve multiple participants solicit their approval for either rolling out standardized practices such as patching something, isolating something, et cetera, et cetera, et cetera. So when we're talking about automating these processes, it's not that we do it in a fraction of a second, it is that we do it in minutes instead of weeks.
And it is that none of 1,548 vulnerabilities that are currently on your table and you need to complete will ever fall between the cracks. And the fact that automation will ensure a full lifestyle completion for all of them, this is the value. So this, this sort of like, oh my god, it is too fast for me, is not necessarily the way people look at modern automation processes.
And if they are human in the loop and preco collect all information pre-pro provide you remediation strategies and you push the button to approve it, then indeed the control still remains in the hands of the human. Plus, of course, you mentioned VIPs. Not all the people in your organization are VIPs.
So let's mention risk. Let's take certain, hopefully big chunk of the events, and there we are confident that the risk of leaving them unhandled is way bigger than handling them and maybe making a mistake and use the funnel approach, where indeed for the most critical ones, we will still draw the attention of our human specialists in the loop, but that will be 5% and all the 95 others will already be handled. It's not a perfect, uh, black and white or whatever other opposites you would like to look at world, right?
It's a world with many graves where huge gains could be delivered by handling big chunks. Make sense? Makes a hundred perfect sense to me.
Perfect sense. Alright. Unfortunately, I took us down a hole, but I wanted to talk to you about Torque Socrates.
So Torque Socrates is the newest layer, if you will, that we built on top of our hyper automation platform. Torque Socrates leverages large language models and generative AI in order to help security operations teams to automate even more. What do I mean by that?
Up until now, automation, uh, whether done with, uh, no code, drag and drop interfaces or with a full code, Python, JavaScript, or any other language at the end of the day, yielded a deterministic process, right? If an event of this type arrives, we do operations A, B, C, D, and thus conclude our automation, it is deterministic. It could be implemented with, uh, robotic process automation or anything else.
However, if we take a look at what our tier one security operation analysts perform, uh, tier one is usually responsible for triaging incoming security events. We'll find an interesting picture. These are humans fatigued, overworked, working in shifts, and they are, um, triaging security events coming onto their desks using well-defined guidelines, guidelines that are known as playbooks, uh, run books in some organizations, et cetera, prepared by more senior SOC architects, SOC leaders, et cetera.
These run books are described in natural language, usually English being sort of like the defacto lingua franca for all technical, uh, uh, operations worldwide. And, um, it, it, it kind of tries if, if you will, to program humans. The recent advancements in large language models allowed us to be able to take large bodies of natural language and to talk large bodies of natural language and to semantically dissect them into their meaning.
Torque Socrates allows us to take, and we are collaborating with a lot of SOC organizations today, the guidelines they have today for humans and turn it into automated processes without forcing somebody to go ahead and translate these guidelines for the machine into a machine code into a set of operations. This is a huge leap, allowing many organizations that are in the state that you mentioned, where they in theory, would like to automate things, but there are certain, um, you know, concerns stopping them down to start doing this with a very little investment. And of course, everything that happens happens with a full human oversight.
If you do not want, um, the automation to perform remediation, but only to reach a conclusion what needs to be done and then escalate it to a human, it could definitely do so. If you would like it to perform everything and then do this human in the loop where the human approves the suggested remediation strategy, it can definitely do so. And thanks to an architecture where everything, every action performed by this AI agent is a torque workflow and is fully implemented on top of our very unique architecture, allows you a full confidence that you are remaining in control despite a lot of reasoning and potentially a lot of acting being delegated here to ai.
I love it. Alright, Landy, I, we can talk about this all day. This is something i, I talk about, but in the interest of our audience, I, I want to get, you know, where the, how, what's the on-ramp for them?
How do people engage with Torque and Torc Socrates? How do they get started? What, you know, can you kind of, you know, vector them in?
So the process would be first and foremost, uh, to subscribe to a torque platform. We are enterprise grade security, hyper automation, but again, as I mentioned, we have customers beginning with Fortune two hundreds all the way to modern fast-paced technological organizations. Once you onboarded the Torque Hyper automation platform, connected it to the main, let's call it, uh, components of your IT and security stack, it is a question of these, uh, let's call them operational guidelines.
Imagine pilots in any commercial airplane, having a clear checklist of what do you do before takeoff? How do you perform takeoff, what do you do before landing, et cetera. These operational guidelines exist by the way, either as recommended blueprints by institutions such as Nest or Mitre in their educational services for security operations or any organization that has today.
Security Operations Center has such guidelines already prepared for the tier one specialists. If it's a services organization, then these guidelines would actually be much more detailed. If it's for internal use, they may be more generic.
Taking them and importing them literally as they are from Wiki, from wherever they are stored in your organization is the first thing that, uh, toric Socrates needs to operate. From that point on, it will tell you which workflows and which integrations are needed in order to perform different actions there. And you can start delivering real events to it and monitoring it.
The process we see usually is that at first, and again you were spot on with your original hunch, people would like to run it in a mode where humans oversee every case. Uh, as the confident grows, humans may start overseeing every fifth, every 10th, every whatever case, right? All the way until you feel comfortable and confident to send a flexible and granular boundary on what kind of cases you even wants to be reviewed by humans and which types, severities, et cetera, et cetera.
You are perfectly comfortable to be 100% resolved by that. And that controls your budget and that controls how much headcount you get relieved to do more vigilant, more proactive, more innovative work rather than, you know, this repetitive, uh, thing. Got it.
I don't think we mentioned the website. Can you tell people the U R L? Absolutely.
Um, we are HT p s of course Torque Do io You can definitely find their information about torque hyper automation platform, uh, about our most prominent use cases. And of course the newest section there talks about Socrates. Socrates talks about safe and responsible leveraging of generative AI for the sake of security operations.
And that's talk T O R Q, Correct. io. io.
Very important. Yep. Alright.
Hey Landy, I appreciate you coming on here and making us a little smarter about this today. Please keep us posted. Feel free to come back and, uh, continue the conversation.
Would be my pleasure to do so. And I don't think I made anybody smarter. Everybody is smart enough.
I just made them more knowledgeable about this particular subject. That's a very important piece. Excellent man.
Leah, need Belkin co-founder, c t o over at Talk. io talk. Socrates a new, a new, uh, offering from them.
Check that out. We're gonna take a break here on Text Drunk tv. We'll be back in just a moment.