iCOUNTER’s Unique Approach to Defending Against AI-Powered Adversaries
John Watters, CEO of iCOUNTER discusses the evolution of threat intelligence, highlighting the transition from traditional methods to AI-driven adversaries. John stresses the importance of understanding risks from third-party connections and the need for organizations to adapt to evolving cyber threats. He also addresses the challenges defenders face against adversaries using AI technologies and outlines iCOUNTER’s unique approach to risk intelligence.
Transcript
Hey everyone. Welcome back here to Techstrong tv. Um, my next guest is the founder and CEO of a company called Icount.
His name is John Waters. Let's welcome him to Text Drunk tv. Hey John, how are you, man?
Doing well. How are you? Very well, thank you.
So John, you know, we were talking a little bit before we went, uh, on camera here. And, um, we, you know, talking about what it takes, like, you know, gonna be a little bit crazy or really, really believe in what you do and to go out and found a company and, and, you know, try to make a go of it. I've done it a number of times.
People out here have, but a lot of people out here have it. John, let's hear a little bit about your story, your journey, your makeup that led you to, uh, go out here and found Die Counter. Yeah, sure.
Uh, you know, long journey actually in the cybersecurity industry, since it's a relatively new industry in the scheme of things. Yeah. Mm-hmm.
You know, those of us that have been in it for 20 plus years have seen quite a bit of change, uh, for, say that again, by accident. I made a bad investment in a company and tried to go fix it. So I ended up running, oh my God.
So that dates all the way back to 2002. Um, I was a finance and economics guy. I managed all the, the money for the founder first data resources.
I was CEO of the holding company. He died 98. I spent out of my own.
And I started looking at different investment themes and dotcom had played out, telecom had played out. So I looked at cyber as an investment theme. 'cause I thought it had secular growth forever, and it was inefficient as hell.
And yes, it was in that lens. I started looking at the problem set in the industry. And, um, which was amplified after September 11th for me, was an indication of the, the age of unconventional warfare and, and the construct of where are new domains of war gonna be.
It's not your traditional land, air, sea space, you know, this is, it's a new complex world that's gonna leverage technology. And I determined that cyber would be a domain of warfare. So then you start studying, you know, the traditional military principles and intelligence leads operations in everything they do.
You gotta study the opponent to understand how to resource against the fight. You know, what to bring, you know, to the battle space. You gotta understand the opponent, the battle space or capabilities and no understanding of that in the cyber industry.
Everybody was fighting at the fight at the line of scrimmage, you know, where we're on the attack surface trying to, you know, look at flashing lights and figuring out what to do with it. So there was a, a couple of companies in the industry. In 2002, the total addressable market globally was 5 million in the cyber intelligence industry.
Uh, and I thought I would, uh, embark on some lunacy of, of creating an industry. So I bought a company outta bankruptcy called I Defense, which was the first cyber intelligence company that was founded in 1998. They'd been through bankruptcy, they were going through bankruptcy again, and literally bought it for $10 and, uh, in 2002.
Yeah. And the, the, the second management team was in there. So I was like, all right, I'm just gonna back these guys and try to coach 'em along on how to build a company.
And, and I could, I, I realized pretty quickly that wasn't gonna work. So I, I, uh, um, asked my wife for a kitchen pass for what would be two and a half years with five kids at home, young kids, oh God. And started commuting to DC where the company was.
So that was in January of 2003. So I bought it in May of 2002 and began to run it, um, in 2003. And that's where I embarked in my career as an operator in cyberspace.
And, and that and that trajectory, that business changed dramatically when we began to source zero day vulnerabilities all over the world. Uh, this is chronicled in Nicole Peros book. This is how they tell me the world ends, you know, the history of cyber warfare Sure.
In chapter three, where the whole thing is about I defense journey. And it was the whole idea of buying zero day vulnerabilities in, in the market to where all these researchers all over the world had no ability to do the right thing. 'cause they couldn't, they couldn't get in touch with the software manufacturers, you know, the Microsoft's the world, the Oracles.
They didn't know how to reach out to 'em. So we created responsible disclosure. We would buy those zero days, we would validate 'em, we'd work with all the vendors.
They would then publish the patch and give credit back to us. And the researcher that found it. And we began to really modernize and hold accountable as software developers to really patch their problems quickly.
And a lot of these guys were reticent to that. They were like, who are these guys telling us? We've got flaws in our software.
Um, of course now there's bug bounties and the community is really well embraced, you know, trying to help, you know, get vulnerabilities closed out. So that I defense was using intelligence to defend better against zero day attacks, you know, tax against, you know, um, of vulnerabilities in your system. We sold that business in 2005.
And then in 2006 in December, I incorporated my second business, which is called Eyesight. So, um, eyesight partners set out about how you gain global visibility from emerging threats around the world, including nation states. And we began to build decentralized collection capability all over the world.
So we were in, uh, kind of the most hated neighbor construct of, of our architecture. So we'd cover China through Taiwan, Russia through Ukraine, you know, um, Iran through Israel, North Korea from South Korea, Pakistan from India, you know, so, so we had embarked on this journey of building out this global collection capability with centralized analysis in, in Virginia. And then we delivered what became, um, considered nation state equivalent type of intelligence capability, right.
Intel to both augment the government, you know, in the US and our allies around the world, and really served as a core operating partner for our large customers who were leveraging Intel to begin pivoting into an intel led security model. Sure. And, and that that's great, great journey and eyesight, uh, a lot of those, those early folks are still there at the company.
We were, uh, FireEye bought Mandiant and the next year they bought us, we merged Mandiant and Eyesight a year later, um, and became Mandiant Intelligence, and then Google selling FireEye, and then Mandiant, we kinda liberated the good assets, and, and Kevin and I were running the business at the time, and then we sold that business to Google, and now it's Google Intel, so, sure. Um, but now you've got an industry with seven or $8 billion versus 5 million originally and 390 plus companies. Absolutely.
And we created a big data problem for customers. Uh, to your early question, yes, we have journey. What did, what did we, what did we do?
It was a great concept. It was well executed. The industry followed a lot of, a lot of, uh, companies and entrepreneurs came to the fight and built all kinds of structure around, here's all the adversaries, here's all their tools and trade craft.
Here's the machine readable components of it, and all the process of plumbing it through a, you know, threat intelligence platform and integrating it in sims and building detection rules and creating hunt scripts. That whole model, that operational model, um, has been in place now largely for about 10 to 15 years. Um mm-hmm.
And it's worked effectively, but it requires two things, latency and reusability, because you think of the latency there from us collecting on something that happened to going through the analytical process, to pushing it to the customer, to them reconciling it with all their other threat alerts and all their internal alerts from all their own systems to try to do something with it. You're talking weeks, you know, from threat, you know, discovery to threat, countermeasure implementation. Um, the other thing it relies on is reuse.
What I mean by that is the same adversaries with the same trade craft and the same tools, they're gonna use it over and over again until it's no longer successful. So our operating doctrine and the operating doctrine of the government, frankly back then was if you're seeing something that has most certainly been seen before. So if you can document everything you're seeing and say, if you see, you know, these registry CREs combination with these, these domains and these URLs and these hashes, that's this group using this playbook against you, here's how you go find them then and move 'em outta your environment.
Excellent. In an AI will, Hey, John, I'm, I'm, what's gonna happen? Sorry.
You know, I, I'm listening to this though, you know, and I, I, look, I've been in cyber, we didn't call it cyber much as you know, it was just called InfoSec or security, but I, I've also been in since the late nineties. And, um, you know, hearing your journey is kind of making me nostalgic for, for, uh, look, that's, that was the state of things then. And look a little, you know, we've come a long way.
The whole thread intel industry, and it is an industry now, you're right. It, it, it is an industry. I mean, to kind of burst on the scene, y you know, it didn't happen as quickly after nine 11 as I thought it would.
'cause for me, nine 11 was a, on personal level and, and business level was a kind of a watershed moment. I I really moved into security full-time after nine 11. Um, but it, it, it probably took, I'm gonna say 5, 6, 7 years for the threat intel to catch up.
And, and when I mean threat intel as a, as a technology, not as a craft. That's right. Right.
I, I think as a craft, there were always sort of threat intel experts who was looking at what's going on, you know, in, in adversarial places and, and bad actors. But as a, as, you know, threat intel feeds and being able to input these feeds and then marry them to your defense posture and, and what you're doing. That, that took some doing.
And it was the Mandi of the world and I guess the eyesights and and so forth that that enabled all that to happen. Of Course. Yeah.
Journey. The, the, the, the hiccup the industry hit was, was September one, September 11th was obviously a catalyst for the changing battle space, but the, the bigger, the bigger inflection point was really the great recession. Yeah.
And the early innovators in the cybersecurity industry on the defender side rose the banks. So the banks were always the, the people that were deploying, leading edge tech, new technologies, new capabilities, embracing venture capital brace companies, back companies. Yep.
And that came to a halt in 2008, nine, banks didn't buy anything, and there was innovation stagnation from 2009 to probably 2014. Wow. It's literally that long.
And from nine to 12, it was nothing. 12 to 14 was kind of like, you know, making up for past sins to try to re reestablish their basic capability. In the meantime, you saw innovation acceleration on the adversaries during that window.
So you have innovation, stagnation of a defender, innovation, acceleration of the attacker. And that's when you see the elbow and the curve. If you track cyber crime losses in 2009, it surpassed narcotics is the most profitable part of organized crime profits.
They made more money from cyber crime than narcotics in 2009, and it just took off. And that's continued to wipe it. It was outta balance.
It's been, it wasn't outta balances. Yeah. Now we have a, but we've had a new, uh, what's the word?
I, I was just talking about it, recording our text on gang ai. Right. It's, it's kind of, it's a new beginning or a new, a new boundary layer.
It's where we, maybe we're throwing up the cards in the air, let's see how they land this time. And, uh, it, it's changed everything. And, and with this ai, you're out here with a new company now that your founder's CEO of called Icount.
That's I-C-O-U-N-T-E-R. Tell us about that, John. Yeah, so, so you look at the paradigm we're in today with AI enabled adversaries.
We're in another state of innovation acceleration in the adversaries and a bit of innovation stagnation on defenders. While you see all kinds of AI tools coming, not just used by the, the attackers, but also defensive technologies. 53% of budgets this year were flattered down for CISOs.
And a lot of the businesses today are saying, look, you gotta do an assessment of, hey, how we're gonna deploy our own AI engines to build productivity gains in our company, how to do it securely. And yeah, you go look for some tools to help us defend better, but we gotta go compete more effectively in the, the industry we operate in. So the, the CISOs have almost become like the governance officer of all the deployments of AI inside the companies that create means for an adversary to exploit them, leveraging your own AI infrastructure.
So good degree more. So there's all kinds of hesitation in studying of the problem that's happening. Well, the adversaries don't have any of that.
They're like, Hey, this stuff is great. Let's see how I can leverage AI in every aspect of my attacker world. And you saw that recently where, you know, quad was leveraged for what, 80, 90% of an automated attack through the entire phases of an attack.
Let's talk through that. The long pulling, that 10 has always been reconnaissance. You know, if you wanna go steal the F 35 designs from the us, it's not gonna reconnaissance that target overnight.
It can take a year to profile a target. Once you profile the target, then you say, how do I build a durable advantage, understanding where those security gaps are, then I can exploit it, maintain persistence and exfiltrate the data I need in the format I need over the timeline I need and cover my tracks. Along the way, all of these components of an integrated attack are now being automated leveraging ai.
So now automating the reconnaissance phase is allowing target selection very quickly, and then leveraging AI to build the attack capability to exploit that particular target is allowing customization at scale. What I mean by that is, an adversary can go look at a thousand targets down, select a hundred, and then leverage LLMs to produce attack methodologies to uniquely exploit each one of those hundred in an automated fashion. As you begin to do that, you can go from the scattered spiders of the world that can pick a sector and profile and build and execute a target in a matter of days.
So latency is coming out of the system. And what I just talked about is reuse is coming outta the system, which leaves the traditional cyber intelligence model vulnerable, you know, as attackers are essentially looking at every target as patient zero, and how do I craft something new and novel to target them with? Now, this is on the leading edge of attackers.
It's a small part of the attacks happening, still the vast majority of attacks operating the old paradigm. But the irony is, as we deploy ai, we are accelerating the obsolescence curve of the old approach. And what I mean by that is, where I see AI being levered today with a lot of these new innovative tools is automated alert triage, basically studying every attack methodology that's ever been done before, executed before.
And figuring out how to automate and triage those alerts down to find what's important. Automating the creation of a detection rule based on all the intelligence that you bring into your system. You see all the intelligence.
You say, okay, that's something we want to build a detection rule, leverage an LLM to create and, and implement a detection rule in your defensive layer. So the net effect is we're increasing our velocity to make reuse of attacks less effective. And as you do that, we effectively squeeze the balloon back into AI enabled adversaries that will leverage LLMs to create new and novel attack methodologies for every target.
That's a tough problem. So I counter's history, um, and the capabilities built over years here, you know, I took it over, renamed it and spun it out, uh, of a company is all around how to target, how to counter targeted operations against a specific company. And what we're seeing now is a shift in the target from create a same, same attack methodology and use it against thousands of companies.
And maybe you'll be successful getting into 10 of them to saying, let's build bespoke capability for every one. So every one is profiled and targeted uniquely. So the business model that we had built here was to counter an AI enabled adversary using unique capabilities on every target and how you get ahead of the game and stay left to boom even as time compression's happening from tack target selection to attacker execution.
Um, so, so we will live in an agile world and advocate for defenders to spin out some kind of a special forces team, uh, on their definitive group. Use your traditional means, the defend against most attacks, create your seals delta rangers to work with us around an agile team of countering targeted threat operations that they're spinning up operations at, at line speed. Um, and that's what we do holistically.
The first productized application of our capability will be in disrupting the third party risk world, um, which has had very little innovation for the last decade. It's basically posture scores masquerading as risk scores amongst the third party categories and saying, Hey, your risk score is an 82. No, it's not.
I mean, that's, there's no threat in that equation. It's looking at web facing applications that have vulnerabilities. It's automated assessment tools, it's attack surface monitoring tools, it's questionnaires, it's all around your security posture, which has its place.
It's, you know, vulnerability management, posture management. No, No. It's part of the equation.
Don't get me wrong, I'm not, let's not poo-pooing it's part of the equation For sure. I'm not saying you get away with it. Yeah.
But there's no threat detection and response for third parties. That's our product we're releasing in Q1, it's threat detection response for your third parties. So where we can monitor all of your connected third parties holistically for all emerging compromise against the entirety of your third party stack all your interconnects, every time there's an open API OAuth share file, SEO connection, where you got data flows going back and forth that an attacker can find.
We find your third parties don't, we don't tell us who they are. So once we discover your third parties and we understand the data connections, adversaries are increasingly shifting to bank shots into your environment through a third party's trusted connection. And in fact, you saw the number of breaches double in the last year executing that very strategy.
Absolutely. Find a connected third party and use it as an attack vector in. So I think there's a few things there, John.
Yeah. I think first of all, what you're describing is sort of the difference between fishing and spearfishing. Yeah.
Right. One is just casting a wide net and like walking down the hallway of a hotel and jiggling handles Exactly. Right.
And whatever doors open, I'm, that's the one I'm going in, versus I know there's big jewels in that room. Right. Exactly.
Right. Secondly, though, you know, I was recently at, uh, a Qualys had a conference called Rock on R-O-C-O-N. ROCK stands for Risk Operation Center.
Mm-hmm. And, and they're onto something, right? Qualys has been a leader in sort of garden variety vulnerability management and now patching for a while.
But they made this realization that you're talking about that that in and of itself isn't a risk score. That's not your risk profile in order to really understand your risk. And that's what the board wants to hear, right?
The board wants to know what's my risk and what's at stake. In order to really understand your risk, you gotta understand the threat. You gotta have that threat intel.
You've gotta marry that to your posture and, and your, you know, what you got going on if you're gonna truly have a picture of your real risk. Right. And I couldn't agree with that.
You're spot on. I mean, that, I mean, we could finish each other's sentences. I mean Well, Yeah.
I guess when you get old enough, John, that happens. Right? And you're in this business long enough, you know, you, there are certain truths that you realize.
That's right. You, you mentioned another thing though, and, and again, it, it's something I think we're dealing with, which is in the, in as as a cyber industry in general, a lot of boards are telling CISOs, look, I'm done buying you shiny new toys. We every year you want a new shiny toy.
But you can't tell me how that is improving my risk posture. Yeah. How is that decreasing my exposure?
You're just buying me shiny toys. Uh, we're just buying you shiny toys. I think that's why it's important that the, these things come together.
Lastly, Well, We're, Go ahead. You see a mammoth difference even down at the compensation level of the very top CISOs Yeah. Versus your average ciso.
I mean, it's an order of magnitude compensation difference between the two. And the people that are paid the most are business leaders that happen to manage a security program. And they have mastered the art of speaking in terms of risk, which is the language that bridges business communicates, and ca the communication chasm between security and the business.
And agreed. When you leverage the economics, like as my background, you gotta say, here's how we're managing this budget that you've given me to buy down the most risk per dollar of investment so we can optimize Paying for the Buck investment buying down risk. So the reason why we need these new capabilities deployed is the threat environment's changed in the last year that has rendered certain components of our defenses no longer effective.
So we need to shift resources in this new layer of defense to counter this innovative anti adversary. That way we can buy down the risk associated with it. And if we don't do that, then we have to be willing to accept the risk of probably an additional a hundred million of loss, you know, whatever, whatever the equation is.
Well, It's gonna change on the business, but yeah, it's gonna be substantial. Is the bottom line. The risk of disruption this year is significant company.
So Abso and it's, it's not getting easier. No. Right.
This AI stuff, they're, they're just kind of feeling their way into it. John, unfortunately, this is a long 15 minute interview we did here for half hour. I wish we had another hour to sit and talk, but we don't.
I, I gotta wrap up. We've got more to do. But for Icount, what's the website?
com. And to, to repeat what you said, we are not in the threat intelligence business like the other three 90 company. We're in the risk intelligence business as we only talk about threats that have intersected with a customer's environment, either their direct environment or through their connected third parties.
Anything from us stuff, high fidelity, low frequency, and presents a risk to our customers. That's a difference. Today, the threat intelligence industry throws threat information into the customer environment and they have to determine where the risk is.
People don't have time to do that anymore. That's a huge Difference. Huge difference.
Hey man, it's a pleasure meeting you. I'm sorry I didn't meet you before. To tell you the truth, you would think over 25, 30 years we would've ran into each other.
Totally agree with that. But, um, best of luck with Icount. Come back.
We'll continue this conversation, right. It's a conversation to keep having. All right.
John Waters founder, CEO of Icount. com. It's not just about a threat Intel feed, it's about risk and intel.
So check it out. We're gonna take a break here on Text Trunk tv. We'll be back.