Navigating Cybersecurity: AI Innovations and Compliance with Deep Instinct’s Carl Froggett
Transcript
Hey, everyone. Welcome back here to Tech Trunk tv. My next guest is Carl Frockt.
Carl is the CIO of deep instinct, and he was actually, we had Carl on and maybe a month, a month and a half ago. Spoke a little bit about deep instinct and you know, what they're about and AI and everything, but we've got more to talk about today. I invited Carl back.
Carl, welcome back here to Tech Drunk tv. It's great to have you on. Hey, good to see you again, Alan, thank you.
From me back and, uh, my pleasure. I look forward to today. Very cool Call for, maybe for people who didn't catch the first time you were on, give them a just a, maybe a quick synopsis of how you came to be CIO here.
Yeah, sure. So I've been at Deep Instinct now for three years, um, where I'm the CIO and ciso. Uh, I also run customer support, uh, so all the post-sales, uh, here at Deep Instinct.
And how I got here was prior, I was a customer of Deep Instinct. I worked at Citi or Citibank for 27 years, where, um, I spent a majority of my career in cybersecurity as it's called now. Uh, way back in the day, Alan, when, uh, it wasn't cool, uh, it didn't have a budget, it first stack, we used to say no a lot because we didn't have any answers to questions.
Um, but obviously it grew. And then, uh, at Citi, probably from the last 10 years, I built a team that we called Infrastructure Defense, uh, under the CISO organization. So reporting into the CISO responsible for what it says, all of the city infrastructure for all business lines globally.
So very large, big scale, 200 plus countries, half a million kind of people, a million devices, 300,000 network devices, and providing, uh, all the defense and protections to enable the business to do what they needed to do whilst protecting, uh, Citi from, uh, the ever changing threat landscape balance. So, uh, and it was there that I came across deep instinct and, uh, joined the company. Very cool.
Very cool. Um, deep instinct, obviously you have, uh, as a customer and now a CIO have a deep connection, but for people maybe who aren't familiar with Deep Instinct, how would you describe it to them? Yeah, sure.
So one of the, how I came across Deep Instinct was solving a problem that we had or trying to solve a problem that we had, which was the threat landscape and the bad actors become more and more advanced. And clearly, uh, working at Citi money was not an issue, and I deployed, uh, all the very latest available technology, but the matter of fact was, was threats were getting more and more successful or penetrating our layers, uh, you know, deeper and deeper. And we obvi like everybody else.
We were, um, in the detect and respond kind of, uh, mode of detecting these things and trying to cut them off. Um, but as they get deeper, obviously that time becomes, becomes an issue. So, uh, our CISO at the time, a gentleman, Charles Browner, challenged me and said, Hey, Carl, you know, you, you have a very large budget.
Why is this happening, right? Why, why are the, the vendors and the solutions we have not being more successful? And, and so we did two years of testing and research, and we really came across Deep Instinct because it was unique in that it's powered by deep learning.
And deep learning is the most advanced AI that's available today. So we all hear the AI buzzword, uh, but deep learning is by far the most advanced available today. And the company had taken that more advanced AI bearing in mind, Alan, this was seven, eight years ago, the, this is not something recent and applied it against cyber and cyber threats.
And so they were able to prevent, uh, threats coming into the environment. But when I say prevent, I mean zero day things that have never been seen before and that are unique. And historically, as I mentioned, our machine learning and other AI approaches or signatures, if you want to go back that far, it was detect and response, something bad happens, and then you hopefully catch it before, um, before it's too late.
So it was a prevention first mindset that we deployed at City into the applications and storage and, and cloud areas. So enabled us to be on the front foot. And what we're seeing today, Alan, uh, especially in the last couple of weeks, is how the bad actors are using LLMs and dark ai, as Gartner coined the phrase, dark AI to produce zero day unique, sophisticated malware at great speed, at great sophistication.
But the big thing there is each one is unique. So there's no history, there's no pattern to, to, um, to be able to kind of detect and respond. You're, you're really on the back foot all the time.
Deep learning doesn't have that problem, and that's what we bring to the market in a very unique way. Excellent. Good.
Good, good stuff there, Carl. Um, so Carl, I, I called you back on because when you, I think when you were on last time, you hinted at some new, new research and studies and news coming out, and it seems you guys have, uh, have some new data. Yeah, we can share.
Yeah, we produced, it's available on our, on our website. Obviously we produced our, uh, uh, SecOps report this year. Um, and the report is, uh, not, not only of our customers, but of, uh, I think over a thousand customers.
Uh, and, but I wanna be clear to the audience, security analysts, security operate people in the trenches. It's not like research and like this is real feedback from people, hopefully some of your audience who are on the front line every day, who like I am, and certainly like I was, right? And, and really what they're seeing, and, uh, obviously AI was the big thing of people.
Uh, certainly insecurity being, uh, pushed into, uh, investing into ai, having that strata. This was an interesting one on their strategy shifted mid-year. So obviously, you know, you plan for a year usually as about what you're gonna do.
Uh, the, uh, the research that came back from our, from our surveys and that we published is even, even mid-cycle security operations analysts were pivoting to their strategy for the year to implement AI tools, right? So it's a really, uh, different insight than some of the other research that is out there, because like I say, this is wholly from people on the front line, what they're seeing and, and what they're experiencing, and how certainly AI is having an impact on their operations, how they're doing their kind of, uh, business and conducting their SecOps, uh, but also around their worries and fears about how the bad actors and the threat landscape, again, are using dark AI and really producing this sophisticated kind of threat landscape that we're just starting to see today. I really don't feel it's matured yet from that perspective.
Absolutely. You know, Carl, I was, I got into a discussion, I'll, I'll, I'll, I'll call it a discussion. It was a little more heated than that with a, uh, security analyst from a very, very large analyst firm, but not the one with a g, um, who they just came out last week with their 2024 look at, uh, security and DevOps actually.
Mm-hmm. And, um, you know, my point was this year, more than any year in my memory, what you did in 2024 isn't very important to me. Tell me what you did in June, because I, I, I do think what you said is dead on ai.
Uh, it, you know, it burst on the scene now, I guess two and a half going on November. I guess it'll be back three years, right? That, that judge GPTs out.
Um, but really in the last six to eight months, it's bit right. Everybody is now not just talking, but implementing or trying to implement, whether it's agent AI flows or, or generative ai, you know, help everybody is, and it's changing the fabric of what we do and how we do it. Yeah, I think, I think I, I mean, I've been around a long time.
Um, yeah, I started, you And me both. No, uh, I started my career, uh, very junior kind of as the internet was, was having an impact. Me too.
Um, in, uh, certainly, uh, in, in business, right? Obviously, uh, yeah, we had jam You Weren't there for DARPA uk, but, but as it impacted business, and, and that's where I started my career was internet connectivity, networking, and, and then obviously, uh, the bad actors figured out how to manipulate that, and that's where I moved into cyber. But I, I see, uh, ai, um, uh, as a real trans, the similar transformational point of, of, we can't really comprehend what the next year, nevermind five, everybody talks about a five year plan.
Good luck with that. We can Get about it, right? I plan the next six months, maybe May maybe 12, but again, uh, and it was showed on our survey, be prepared to, to pivot, right?
Yeah. Um, but I, I think with that, and again, it's, it's in our, in some of the feedback is, um, I think around 70% of our respondents said that the implementation of AI was, was contributing to burnout, right? That it was that it, it, it was, uh, if I read between the lines, again, coming from a very engineering operational background in cyber, um, you've still gotta do your day job, right?
Nobody's stopping that from happening. But now you have, um, what I'll call all this AI stuff, right? Uh, to your point, Alan, you know, it's, it's only three years old and, and honestly, you could spend all day reading about the next big thing that's just come out of some company, some ai, right?
It's still, the, the velocity of changes is we can't keep up. And, and yet we all know you can't just implement it overnight. It nothing works that way.
So the challenge is you gotta keep the wheels on and, and keep doing business the way you are today. Um, there, there's a lot of, uh, um, hype and, and potential advantages from implementing ai, especially in SecOps and some of those workflows. Um, but you have the complexity of doing that.
You have the, the complexity of, uh, first of all, getting it right, not having bias, not having hallucinations. And now you also, on top of that, have all the compliance regulatory kind of pieces, uh, to go. So I, I can absolutely see why, whilst if you read the marketing right, there's, there's a lot of advantages, and yet it's not mature.
It's rapidly changing all the time, uh, and you dunno what your risks are, right? So, um, it's, it's, uh, it's an exciting time, but it, it can be a very strange time and a very challenging time, um, you know, to, to be certainly in cyber, certainly working in AI and trying to transition, uh, in a, in a thoughtful way from something that you've been doing to, to something really new, uh, very challenging. As anybody who's deployed any new technology in any company will attest it never worked right the first time.
Absolutely. Absolutely. Carl, we don't have a lot of time left, but I would like to zero in on regulations.
Sure. Right. We're just, there's a lot of talk.
I mean, the EU as usual a bit, you know, a bit out ahead in, in, in regulations here around usage for ai, um, in the US I think anything with the word AI is, is just full speed ahead. Damn. The torpedoes it seems, because they, you know, it's, it's, there's some sort of, you know, imperative if you will.
It's AI at all costs. Um, but, you know, AI related regulations and the penalties that'll be attached to them have to give people, uh, time to pause and, and say, Hey, what does this mean to us? What do we have to do?
What shouldn't we do? And, um, you know, and, and, and quite frankly, again, I think we're still in the beginning of that cycle, because generally it takes legislature, legislature, you know, rulemaking kinda years to catch up to kind of the state of the art. Yep.
That, that, what do you, sal, and that's always been the case though. Sure. Right?
Uh, yeah. The, the, how can I put it, the technology, the innovation has to exist and, and has to be seen in the real world. I'll say regulation lags before a regulation and, and lawyers mm-hmm.
And, and whatever can, can really assess because, um, you know, you always have to, so you always have this kind of, you know, push and pull of innovation, right? So certainly I come from the banking sector, obviously. So I remember when electronic trading and algorithmic trading and, and many other things that I was, I was involved with.
You wanna rush ahead. Um, but the risk frameworks and compliance, especially there, there were already things in place, um, that, uh, you, you already knew and understood. So what you were trying to anticipate was getting ahead, uh, from a business perspective to deliver value to your customers and, and so forth.
But you could anticipate some of the things that ultimately a regulator or compliance or law would maybe put into practice, right? You could anticipate, I think the difference with where we are today is it's so transformative, right? So you've got the EU AI Act, I think the penalties on that, um, you know, uh, they land in 20 26, 20 27, I think.
So companies already have a compliance and risk function. Uh, so there's nothing new there. I think, I think AI is challenging.
'cause if I think again, of, of some of the things in there around the output, um, you have biases, hallucination. So a lot of those things certainly in the, in financial processes are already baked into compliance. The issue is with AI is who's accountable.
'cause ultimately, if I think of compliance, there's always somebody accountable. So if, if, I don't know if you, uh, if, if your business is making in incorrect or biased decisions on who to loan money to or which company or not. Well, historically, you had people in the loop, right?
So you had a maker, a checker, you, you have different controls. You don't necessarily have that with ai. So what you gotta do is, uh, shift left, right?
Compliance needs to be embedded in the training of these models, in the usage of these models, in the process flow, maybe in a way that compliance hasn't been embedded before. 'cause generally, and I've been general, compliance was embedded at the output. You look at the output, does it work, yes or no?
I think the issue with some of these ai, you, you need to be more in, in the, in how the decision was made by the ai. So you need to be further in and more embedded in the process, uh, because you can't always explain, uh, why even with machine learning and deep learning, it's not always deterministic. And so you've gotta embed more compliance into not only the output of those out, but how they're deployed, how they're trained, right?
They're constantly updated. Um, so there's a lot more complexity there, uh, than maybe we've had in existing technologies. Alan, I, I don't disagree with you there, Carl at all.
Carl, we're about outta time. But for people who want to get more information, you said it was on the website? com or, or hit me up on LinkedIn and I'll, uh, happily redirect your, uh, audience or, or equally take any questions.
I think we just scratched the, uh, the service of our SecOps report and this compliance landscape that's, uh, you know, shifting a lot and it's very patchwork right now, um, you know, with different countries and even different states in the us. So yeah. Yeah.
Compliance frameworks, especially around AI, need to be more modular than maybe what they've been historically, because you, you're gonna have different requirements and, and again, depending on your business, you might not want to apply, uh, everything that EU does to California or Florida or, or wherever, right? So it's, uh, a very complicated landscape right now, uh, but a necessary one. 'cause the reputational risk and the fines and the, uh, the things that we're seeing, um, it, it, it, it's not second place.
It's as important as cyber. It's as important as running your business. So, but yep, sure.
com or hit me up on LinkedIn. Alright, Carl, thanks for coming on again. Hope to have you back on soon.
Keep doing what you do with Deep Instinct. Thank you very much. You're watching, uh, text Drunk tv.
We're gonna take a break. We'll be back in a moment.