Orca Security Arms Defenders for AI Vulnerability Race
Mike Vizard talks with Gil Geron, CEO and Co-Founder of Orca Security, about why AI-driven vulnerability discovery is turning cloud security into a faster-moving arms race. Geron explains why the challenge is shifting from finding vulnerabilities to prioritizing and remediating the risks that matter before they reach production or become exploitable. The conversation also covers AI remediation agents, security budget pressures, developer-driven exposure, supply chain attacks, secure AI adoption committees and why security teams need better visibility, context and automation to keep pace.
Transcript
Hey guys, thanks for through. We're here with Gil Guron, who is the CEO of Orca Security, and we're having a little chat about what's going on with vulnerabilities in AI models these days. It seems like the bad guys are going to be able to discover these vulnerabilities soon, whether we like it or not, and we're involved in something that looks like an arms race.
Gil, welcome to the show. Thank you for having me, Mike. So what's your assessment on what's going on here with these new models, whether it's Mythos or any of these other ones?
But it seems like this is going to become a fairly commonplace capability to discover vulnerabilities, and it's not going to be anything that we can keep secret. So what are we supposed to be doing here? I think having a tool that helps you to find the vulnerability is actually better than not having it.
Where in the past it was a surprise, do we have an issue or we don't, and we have to chase a zero day. Now we actually have a better opportunity to discover vulnerability and patch them and fix them before they are going into the wild. And so I would say the opportunity is greater than the risk here.
To your point about that, as I understand it, at least, a lot of, shall we say, nation-states and probably syndicates have been collecting vulnerabilities for years. They don't necessarily share them when they find them, and maybe we should assume that a lot of the vulnerabilities that we're discovering with AI have probably been previously discovered by somebody else. That definitely could be.
I think that the challenge moved from discovering of the vulnerability to actually addressing the vulnerability. And here, there's every company, every software company has thousands or even millions of vulnerability that they are know of, but so far flagged them as, deemed them as low risk. And now there is an opportunity to better prioritize and focus on the ones that matter.
And how do we fix the ones that matter? And I ask the question because we have been kind of slow off the mark, is the one way I'll describe it, in terms of how we go fix things. If somebody develops a patch, we test it, and we might not deploy it for a few months, and we hope for the best.
It seems like we've only got now maybe a few days to go do all that, and maybe sometimes even a few hours, because the bad guys, they seem to be developing the exploits faster than the patches available. You've mentioned the word arms race, and that's definitely the case also for the defenders. There's an arm race also in the defenders, where what we are trying to do is provide and arm our customers with the defense they need to gain the velocity to fix the issues before they hit production, or if they hit production, to be able to resolve, remediate them extremely fast.
That requires operations, that requires context on what to fix and when to fix it. One of the assumptions that I'd like to make, at least I'm hoping is true, is that at some point, we'll be using AI to accelerate the fixing of these things and not just worrying about what the bad guys are doing. Where are we on that journey?
What do folks need to do to kind of get AI into this mix? Because we're not going to win this war without AI. It's moving extremely fast, and I think that AI is actually doing better for security than anywhere else.
Mike, we are in this business for a long time, and we all heard about the challenges of getting resources into security. AI allows us to bridge some of that gap. There is now AI remediation agents that you can deploy that allow you to gain the velocity that you need.
In order to make sure that these agents actually automate and reduce the amount of work, what we need to provide them is the right data of what to fix and where to fix, and so there's a real opportunity here to gain the velocity, but it requires us to basically to retool ourselves with security tools that are armed with AI to be able to address these challenges. How do I make that case? Because a lot of folks have been investing in cybersecurity for a long time, and part of their mindset, I think, is that at some point, the people who provide my existing tools and platforms will embed AI into them.
Or do we need an entirely different set of tools and platforms or some other layer on top of all this, but what's the right path forward? My belief is that we need a new set of tools, or at least tools that evolved into the world of AI. And the justification is rather simple.
We are making more software with AI. We need to provide better and faster velocity and security. And so it's a clearly, we have today more developer than we ever had.
We have more people in the company that are building, right? You have marketers that are building, you have product managers that are building. You even have some CEOs that became builders.
So if you have more builders, it means that you have more exposure, and you need more security, and that's where we need to retool ourselves to tools that will address these challenges. Can we do that within the confines of our existing budgets, or do we need to have a chat with the business leaders and say, "Look, the world has changed, and the total cost of securing these environments is going up"? The reality is that while you can replace many of the legacy tools, it's not necessary that you can do it in day one.
As you do have mixed environment, there's going to be some overlap. So I assume some budget can be taken off, but also some would have to become new budget. Same as you're paying now more to Frontier Models, Frontier Labs, you're going to have to invest in security that fits these challenges.
What's your sense of how proactive are we being about all this? Because I sometimes wonder if the cybersecurity side is waiting for some sort of catastrophic event to occur before they go and ask for that money and start making these investments. Or has the community kind of heard the clarion call here, and are they being more proactive than they might have been in the past?
From my experience with CISOs, they are extremely proactive, and they are trying to find the ways to address these challenges. I don't think it's lack of concern. I think they are extremely concerned.
It's more around trying to wrap the business around this challenge. It is easier for CFOs and CEOs to believe that the fact that you're using a modern new technology just means that you're going to be secure out of the box. And the reality showed us that it's not right.
The fact that you have a new tool needs a new set of security tooling, and usually does not mean that the job got a whole lot busier for other portions of the business. In that sense, security did not became easier with the leverage of AI. The last time I checked, we weren't replacing all those legacy applications overnight anyway, so they'll be around for quite some time.
I guess everybody's trying to figure out, well, how long might this be the current state of affairs where we have an insecure code base that we need to maybe more aggressively protect, but is that the case forever, or will eventually we modernize that code base? I think that the financial reality and the financial pressure is pushing us to modernize everything fast, a lot faster than it used to be before. Knowing and having to maintain old code base becomes almost impossible if the pace continues, and so that's where we are seeing more and more companies pushing towards this high velocity delivery model.
It will cause basically adoption of new infrastructure, whether it is more cloud or even more unmanaged infrastructure in order to maintain it. We are seeing every company starts to deploy and provide agents, internal applications, and display software. And so maintaining old code base becomes a huge headache in the old way you can easily find more and more vulnerability.
Do you think the way that we're organized internally needs to change as a result of all this? Historically, you had the IT ops people, the cybersecurity people, the application developers are over here, and everybody kind of did their thing in isolation. Do we need a different way of thinking about all this?
What I'm seeing is that in the more modern companies, the security team is much more involved in the adoption of technologies, even having internal committees of AI adoption where security has a seat on the table. The fact that you have security involved in this project, in these adoptions, just allows you to accelerate the business and accelerate the adoption of AI with the benefits that comes with it. And so what I'm seeing successful companies do is that instead of waiting for something to break, they are involving the teams early on, talking about challenges, looking for a solution, evolving into deploying these solutions, and just enabling the business to move a lot faster.
What is your best advice, therefore, to the cybersecurity leaders out there, some of whom are clearly struggling, about how to go have these conversations or get themselves involved? They've been trying to kind of have that breakthrough moment in a lot of cases for years. So is this finally the thing that pushes everybody closer together, or what do you think?
I absolutely think this is a huge opportunity, and my best advice is to find tools that allow you and enable you to move faster and allow you to make decisions, allow you to move towards automation of decision making, because you will not be able to handle and do the same things you've done yesterday in this velocity. And the last, but definitely not least, go now to the engineering team, go now to the leadership in your company, and make sure that you're involved in these decision making of where and how we adopt AI, because getting to the party too late will be extremely costly for the business, and even could cost the business. We've seen so many in the last few months, so many supply chain attacks, and extremely large companies have downtimes with fast adoption of AI.
It doesn't mean that necessarily the AI is bad. It just means that we need to be very responsible as we are using this amazing technology, and that's where security team could be enabler of the business. Is there something that we're not paying enough attention to as we kind of get caught up in the moment here?
I feel like a lot of times we get excited about a particular thing, but maybe we overlook other things. So as you kind of look around, are there things that you wish organizations were paying a little more attention to? I would urge security teams to constantly think about how they adopt AI and not just how they secure AI from the perspective that it will give them a very clear view of the opportunity and risk, and it will give them the power and the ability to actually secure it.
And so look for tools that are enabling you to use AI, and your situation will be much, much better off with better visibility, better prioritization, and better ability to take action. " I think the big transition is that everyone became builders. Everyone in the company became builders.
And, that leads to a situation where getting into a demo or a POC of a new service seems extremely easy. What makes me shake my head of is that immediately you are no longer compliant because you do not have a code base, you do not maintain the code, you have new vulnerabilities, you might have exposed PII. What I would say, guys, it looks great.
Make sure it's secure. Think about the data that you're opening. Think about how you're opening it.
Don't be afraid to ask. It's better to know if we have a risk rather than to find it out on the newsletter later. And so, move fast, but be conscious about the risks.
" I definitely don't think so. I think that for the bad guys, it's going to be extremely more difficult because it used to be like having these glitches or simple mistakes, so easy to do, and it will become a lot harder for these simple mistakes to be deployed. And as long as you will act responsibly, it will be much, much harder for them to do the simple stuff.
All right, folks. You heard it here. Things might get better.
" Gil, thanks for being on the show. Thank you, Mike. Thank you for having me.
And back to you guys in the studio.