Securing the Future: How AI is the Key to Addressing Modern Security Gaps
Chen Burshan, CEO of Skyhawk Security, highlights the importance of addressing security gaps and the role of AI in enhancing security measures. The evolution of cyber threats necessitates continuous adaptation in security strategies. Skyhawk’s platform integrates various security functions to improve efficiency and reduce noise, inviting further exploration of their offerings.
Transcript
Hey everyone. Welcome back here to Tech Drunk tv. You know, we've got a full day today in addition to our regular tech drunk tv uh, lineup that you're watching here at, uh, well, I think it's one o'clock Eastern Time, 10 o'clock Pacific time.
We will be live from AWS reinvent and, and so it's gonna be pretty cool 'cause some of these text drunk TV interviews we've recorded prior to reinvent and in the, in the case of this one, hopefully we'll be following up with a live follow up to it tomorrow. So watch it today and then watch for the follow up tomorrow. Let me introduce you today though to Ken Han.
Ah, Ken is the CEO of Skyhawk security. Ken, it's a pleasure to have you on here with us at text from tv. How are you?
Great. Thank you, Alan for having me. It's a pleasure being here.
Thank you. So, you know, I said your CEO of Skyhawk security, we're going to get into what Skyhawk security is, but, you know, people always want to know, who's this guy talking to me? Where did he come from?
How did he become the CEO? Why is he the CEO? Why does he wanna be the CEO, give them a sense kind of your, of your journey, of your path to becoming how you came to be CEO here.
Yeah, uh, sure. So, Han, CEO of Skype security, I started my career as many, uh, other, uh, colleagues, tech, uh, CEOs out of the Israeli scene. I started as an engineer, uh, many, many years ago.
I'm very proud of having, uh, around 50 technology patents on my name, uh, where I'm inventor or coin inventor. Uh, I think that That's impressive. Innovation.
Yeah, innovation is like in the core of, you know, very close to my heart, my heart and, and in what I'm doing. Uh, I spent most of my career, uh, post, uh, being a engineering manager, uh, as a product manager and, and a product executive, uh, always kind of thinking practical engineering what customers needs and, uh, how do we solve their real pains. Uh, and the, the position that I think, uh, uh, placed me in the CEO seat of scale was basically always heading the Israeli, uh, site as a GM of Dom nine, uh, that got acquired by Checkpoint, uh, 2018 and was kind of the first creator of the, uh, CSPI market later on developing to become cna.
And, and we all know, you know, the, the second wave, the second generation kind of took the market by a storm. So I, I've been doing cloud security for over 10 years. I know the market extremely well.
Uh, and when, uh, sky Oak was created, I was called to, uh, lead the company, uh, and bring my technical expertise and go to market expertise all together, uh, in order to, uh, bring innovation and make sure that we take it to, uh, to our, uh, customers and to the market. And that's, uh, who I am. It's a great story.
You know, the old thing, you can't make wine before it's time, so you this needed to, you needed to cook and based and, and mature to be in this, to, you know, be the right person for this job at the right time. Totally. And That's fantastic.
Um, Ken, of course, there are many, there are many, uh, cyber firms that come out of Israel, right? Next week is, is Cyber Week in Israel, right? Actually, we were supposed to go there and then we just couldn't get the logistics together in time.
Long story, but, um, Skyhawk might be one new to our audience, if you wouldn't mind, explain a little bit, kinda what's the mission? What was the passion, what's the, what's the idea behind Skyhawk? So, Skyhawk, uh, is, as I mentioned, a cloud security, uh, company.
Uh, and, and if you think about my history as well, right? Being there in the market before, you know, the term CSPM was even created, uh, and seeing how the next generation kind of transform, transformed it into a synap, right? Uh, we felt there is a, a gap and, and there is time to create, uh, the third generation in a sense.
Uh, and the third generation in our view, uh, is a purple team powered cloud security that is essentially bringing together the domains of, uh, CSPM cloud threat detection and response on the defense side and cloud native breach and attack simulation on the, uh, breach and tax simulation offensive side in the same platform, creating synergetic value, uh, by fighting kind of once against one against the, the other in an AI against ai AI manner. Now, that's what the platform is doing. Uh, why are we doing that?
Because we understand that synapse today, uh, have gaps, right? They, uh, what we hear from customers, uh, and it doesn't matter which Synap platform they bought, is that, generally speaking, there is a lot of noise, uh, from the c nup findings. Uh, even, you know, the most, uh, prestigious, uh, platforms out there, uh, have a lot of false positives, both on the risk management side as well as on the runtime detection side.
Uh, we understand that it creates a lot of, uh, time waste and a lot of friction between security and DevOps. And also, generally speaking, if you try to take, uh, a breach and attack simulation, uh, and apply it to cloud, these technologies were built, uh, for on-prem, and they are not fit to the cloud. So we built a platform that when understood, from a technology perspective, from an innovation perspective, that has a lot of value.
When we placed it in the hands of customers, they came back and said, you know, you're doing more than automated purple teaming or C automation. You're actually, uh, getting a synap noise reduction. We have case studies with customers that reports 99% noise reduction, uh, and you are doing red teaming, automated red teaming cloud native in a way that takes a lot of the manual effort that is required to build samples environment and, and basically do red teaming.
Uh, and, and that's what Sky Oak delivers. Basically, if we think about our platform from a technology perspective, it's autonomous, continuous purple teaming of red versus blue. Mm-hmm.
From a use case perspective, from the value proposition perspective, we are providing, uh, autonomous agentless effort, free red teaming, breach attack simulation. We're providing, uh, unified vulnerability management, synap noise reduction, and all of that with our, uh, Cloudera detection and response that is adaptive to the customer's environment as a result of this continuous purple teaming process. That's in a nutshell, uh, what Kayak is doing.
Love it. I've got two, two areas I I want to touch on here. First of all, people are watching this.
We're out in Vegas, as I said, hopefully we'll have you on live tomorrow. Um, for AWS reinvent, let's talk about how this, you know, obviously when we talk cloud AWS is, is, is probably the biggest in the world. Um, well, it definitely is, but how does this work within the AWS environment?
Great question. So, uh, our platform is agentless and very easy to deploy. We actually have, uh, a very, very compelling better together story, uh, with AWS 'cause the way we actually work is we onboard, uh, and assess the environment over APIs almost as most seen up, uh, do by reading, you know, inventory and configuration data, uh, from a Ws.
The way we actually work, once we bring this metadata in is we're doing very smart analytics, uh, on top of the data. Plus we know how to do analytics on top of AWS native security controls and create a story, uh, that is not easy to create with these tools independently, even if you consume them. So, uh, it's a very easy deployment.
We are a SaaS product, no agents to deploy onboarding takes minutes. Uh, and the nice story is that we basically digest, in a sense, configuration data, log data, uh, and data from the security services. And what we're creating is a smart analytics layer on top of all of these that are creating use cases and synergetic value on top of, uh, uh, everything AWS related, including the AWS, uh, security services such as Inspector Guard duty, uh, Macy for data classification.
We actually create good incentive together with AWS to consume these services and use them as an reaching data to what we do. Love it. Here's my second question, and it's more to do with AI and the, you know, the, the state of, of what we see today, um, in a world where so much of the code that we're generating is generated by, by ai, right?
And, and we try to keep a human in the loop. I hope we do anyway, right? We're, we're humans are reviewing this and making sure it's good, it's secure or what have you, but can you have too much ai?
So in other words, can we have AI create the code, write the code, and then have agentic ai, right? Doing autonomous automated, if you will, purple team type of work? Where is the human in the loop?
Here is what I'm afraid. Or are we getting to the point where we need, we can't have that human at that juncture. The human's gonna be further down somewhere.
It's an amazing, uh, question. Uh, I actually, I I want to answer it from a different angle. Go ahead.
Uh, a little bit, uh, different than the way you ask. When, when we came with the vision of AI against AI almost three years ago, you know, we had, uh, an amazing cloud threat detection and response system, and we understood that the adversary world is going to change significantly because of generative ai. What we saw three years ago was that, uh, you're going to need less skills as an attacker to build an attack.
Therefore, attacks are going to change, uh, volume and velocity. The skillset is gonna change. So a lot of what you asked about, I'm actually looking on it from the risk perspective and what attackers needs to do in order to create, uh, uh, attacks on a customer environment.
Uh, and y you know, two years after we saw a report from OpenAI discussing how OpenAI was used in order to build deliverable attacks and just recently, and traffic gave another, uh, example of file. They detected that on traffic was, uh, uh, used by, uh, uh, a state, uh, level, uh, adversaries to build a attacks that, uh, you know, basically took minutes to an attacker By leveraging, uh, uh, generative AI and including that case, uh, the attacker's world is changing. They are building attacks that would otherwise require a lot of skills.
They can now consult with generative ai. You know, what do I need to do when I have that vulnerability or this vulnerability? And they can actually get the code.
And in a sense, almost that, uh, generative AI build attacks completely autonomously. Uh, our concept was that we needed to prepare our customers to these types of attacks. And that's why when we went ahead to build our autonomous red teaming, we actually used generative AI in our, uh, uh, models in order to build that, uh, AI based, uh, uh, uh, we build a process that it's not, um, um, it's validated.
We have our own researchers validating what the, uh, AI is doing. So, but efficiency wise, to do what I'm doing today as a company with, you know, a startup with a relatively small, uh, group of, uh, researchers and, and, uh, red teamers would in other world before generative AI require a team of hundreds, the pace in which we let AI adds add more and more building blocks of TTPs into our AI is just amazing. Uh, and it's validated.
But we're basically letting AI build these attacks, uh, at a scale that, uh, would never, uh, be possible, uh, without a huge, uh, budget. We're able to do it extremely efficiently and prepare our customers to the attacks that they're likely to, to encounter on their environment. Uh, it's, it's so impressive and powerful.
Uh, and, and it's not just efficiency. It's the actual risks that, uh, that we're preparing our customers to deal with. I love it.
Ken. Unfortunately, we're about outta time in this 15 minute thing. I think we hit on two very important pieces here.
A few, maybe more than two. If, if we can continue the conversation on Wednesday, I wanna talk to our audience out here who maybe aren't familiar with like, purple teaming, or maybe not red and blue teaming, and how does this fit into the larger cloud security synap and, and kind of structure. And, because I think at some level, you know, we jumped right into the agent ai, autonomous, uh, continuous aspect of it.
But I don't know if we laid the right foundation for making sure people understand that even before we had agent ai, even, you know, before we had this, this, this was a, this was a big problem in security that we had to address, and we, we've tried. And now how great it is to have this kind of solution that is harnessing and leveraging AI and is continuous instead of, you know, whenever I could afford to pay a blue team or, you know, the red team or to, you know, to do these things, uh, whether they were in-house or out. So we'll continue the conversation, but you know what we didn't mention for people want to get more information about Skyhawk security.
Ken, where can they go? security. Easy, easy one.
All right, my friend. We will continue this conversation in, uh, in Vegas, but for now, this is Alan Shimmel for Text Drunk tv. Thanks for listening.