The AI Paradox: Arnie Bellini on the Challenge and Opportunity in Digital Security.
Arnie Bellini discusses AI’s dual role as a challenge and an opportunity in cybersecurity. Regulatory differences between the U.S. and Europe are highlighted, along with the importance of compliance in cyber insurance. The upcoming Cyber Bay 2025 conference aims to unite stakeholders to tackle these critical issues.
Transcript
Hey, everyone. Welcome back here to Techstrong tv. You know, we almost didn't get this recording done because Arnie and I had such a great discussion off camera.
We, we used up all the time. Turns out, him and I are about the same age. We've had very similar journeys in our tech adventures, and it, I think this is gonna be a great interview for you to watch.
Let me introduce you to Arnie Bellini. Arnie is the managing partner at a company called Bellini Capital. Arnie, I hope I got all your names right, because I didn't even ask how you pronounce it, I assumed.
But, uh, welcome to Tech Drunk tv Arne. Tell people a little bit about yourself. Yeah.
So, uh, hey, look, I'm a tech entrepreneur and investor. Uh, my main mission in life now, uh, is to make cybersecurity ubiquitous. And I'd like to talk about why that isn't happening in the United States today.
Uh, so I'm a CPA, I'm an MBA. Uh, I started a company called ConnectWise. 5 billion.
Uh, and now I'm doing good things with that money. And my main mission is, as I said, to really make cybersecurity ubiquitous. And there's a lot of problems associated with that that I'd love to talk about and, and how we could potentially solve those problems.
So, I also recently just funded, uh, $50 million to the University of South Florida to create the brand new Bellini College of Artificial Intelligence and Cybersecurity. And the reason for that is because we've got a huge gap in cybersecurity talent in the United States, and that's what we keep hearing from everyone. So we're really working hard to try to close that gap.
Absolutely. So, Arne, there's a lot to unpack here. If it's okay with you, I'd like to go back a little in time before AI was a thing I'd like to tell.
You know, we, we do a show every morning here called Text Drunk Gang. I'd love to invite you to it. We get four or five pundits every day.
And, and basically every day we're talking about AI and security, to tell you the truth. But we, we've discussed this before, AI didn't make our security problems. We've had security problems way before we had this generative AI and everything.
We've had a security problem almost as long as we've had a computer. Well, certainly, you know, since we've had networks and, and the internet, obviously. Um, now AI is kind of the classic double-edged sword where it, it presents a lot more, or maybe a higher level of threats.
But the promise of AI helping us finally, finally pay off this tech debt bill that we have with cyber right is, is so promising. It, it's, it's almost too good to pass up. But that's my view on it.
What's your view? My view on it is AI is going to be our biggest challenge and our biggest opportunity, right? So, you know, the hackers are already using AI and they're using it to scale, uh, social, uh, engineering, uh, to a new, a whole new level.
They're using it to crack into systems in a whole new way. And, you know, AI is very similar to, and you mentioned the fact that we are, we have similar backgrounds. You know, if you think about, we go back 40 years, uh, when we first started, we, the whole goal was digitize everything.
Digitize everything. My first job at Price Waterhouse, I walked into an insurance company, 10 floors had their own building, four floors, four floors were all filing cabinets, right? And so I'm looking at that.
I remember you remember that. So it was all about let's, You had the lateral filing cabinet, or the vertical filing cabinet, remember maybe, yeah. That, and that was progress, but we went from the old fashioned vertical ones to the lateral ones where it was like, oh, I get it.
Yeah. So we had to digitize everything, right? So it's like, think about this cost savings, thinking about how faster you could get to your, uh, insurance claims and, and all the information about your clients.
And so the whole goal was digitize digi, digitize, baby Digitize, right? So it was like, we digitized everything, but we raced for 40 years to digitize everything. And hey, good news, we've digitized all of the world's knowledge, all of the world's music, all of the world's art, all of the world's, world's, uh, uh, uh, books, uh, and all of the world's transactions.
And so everything is digital now. And so congratulations. We digitized everything.
The problem is we didn't think about locking doors and windows and securing that data along the way. And so now we're faced with this incredibly leaky digital world with a bunch of Swiss cheese, uh, a bunch of holes. And we're coming in after the fact trying to plug all of that.
That's the scenario that we're in right now. And we're getting ready to go to the next big issue because we haven't, we haven't secured everything. But now, just like we did with digitizing everything, we're gonna put AI into everything.
And, and there's 85 billion devices connected to the internet today, right? 85 billion. We're gonna racing to put AI into every one of those devices, which it just massively expands the attack vector.
And I think that's just the next biggest challenge. So AI is the biggest challenge and the biggest opportunity for us. You know, I think the greatest hope of AI is that, and we're using it in a lot of our investments, is to actually automate cybersecurity, automate the fixes, automate the remediations, right?
And that's our only real hope is like, we're gonna have to, 'cause humans aren't gonna be able to do it. I mean, there's 5 million open jobs in the world today for cybersecurity professionals that are going unfilled because there's such a talent gap in the space. So we've got a real big challenge, but a real big opportunity in front of us.
Yep. So, Arnie, again, I will say it's not AI's fault that we have that talent gap. It's not AI's fault that we have 5 million open positions in the world.
In, in cyber alone. Uh, we, again, we were talking off, off camera. So when you and I went to school, they didn't have computer security or InfoSec classes.
I I went to school as punch carts, but they do now. And I know smart kids who have gone into these programs right here in Florida, USF, uf, FSU, um, down here in Miami, they graduate these programs and they're not, they're not prepared for to fill those 5 million roles, right? They, we we're doing a lousy job.
And maybe it's because cybersecurity as a major, as an education is something that we're still trying to figure out, right? When I first broke into cybersecurity, most of the people came in two flavors. They were the network guy who wasn't smart enough to say no when their boss asked them to take over security for the network.
'cause it was about network security, or it was the hacker kind of guy who liked to break things and then build it back better, safer. So it couldn't be broken again. We didn't have a professional cybersecurity, uh, courses and stuff like that we do now.
And I know that's part of your mission, is to make these classes, make these programs better, prepare our graduates for the, for the jobs that are out there, the jobs that are out there. At the same time, all you hear about, you read the, the headlines, you know, uh, we're eliminating jobs, AI's taking your job, AI's taking your job, AI's taking your job. I'm gonna tell you something.
I don't think AI is gonna take a lot of cyber jobs. It's gonna fulfill a lot of the automation, as you said, but there's still gonna be a lot the humans in the loop, the human in the loop of ai. How, talk to me a little bit about how do you see the human in the loop?
Yeah. So you make some great points, Alan. And I think the first one that I wanna, uh, attack is the current status of cybersecurity education in our university system.
It's not good. Okay? Uh, it's not good.
It's not modern. It's content based. It's good old fashioned content based.
Take a test on the content. It's like, well, cybersecurity doesn't work that way, you know? Yeah, you gotta learn things from content, but you gotta do hands on.
And so what we're doing at the University of South Florida at the new Bellini College is we're changing all of that. We are creating from scratch an entire learning platform based that is guided by ai, uh, that is based on CS a's new standard, right? So CSA came up with a whole new standard for the work, perfect for the cybersecurity, uh, workforce, right?
They're saying, here's the skillset sets. There's about a thousand skill sets. Here's the skillset sets you need to learn to be a cybersecurity professional.
So what we're doing is we're taking all thousand of those skill sets, creating content for that, okay? And not only content, but here, we just taught you an example. We just taught you how to set up an a local area network safely.
Great. And we're gonna test you on that content. Good.
You passed the content test, but now we're coming over here to a hands-on, uh, experiential test where we're gonna say, here's a network. Show us that you can do it. Right?
And so it's the combination of experience, it's a combination of content plus experience and hands-on with real live tools that is going to make the difference. And so that's the whole new world that we're creating. And what's great about what we're doing is if we get it right at the University of South Florida, we get to export that to the rest of the, uh, uh, the rest of the democratic, uh, world, right?
Democracies of the world, right? Uh, but we gotta get busy here in the United States defending our digital borders, right? I mean, thank God we finally closed our physical borders, okay?
But now we need to get busy closing our digital borders, because every nanosecond of every day, those who seek to do us harm are crossing those borders, planting Trojan horses, hacking our, our whole culture, our whole civilization in many ways. And it's serious. It's, it's the new World War.
It's World War iii. It's not a kinetic war. It's a digital war, and it's never, ever, ever gonna end.
So you and I are both old enough to remember Mad Magazine, spy versus Spy. That's what we're mm-hmm. It's gonna be forevermore.
It's gonna be Spy versus Spy Wiley O Coyote versus the Roadrunner, right? Uh, and the Acme company, right? It's, it's the ac it's always gonna be that way.
And so, you know, it's really interesting, but so many job opportunities and high paying job opportunities. So that's the thing that we're most excited about at University of South Florida, is actually being able to, to teach these kids in a modern way, hands-on experience. We're getting all kinds of software titles to donate their software so these students can actually get real hands-on use.
And so we think we're gonna be changing that paradigm. And because it's a digital system, because it's 24 7, 365 all online, uh, you have your own personal tutor with ai, it's gonna guide you through the entire content. Uh, so what we're gonna be doing is breaking all the paradigms and all the restrictions, and all the constraining factors that education has now in cranking out cybersecurity warriors, cybersecurity soldiers, cybersecurity professionals.
And hey, you starting, starting job is $60,000, and it can go all the way up to $2 million, depending on the skillset that you have. So there's a real opportunity here, uh, and there's a real threat. So we're gonna be addressing both of these, but there's other problems.
And, and, and, and why is, you know, why is cybersecurity not ubiquitous? That's the real question that I have on the table. It's like, why, why are the tools so expensive?
Okay? Why are the tools not comprehensive? Why are the tools not integrated?
Current tools integrated with other tools? I mean, we've got a talent gap, but we've got a real problem on the technology innovator side, and we've got a problem on, I believe, how cybersecurity software companies are addressing the marketplace today. I see them as profiteering and not solving the problem.
And they gotta, we, we gotta get serious. It's like this is a national security issue. It can't be seen as anything less than that, You know?
So one of the companies I found was, I mentioned to you a security company. After doing that for seven or eight years, I came to the conclusion, Arnie, that security was too hard for the average company that only, you know, maybe Fortune 50, have the resources and the wherewithal to do everything they need to do to, to block it down. The vast majority of other, they just don't, they don't have the talent, they don't have the resources, they don't have the will to do it.
I turned, I pivoted our company into what we call an MSSP, a managed security service provider, because I felt like that was the best way to give most companies, at least the minimum of what they need to sleep at night. Right? Let's outsource it in essence, right?
To a, a professional who this is what they do, and they're set up to do it on multiple things, on multiple companies. However, even that is not enough, because you can never, this, this, you spoke about attack surfaces before. Attack vectors, attack surfaces, the attack surfaces are multiplying so much every day, right?
Today it's the ai tomorrow it's something the, it's the glasses that record everything. It's, you know, there's so much, there's just, it's coming at us so fast and furious. But as we said before, we, we haven't even paid the last bill.
We haven't paid the bill for everything that's come before this. We, it's a technical debt that we need to really get into it. I love what you're doing with the school.
Let me ask you a question. What about helping these kids? And I say, kids, you don't have to be a kid to go to school and do this, but what about helping these kids get jobs?
What any part of that? Yes, sir. So you hit the nail on the head.
So it's not about just, it's a modern education, uh, approach. It's also about, uh, getting these students cybersecurity internships. And so, uh, that's The key.
Yep. And so another investment I've made at the University of South Florida, another $11 million investment is the Bellini Center for Talent Development, where we get students internships. And so we've proven that if you get an internship that 90% of the time that, that the company you're interning with, we'll hire you.
Right? And a lot of our students are now getting jobs in their junior year job offers in their junior year right's. Uh, so it's really booking approach.
That's great. So it's really about, it's about real life experience. It's about real life and, and modernizing training, and then giving them real life experience.
And so, yeah, we're very busy on that front, and I think that is the way that you're gonna help solve the problem. Great. I got another area I want to pick with Arnie, if it's okay.
Sure. This is a national emergency. I don't know if you're familiar with csa.
Oh, yeah. Right. The, so the, the bill funding, I, the government shut down.
Now, that's a whole nother story, but even before the shutdown, the bill funding, CS a, I think was CSO started in 2015 or something like that. The bill funding CSA has run out. And the, and congress is, as Congress is prone to do horse trading over whether or not we even need CS a, what's their mission, CVEs, all these things.
And it's not just CSA as a country, we don't seem to have the political will to, to pass the regulations, governance that we need to enforce to put some teeth into our cybersecurity where, you know what, say what you want about the eu, but they don't have a problem passing one, you know, regulation after the next. They actually already have an AI safety regulation. They already have the GDPR.
They already are, you know, they seem to have more of a political will, recognizing how crucial and critical cybersecurity is. What, what, what is, you know, I, I don't want to see a digital Pearl Harbor. Mm-hmm.
But that's, I sometimes I feel that's what it's gonna take for us to get serious about this problem. Well, I hope you're wrong. Uh, now I will say, I was just up in DC a couple weeks ago talking to legislators, and I can promise you, it's like, as I talked about this problem, they looked at me like I had lobsters crawling outta my ears.
Okay. Yeah. They don't, they don't get it.
It's like, it's like they, I, and I think everybody has a problem understanding the real issue and the real concern of cybersecurity, because it's invisible. We don't see it. Right?
It's not like a bank robbery, right? It's like you don't have this great visual associated with it. You know?
It's, and it's relatively boring. So, so nobody's really paying attention to it. It will.
And I don't, I hope it won't take a digital Pearl Harbor. I like that analogy though. I think, I think we've seen plenty of those, don't you?
I think we've seen, we've already seen plenty of those. I mean, we just had one with Microsoft SharePoint where all of our nuclear locations and information about our nuclear sites was hacked and stolen by the Chinese Communist Party. I don't think we wanted them to have that information, right?
I mean, it's like, so we've already, and as far as I'm concerned, that is a, a big enough Pearl Harbor right there. So what has to happen is, and I'm gonna be active doing this as well, it's like I'm, I've been active at the Florida state level, uh, promoting cybersecurity, uh, uh, education. I am going to the federal level.
We are going to hire lobbyists. We've gotta educate our, our federal government on how important this is. So, uh, believe me, I have letters out to President Trump, his wife.
I've got, we're going to make a difference there, but I think it does come down to some policy. Now, you mentioned Europe, and I think you're, I think one thing about Europe is they're pretty quick to regulate, and that's a problem, right? One thing I'll say about the United States is we're letting things sort of sort themselves out until there's a big enough problem.
And then we come in and we put some either regulations or laws in place. And what I've been told by CSA and folks in CSA is regulations don't work very well because it just creates lawsuits for the federal government, right? Uh, so what they're going to do instead is we're gonna have laws, right?
The rule of law, right? Your liability. Think about the massive liability that everyone has with the data that they currently possess.
And if someone gets that data, that's a liability for that company, well, they're the ones that are gonna have to pay the price for that. It's gonna come down to, you've got to eliminate your liability associated with the data that you have and the information that can be stolen from you. It's gonna come down to that.
And then if you really think about it, there's no regulation today, but there is this tacit regulation. So what I mean by that is, everyone's starting to get cybersecurity insurance, and if you're gonna get cybersecurity insurance, you've gotta make five major attestations. And if, and those attestations are, do I have a backup that I can restore from?
Am I using, you know, antivirus solutions? Do I have multi-factor authentication medication? Okay, uh, uh, do I have some policies and procedures in place that I'm teaching my people?
And have I, and have I have I done user awareness training with those people? And then the last one is just continuous risk assessment. And if you don't have those five things in place and you get hacked, your insurance company is not gonna honor your claim.
'cause the first thing they're gonna do is come in and verify that you got those five things. Well, what's interesting about those five things is if everyone did those five things, the attack surface is reduced by 80%, right? 80%.
And it doesn't, No, they, they say if we, if we really enforce MF two multifactor, you could probably cut 80 to 90% of your phishing based intrusions incidents right there, right there. But we don't, we, we don't enforce multifactor. And, and, and what we've done here, you know, it's funny you bring up the whole cyber insurance.
I'll talk to you offline about a situation I recently ran into. But what we've done is we've substituted the insurance industry for legislation, right? The insurance industry becomes the big stick.
They're the ones who, you know, enforcing, uh, these five things and beyond that, but, you know, insurance industries are in it to make money too. And, and there's a lot that gets lost in the sauce from those five things to pay paying your claim and, and to, and to having best practices for security. Um, I just, you know, and, and then you have this whole patchwork, California has their thing.
This state has their thing. The bottom line is we, we don't have a national standard for what it is. And, and the way our system works, when we have tried to put in standards, like, like you said, if, if a company is breached, they should be responsible.
Well, their responsibility basically is, I'm going to give you some credit monitoring for a year. You know, and I, you know how many Arnie I get? I get about three letters a week from all the accounts that we have.
You know, you, you, you, your stuff might be at risk. Here's a free year of, of ca of credit watch, or I, I have from every one of these. I haven't paid for, for, uh, uh, credit watching in years because I, I get it from all these breaches.
We need, we need more. I'm hoping AI is the answer. I I really think we can, we can make AI our best security friend to make us more secure, better secure than that.
And, and it, you and I, we're tech dudes, right? We get it. I'm sure, like you we're of the same age.
We have plenty of family members who've, like, we, you know, we're their go-to for, for, for, uh, advice and information. What are those poor people to do, right? We need something that, and AI is the answer.
I think we need something that they, they're, it's gonna protect them. They don't have to be going to the University of South Florida Bellini School, but they're, they're secure in going shopping and using the internet and getting information. I, you know, I pray for that world, Donnie.
I don't, you know, and God willing will live both live to see it. But, you know, AI I think gives us another bite at the apple. Maybe you're getting it right.
It does. And I think it's gonna be the answer. So, uh, you know, what are the other problems?
Uh, AI could be a solution, but I mean, we really gotta attack the fact that so many of the software titles out there for cybersecurity are too expensive, and they're just point, they're point solutions. They're not comprehensive, and then they don't integrate to anything else. So, you know, that's the biggest problem because we have to rely on private industry to create those solutions and to offer them at an affordable price.
Well, There's open source, there's a, see, when I was coming up in cyber, there was a ton of great open source solutions in security. Things like Nessus and Snort and Nmap and Clam av, and these are all, you know, they were free open source. All of them got bought by commercial companies.
Yep, Exactly. And so, you know, you don't really have that. So I mean, like for instance, at Bellini Capital, we will not, we invest in a lot of cybersecurity, uh, solutions, and we make every one of our investments guarantee that they will offer it at a very affordable price, and that it will be a comprehensive solution.
com. It's one that's interesting because the price point is so low, but it's so comprehensive as a risk assessment tool. And what we're finding is that we can start adding artificial intelligence to this.
So we're literally creating a, a a a, literally an AI version of a Chief Information Security Officer. And when you start, that would Be great. Could you imagine?
Oh, yeah. We've already created an AI version of a security analyst. And so as we do risk assessments, we gather, you know, just a hoard of information about how things are misconfigured or where there's gaps, and where, where your systems leaky.
And, you know, we're gonna just end up handing a human a thousand list checklist there. They're not gonna be able to get to it. So AI is now use, we're using AI now to look at that thousand to look at, okay, what, what are the highest priority things that we need to hand off to a human to do?
And then what things can we automate and do on our own, right? And so it's gonna be closing that gap, closing that gap, closing that gap, uh, is gonna be the key. You know, you mentioned, uh, cisa earlier, and, well, first of all, they got I think, a two and a half billion.
They did have like a almost a $3 billion budget, and it got cut by I think 700 million. It's like, I think they probably can find efficiencies to do what they need to do. And maybe Well, I, I will tell you, they did good work with that money, though.
When I look at what CSA has done, I, I, I'm with you on very good work. Absolutely need everything that they're doing. I mean, we're based, you know, so many of us in the industry are basing everything on the standards that they put out there.
And we, they have put out standards, which is great. You know, I think the issue is that CSA only really covers 20% of our infrastructure in the United States, and then 80% of it is still in private hands. So we do need cisa.
They're doing a great job. I think they can probably get a little bit more frugal with how they're doing it. But I will also say that, uh, you know, what they're doing needs to be pushed out to all of private enterprise.
And, you know, we talked about this earlier. It's like nobody care. People care about security once they've been hacked.
Okay? And that's the only time that they really make it a high priority. And then even if they make it a high priority, so many of the C-level people in the company have no idea what should be done.
And so they're at the mercy of consultants and other organizations that are charging a real pretty penny to give them pretty basic information. All of that's gotta stop. All of that's gotta stop.
It's gotta be a solution that we can deploy that will guide us that we don't need the, the high level of cybersecurity expertise in order to be able to benefit from the solution. And those are all things that we're working on. We're working on all of those things.
I really do think that we can close this gap pretty quickly, both in talent, uh, as well as the innovation and the tech industry as well. So, you know, I'd, I'd encourage all the big players in the space, uh, uh, Cisco and, and all the other huge players in the space to really evaluate what they're delivering to the marketplace. And how can they make that more scalable?
How can they make that more affordable? How can they add more, uh, automation to what they're doing? Because humans are never going to be able to close the gap.
It's never gonna happen. Agreed. Hey, Arnie, this was the longest 15 minute interview I ever did.
I, I think we're in about 45 minutes, but it was a great discussion, but I, I need to kinda wrap up. Listen, Godspeed to what you're doing. Good luck in doing it.
Feel free to come on, give us updates. I'm happy to continue the discussion. We could bring in some more experts too.
It's a, it's a good discussion to have, like, uh, like they say, good trouble. This is a good discussion to have and it's, it's a important thing we need in our world. Yes.
And I wanna leave you with one thing. org. Please come to our conference, cyber Bay 2025.
We're bringing government, education industry, uh, and military together to answer the question, When, when is it? This is October 14th and 15th in Tampa, uh, in downtown Tampa. And, uh, we're pretty much almost sold out.
But this is where we're gonna bring all of these people together, all different four areas, military education, uh, the industry, uh, and, and, and the government. And really start to answer this question, start to address why is cybersecurity not ubiquitous? So please join us and anyone that wants to come to the conference, there's still tickets.
org. You can sign up there. Excellent.
Arnie Bellini, managing partner, Bellini Capital, talking about the new mission, AI and Cyber here on Tech Drug tv. We're gonna take a break. We'll be back.