Go back

Enhancing Humans in Your SOC with RedCarbon

14m 55s

Enhancing Humans in Your SOC with RedCarbon

In this episode of Security You Should Know, host Jonathan Waldrop and John Scrimcher interview Simon Rapizzi, CISO at Red Carbon, about their AI-powered SOC solution. The discussion centers on the core problem: human teams cannot scale to handle the surge in cyber threats, data volume, and alert complexity. Red Carbon’s platform addresses this by using AI models—such as the Threat Hunter—to automatically understand each customer’s environment, analyze analyst workflows, and provide enriched case data with pre-made recommendations. This helps SOC analysts of all skill levels become more proactive, reduce response times, and free up time for training. The solution integrates with existing security tools (e.g., EDR, SIEM) via APIs and requires at least basic infrastructure to be effective. Pricing is based on the number of cases handled per year, with dynamic adjustments to reflect actual threat activity. Key features include retrospective analysis (up to six months), compliance reporting, and support for on-premises deployment for sensitive sectors. The goal is not to replace human analysts but to enhance their efficiency and enable teams to scale without necessarily adding headcount.

Transcription

2682 Words, 14647 Characters

English
Connecting security solutions with security leaders, security you should know starts now. Welcome to Security You Should Know. Today we're talking with Red Carbon and what they are doing in the emerging AI SOX base. Now the problem that they're addressing, it's a big one and it's the reality that humans can't scale to meet the massive surge in cyber threats. I work on cyber security headlines. We see this all the time. Having us find more about their solution, our Jonathan Waldrop, CISO at large and John Scrimcher, CISO at contour brands. So Jonathan, I'm going to start with you. Why are cyber security professionals still struggling? Why are we hitting this human limit in the sock? Well, find me a team that anywhere says, yep, we've got enough people. I couldn't do anything else if you gave me another person. We have a full great handle on all the tech we've got. There's no new cloud applications. There's no new AI that we're trying to manage and secure and data coming from all different directions. So there's still this plethora of data and systems and telemetry that we're trying to sort through. There's never been more of it and it's never been more difficult to really get to and sift down and filter through what we need to take action on, what is actionable intelligence to go stop threats. John, I'm going to come to you. Why are we still struggling right now with kind of this human scale in the sock problem? It really boils down to two words, scale being one and contextualization, the other one. The contact of the threat that Jonathan mentioned are constantly changing the tactics, techniques, and protocols change and being able to quickly switch context for the different types of threat actors at scale is nearly impossible for the human capabilities. All right. Well, today we're going to be talking with Simon Rapizzi, CISO at Red Carbon. To start out, we're answering three essential questions. So Simon, help us out here. How do I explain the value of your solution to my CEO? What does it do and what does it not do? You know, what are the, what are the kind of category limits here and what is the pricing model? Can you help us out with these preliminaries? So our solution aims to have the people in the socks to be more active, more proactive in facing the new faster emerging threats that we are facing. So since the sector are getting stronger, are they getting more skilled than the defense people? They have more time, they have more tools. We also have multiple tools in the fence, so we are increasing the number of alerts. We are starting to kind of help a human to put order in these scales and to be as fast as possible, because even the attacker are getting faster than the human. So this may not be the main idea. Moreover, with this solution, we can not only address an issue in the shortest time as possible. We also may help your team to get rid of the skills shortage and have the time to increase in the skills they need to be as effective as possible. Otherwise, we may overlook some alerts that it is very important. And then in terms of pricing, where are we at? Is this a based on ingest? Is this based on perceived? Well, just kind of that kind of basic. It's based on cases. You can say a case is an incident, so it's not a single alert. It's a kind of more broad scenario idea. So the price model is based on the number of cases we address in a full year of license. Fantastic. All right. So Siso's, we've gotten the taste for the problem. We've acknowledged that. We've heard a little bit about what Red Carbon is doing. I'm sure you solve a lot of questions, though. So John, I'm going to start with you. What other questions do you have for Red Carbon? Yeah, as you said, there's lots of questions. The first one is around the contextualization piece. That it's already difficult training people on the business and what where the different systems are, where the risk levels are, and things like that. I can imagine it would be difficult to train an AI model. So I would really like to understand better what does the training look like? How do you train it for each unique environment that every business is? We have multiple models. One of these models is called the Trata Hunter, which has a single job. It's a two-understanded environment. So it runs across all the cases we have on the platform. They understand how the analyst solves a case. What are the roles or the objects you find? So a server, what is his role? If he's normal. And if I is trying to find an abnormal pattern in this full number of alerts he has. So thanks to this kind of retrospective analysis, we can understand what's going on better about moreover. We can have a feedback for the training model to increase from time to time. So we can have a more specific training for each customer inside a broader model. All right, Jonathan. I'm going to come to you. What are the questions do you have for Red Carman? Yeah. It sounds like an interesting way to solve this problem. I'm curious really where it sits in our tech stack. And if there's existing tech, you know, EDR, some different technologies that we would need to have in place before we would want to bring in technology like Red Carman, or is it a standalone? Can it come in and stand on its own legs? That would be my first question. Okay. So Red Carman cannot work on his own. I mean, he needs information. This information is data may arrive from multiple sources. Of course, it was designed based on EDR solution or XDR solution, moreover. So we have a multiple connector for multiple solutions. I mean, the top of the bridge right now. You would suggest we have at least Siam to have EDR. I mean, multiple kind of a baseline solution nowadays that we need. So they're sort of more important. The less the visibility you have, the less use we may be, of course. So we work with the customer to increase the visibility they need. I'd like to ask a little bit about the licensing model. Again, we mentioned it was on cases as a C. So that concerns me a little bit. And I'd like to maybe understand if I misunderstood how the model works, because I can't control the number of cases that come in. That's an external threat actor function. And so what can I do to control the costs that I may be incurring? Well, right now we have an idea of top number of cases for each year. So we had just the price at the end of the year in order to match the number of cases we have. So we can predict how many cases you will have in the one in the coming year, of course. As you say, it's more attractor activity to be, I can say, as gender as possible to create less cases. But since we are also helping the company to increase the visibility, we know that the number of increases. So we will perform an adjustment at the end of the year to understand which is the real number of cases we need and to change the kind of cost to the next year. So it's kind of dynamic, is aesthetic in this case. I'll switch over to the interface of the platform. How does a stock analyst interact with your platform? Who's the right level of analyst to be logged in and to take this type of data? Well, the platform provides full environment to the analysis. So he has the case, he has the observable items he found, he has some interesting intelligence that has been found by one of the models inside the current carbon. So every case is enriched by all the information we may have both from internal and external providers. I mean, company systems, for example, or external threat intelligence provider. And even the lower one analyst has all the tools he needs to better help his own company in managing the case. So we can start from the low level analyst to the top one. We can also have a threat hunter, which may use a threat hunting model to perform sigma rules based analysis, for example. Or we may have instead a responder, for example, I'm one of them that can use the platform to perform some investigation in a case. So we'll serve them all by lap for the manager, but interesting. Does the platform is it providing information for the analyst to make a decision? Or is it providing a recommendation? Or is it, you know, is the goal for this tool to ultimately automate the case based on the information it's gathered and a rule set that the analyst helps set up? Hey, if we see this anomalous login activity, then we're going to proactively reset this account type of thing. Reset the password or MFA, for example. The platform provides all the information about the case. So it also provides some already analyzed idea. So based on the experience he has on the customer, based on the other cases he has already analyzed and information, of course, the single case. If you're watching the analyst kind of a pre-made case solution and recommendation. So you can say, okay, it's fine. I'm satisfied with this information. Or I want to do about deeper and it can also perform other analysis. What does the overall reporting look like? So app of bags are not addressing incidents, but executive reporting or just be able to provide metrics back to the CISO, the CIO, the CEO. What kind of metrics are built in? We have, we are of course, the technical reports about the single case. And we have a report about the entire environment. So for a single customer. So for the CDVL, for example, we have a specific report that can help them have a better insight that was going on. So we found the technical information. And we are also compliance point of view. So we also provide some information about how the environment is performing based on some of the main compliance framework. So we can also decide reporting. And the report is a PDF. You can easily download or access. This incident is artificial intelligence. Does it look at the context of the past 30, 60 days of types of threats or cases that it's addressed and provide recommendations for change to the environment? Well, we can run back to 6 market, based of course on all the information we have. We can also perform the analysis on our cases, so based on this data lake or directly on the data lake of the customer. So without any, I can say already analyze information, we start from scratch for them. So the Truntat, the Truntat, the Truntar module starts with scratch and perform a new scenario hypothesis. So we can run back as far as needed, so far. We say six months, but in real time we can go back as back as data we have. We always want to promise the integration of new solutions, because whether we use a different ITSM or use something that's different, all those different things that can happen, what does your ideal customer look like? The first, your ideal customer would be the easiest implementation. Well, actually the easiest one is the one that has all solution with an API, because we are API all documented, the API so we can easily integrate it with other solution. We can also develop a specific connector for the best solution. Right now we have multiple connectors to the main vendor, but if they are solution or SIN, for example, and so on so. And we have yet a customer with a customer, some custom integration, let's say, in this case we can develop the connector if needed. As far as your SOC analyst personnel, do you have metrics on estimations for how much time it's going to save them, how much more efficient are they? And to the extent that you could potentially not necessarily reduce head count, but you could hold off on hiring additional head count because you can scale more easily with this platform. We know for each case how much time we have saved, so we have our own statistics based on our multiple socks we have worked with, so we have our benchmark, we know how much time a single analyst can save, based on the case, based on the complexity of the case, but the minute yeah is to help the people to perform better, so they can run multiple cases, the more cases, you know, in a day, or they can train in the meanwhile with the spare time, so they will be more effective later. So kind of building off the last answer. Frequently people believe that if you implement AI, it can allow you to replace the entire team, which I know you've already kind of said is not the goal here. But if I'm talking to my CEO who doesn't understand the technology, I need to be able to explain the hand, there's always administrative overhead and things like that. What is a minimum number of employees you need to have just to manage the solution? We've seen socks with two people, so I mean, the program may be based on the number of alerts they have to people, even if this platform may be not enough, it depends of course on the number of incident. All right, Simon, well, what's one thing we didn't ask about that we need to know? Well, I think it's the common features we will have. So we are going to focus on different solutions for the same platform. One of these is an on-prem solution, because we are a cloud-based mainly, of course, due to the AI solution, of course. But we have some customary requires of the grid and I support, let's say. So we are working to provide them a totally disconnected solution. They can have the same properties and same capabilities of this. This is a kind of a huge goal for my side, but it's very important because we have for example, a public sector that cannot use public cloud, and moreover, some strategic sectors and strategic companies may need to have as private as possible their information. Well, that's just about it for this episode of Security You Should Know. To learn more about Red Carbon, head on over to redcarbon.ai. And if you have any feedback on this show or questions for Simon, send them over to us at [email protected]. A huge thanks to Jonathan Waldrop, CISO at large, and John Scrimcher, CISO over at Contour Brands for helping us learn more about Red Carbon, dig into the details about what matters to security leaders, and a huge thanks to Simon Rapizzi, CISO at Red Carbon for your time and being game to answer all of these questions. And thank you for listening to Security You Should Know! That wraps up another episode of Security You Should Know. If you like this program, please subscribe, tell your friends, and leave us a review. All companies showcased on this program are sponsors of CISO series. If your company would like to be spotlighted and interviewed by our security leaders, go to our contact page on CISOseries.com or just email us at [email protected]. Thank you for listening to Security You Should Know, connecting security solutions with security leaders.

Podcast Summary

Key Points:

  1. Cybersecurity teams face a human scalability problem due to the overwhelming volume of data, alerts, and evolving threats.
  2. Red Carbon’s AI-driven SOC solution helps analysts prioritize and contextualize threats, addressing skill shortages and alert fatigue.
  3. The platform uses multiple AI models (e.g., Threat Hunter) that learn from each customer’s environment and analyst behavior to improve detection over time.
  4. Pricing is based on the number of cases (incidents) handled annually, with adjustments to match actual activity.
  5. The solution integrates with existing tools like EDR and SIEM via APIs, and requires at least basic security infrastructure to be effective.
  6. It serves all analyst levels, from junior to threat hunters, providing enriched case data, pre-analyzed recommendations, and compliance reporting.
  7. Red Carbon is developing an on-premises version for sectors that cannot use public cloud, such as government and strategic industries.

Summary:

In this episode of Security You Should Know, host Jonathan Waldrop and John Scrimcher interview Simon Rapizzi, CISO at Red Carbon, about their AI-powered SOC solution. The discussion centers on the core problem: human teams cannot scale to handle the surge in cyber threats, data volume, and alert complexity. Red Carbon’s platform addresses this by using AI models—such as the Threat Hunter—to automatically understand each customer’s environment, analyze analyst workflows, and provide enriched case data with pre-made recommendations.

This helps SOC analysts of all skill levels become more proactive, reduce response times, and free up time for training. , EDR, SIEM) via APIs and requires at least basic infrastructure to be effective. Pricing is based on the number of cases handled per year, with dynamic adjustments to reflect actual threat activity.

Key features include retrospective analysis (up to six months), compliance reporting, and support for on-premises deployment for sensitive sectors. The goal is not to replace human analysts but to enhance their efficiency and enable teams to scale without necessarily adding headcount.

FAQs

It addresses the human scalability limit in SOCs by helping analysts manage the surge in cyber threats, alerts, and data more proactively and efficiently.

Pricing is based on the number of cases (incidents) handled per year, with an annual cap and end-of-year adjustment to match actual case volume.

Red Carbon requires data from sources like SIEM or EDR solutions; it cannot work standalone and needs baseline security tools for visibility.

It uses multiple models, including a Threat Hunter that analyzes past cases to understand normal patterns and provide feedback for continuous, customer-specific training.

The platform provides a full environment with enriched cases, observables, and intelligence, serving analysts of all levels from junior to threat hunters.

It provides pre-analyzed recommendations and information, allowing analysts to approve actions or conduct deeper investigations as needed.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.