Go back

Ep 141: AI Hackers Are Here; Cybersecurity Legend Kevin Mandia Is Building the Answer

38m 36s

Ep 141: AI Hackers Are Here; Cybersecurity Legend Kevin Mandia Is Building the Answer

The transcription features cybersecurity expert Kevin Mandia discussing the severe and growing threat of AI-enhanced cyberattacks, warning that many entities are unprepared. He traces his career from the U.S. Air Force in 1993, where he first encountered state-sponsored hacking from China and Russia, to founding the incident response firm Mandiant. Mandia argues that traditional antivirus tools are easily circumvented and that breaches, especially from nation-states, are inevitable. He emphasizes the critical need for professional incident response to determine "what happened and what to do about it." Sharing key experiences, he notes a significant change in Russian cyber tactics in 2015 and describes the high-pressure reality of helping Fortune 500 CEOs during ransomware attacks. The discussion underscores cyberspace as a perpetually contested domain for espionage and crime, requiring constant vigilance and advanced defensive strategies.

Transcription

8018 Words, 43066 Characters

English
During our podcast over a thousand Americans are going to get duped, scammed, and lose money in the cyber domain. Every few days our experts are startled at what AI agents can do. People call you all the time. It's very often a billion dollar problem. If you've been hacked and you know it, you hire manned in to come in to figure out what happened. You sold your company to Google. What made you want to get back in your arena with AI? With AI comment, you can automate human thought. You're going to have swarms of agents that can communicate and think and instantiate normal and learn and have total recall. One of my big fears for 2026 is that these things are getting so much better that a lot of corporations and governments aren't ready for it. The beast is going to come at it, a cage. Kevin Mandia is a cyber warrior that every Fortune 500 CEO has on speed dial. He was a founder and CEO of Mandiant. Everyone knows the name who works in the cyber world. If there's a break in, if there's an attack, if there's bad guys coming to get you from North Korea or China or Russia or some other place. Kevin's the guy you call. It's a really serious situation. He sold his last company to Google. Today he's working with a very top AI talent in the world. We're in a very interesting area where these AI agents that turns out are even better hackers than anything we've seen before in order to save our companies and save our governments. We're going to need to build the ultimate weapons with this AI. Let's hear from Kevin about it. Welcome to American Optimist. Really excited to have my friend Kevin Mandia with us today. Kevin, thanks for being here. It's great to be here. I'm going to be an optimist today. I love it. Kevin, you're a legend in the cyber world. You were a founder and CEO of Mandiant. You're running Arminin now. I want to go back and talk about your history, how you got your start in the cyber security world. You were the Air Force originally. I was. I wanted to be a legend in beer pong or a legend in football. Hey, cyber security came my way. You do what you got to do. I started my career in 1993 in the Air Force. I got stationed at the Pentagon. At that time, we called cyber security, computer security. All I can tell you, Joe, is I was first in line as a second lieutenant putter bar at the Pentagon to see a 06 to get my assignment. Whereas it felt at that time at the age of 21-22, you're sentencing. What am I going to be doing for the next few years? I'm a sucker for the zone one left. He gave me six job offers. You can do this. You can do that. You could be a job programming language guy. You can be as a comp side guy. He gave me all these options, but he said there's one slot left to do computer security. I remember thinking one slot left. I better take that one because it's the commodity. If it's your job, you get good at it. I can tell you the fastest way to tell my history is I started doing computer security in 1993. Now is about the year we started putting eyes on our network in the military. Who's doing what on the military? We started monitoring. That's when we all first started getting online. I think I got AOL in 1993. This is a very beginning. Wait, what was that called? AOL. Yeah, I had grown up in the DC area. We know a lot about AOL. I lived with the whole thing. The first couple of intrusions happened in '88 with the handover hackers and Clifstole and those sort of things. I had the Morris worm. I think Clifstole was '84. Morris worm was '88, Gaia Cornell. Right in the worm that had a finger demon, buffer overflow, and kind of spread across Unix machines. By '93, I'm sitting at the Pentagon looking at log files. TS log file secret log files figuring out who's doing what? By 1995, I'm responding to my first ever computer intrusions as an Air Force special agent in the Air Force Office of Special Investigations. Who was doing the intrusions in 1995? Was this really kids? I was just trying to like what? You love to think, "Hey, it's just kids." Right? You know, it's hate or the infamous. It's the guy in the hoodie and the basement. It was not. It was definitely China and the SVR out of Russia. I think by 1995 until now, I would say on a daily basis either I or someone I work with has been responding to an intrusion from a Chinese actor looking for the government. So we've had a, I guess that's 31-year run now of daily combat in the cyber domain. It's a contested domain and all modern nations have a doctor on how to operate in cyber. So I can tell you it was for me, the SVR was first China was a rapid second and in the first time I responded to the Chinese government hacking was 1996. Did you ever meet any of these guys from China or Russia? Not that I'm aware of. I may have bumped them, you know, bumped into them at a mall. But you know, what's interesting about this and it'll sound weird. You do get a mutual respect as you're responding to the breaches and you see the art of espionage, the art of intrusion. You recognize talent when you see it and I do believe, you know, Russia had the crown early 1990s, early 2000s. The best intrusions I saw was Russian operators on our networks. Later in my career, especially in around 2019, 2020, China, you know, really rapidly graduated to great capabilities and great, Seraptitious Ways to Access Networks. At PayPal, when I was a kid, I think the Russians were the bigger threat. There were some Chinese stuff. But the Russian networks were like stealing the most money back then. You know, I responded to and worked on a case. Lexi Ivanov and Vasiliy Gorskov were two Russian hackers hacking and extorting US companies, but they had whole scams to buy and sell stuff with stolen credit cards on PayPal. Oh yeah, that was awesome. You got it. That'd be the whole thing. You look at their machines. There's no Microsoft Word on it. There's no email on it, but their shares hack is a bunch of scripts to fraudulent and buy and sell things. But that was back in 2000, 2001. Tell us one of your favorite early war stories from the 90s or 2000s. Like what when did this really start to get more dynamic and complex for you? Well, I can tell you in 1996 when I was spotted to intrusions, I remember one of the first intrusions I responded to was China. You know, back then it was there was almost nobody responding to intrusions. It was kind of like a so what? Like who cares? These guys are breaking into military systems. What do they do in flag officers aren't really using email? There's not much there. The reality is there was stuff there. I think one of the first major cases that I responded to are like, okay, now I get it. Was that the Russians broke in and they were exporting display. In other words, they were running our weapons modeling and simulation software from Russia and seeing how it worked. Well, you know, and so then you went, okay, I see how and we didn't export super computers back then, Joe. I don't think we do today. You know, they're like the crazy 90s and the origin 2000s. So if you wanted access to those, you had to hack in and access them. And so you had to hack the mad scientists working at, you know, NASA and other places to get access to those things and they were very open systems. So I would tell you the first couple years that I responded to breaches, not a lot of people responding to them. Yeah, they answered the question, what happened? And that was read the freaking manual. I remember showing up and one of the things the Air Force did really well by 1996. If there was an intrusion on base, you know, the one star cared, the base commander cared. You had to brief that person. Yeah. Inconveniently often, inconveniently early in the morning. So I remember, you know, four or five in the morning, back then we did. Wow. Powerpoint was freelance. Making slides early, but everything evolved by, you know, I could answer this question over 20 minutes. The reality is by 1998, the criminal element is online and making money. These are making enough money to spread. Oh, absolutely. People are going online, unarmed and unprepared. You know, Windows NT was getting popular and you could start a website and accept credit card numbers and sell anything. That brings the criminal element. So I've always believed you're always going to have a certain amount of crime. You're always going to have a certain amount of espionage and both of those, the cyberdomain is perfect for both operators and those two domains. You know, wherever command and control goes, you're going to have the war fighter go. That's in the cyber domain. Wherever you have information, go, you're going to have spies go. That's in the cyber domain and wherever money goes, crime follows. So before we started, we were just chatting and you had to turn your phone off because people call you all the time. Like sometimes when they're calling, it's very often a billion dollar problem. Like the 4200, they call you. How did they get to that point? Like you started this company, Mandiant, like what happened? So I'm in the Air Force from 1993 to 1998. When I get out of the Air Force in 1998, one of the things I did is I trained a lot of FBI agents starting in 1998 as a contractor. The FBI is a critical component to imposing risk or repercussions to folks who compromise networks. That's why for multiple decades, Joe, you are not hacking from the United States. If you were, you got caught. There were penalties. You could not really act anonymously, effectively in the US. We could pierce anonymity and do well. So I'm training FBI on how to compromise networks and then how to investigate those compromises. Kind of like back when they did bank robbers, they kind of, if you can investigate bank robbers, you're probably pretty good at robbing them if you could figure it out. It makes sense. So we were doing that for a while. And then right around 2004, the reason I started in Mandiant, self-funded company profitable since day one is we had a premise security breaches were inevitable. What we had seen was an unfortunately the first generation of cyber security was anivirus. And I literally believe that anivirus was so easy to circumvent. We could teach FBI agents in the classroom who were not malware developers. How to circumvent anivirus in under three minutes. Compress and encrypt malware. And you got past anivirus. So I remember thinking if you believe anivirus is protecting your systems, it was like believing in the Easter Bunny. You know, I mean, it's not going to work. So I'm sitting here on the front line seeing that. So the premise Mandiant had in 2004 was it is critical to own that front line. See what adversaries are doing in the cyber domain. Which I had seen since 1993. So I realized I was lucky enough to be in the military where I had a front row view of, hey, China Russia really doing this. It wasn't making the press. There wasn't really severe impact or to breaches back then. The business impact started in the late 90s. And so with that background, I felt, let's respond to every security breach that matters. And believe it or not, Mandy was actually an endpoint company. I just executed so poorly on that dream. Nobody knows it. But we were building an endpoint to detect what Symantec and McAfee missed. And I fund them and I'll leave you with this. I think Symantec and McAfee had flawed models. No offense to those companies. I respect them both. But the flaw was this. They were like, if Ari and I virus misses something and you find it, you submit it to us in our databases, we'll get better. Well, nobody catches it. It's already too late. The average human sitting in their home is not gonna find malware. So what we were is we're gonna respond to every breach that matters. Find it and we already knew how to circumvent all the endpoint safeguards. And we'd build a better endpoint that it would detect, you know, with that front row seat to what adversaries were doing, we would detect what everybody misses. And since that time, George Kerz and CrowdStrike kind of went on the build, what I hoped to build. So that's, you know, George and you are all allies in your new chapters. Totally. And then Google ended up buying, buying me. I guess it merged with Fire. I Google bought it ultimately. And like, what happened? Well, yeah, use fast forward it from 2004 and I started manuals. That's a respond to every breach that matters. The reason we were successful is nobody believed in the premise cybersecurity breaches are inevitable. Everybody believed that, hey, you're wrong. We're gonna stop this stuff. It's not gonna happen. It says that they needed you to fix it. What's it happened? Yeah, we would answer two questions. What happened and what to do about it? And that's important, meaning we'd have to remediate it as well. We couldn't just say, hey, Joe, you got 10 dark sticking in your back and, you know, we got to kind of pull them out. Make sure they can't get in again. You got it. Absolutely. And retest networks and make sure it doesn't happen again. And the unfortunate reality in the cyber domain, for a lot of companies, it's hard to know or appreciate the threat until something bad happens. And then you go, okay, now I get it. And a lot of companies accidentally underestimate the threat. I mean, I lived through a region 2020, Joe, and I'll never forget, one of the starting moments of my career, when I was CEO of Fire, I we were compromised by the SVR. There was a backdoor put in solar wind software over 18,000 companies downloaded the Trojan version of solar winds and we were one of them. And when we detected that, I'll never forget calling customers and telling them, hey, listen, we've had an intrusion, you know, and here's what we're doing about it. And I remember one of the our customers in the financial services literally said, how did you let this happen? And I almost lost it. I said, let this happen. We didn't let this happen. Where have you been for 20 years? When a nation state targets a company, guess who wins? Then nation does not the company. Where have you been? And this is a security professional. Here's the reality in cyber right now. You cannot expect great blue chip companies that constantly, every day, pitch a perfect game on defense against nations that are targeting them. It's just an unfair fight. So I've lived through that. But, you know, going back to Mandiant, we owned the front lines of incident response, it's called. And that became a valuable thing to kind of own. We became the seal of approval. If you've been hacked and you know it, you hire Mandiant to come in and figure out what happened. And when you go public and tell your shareholders and tell the world, here's what happened and here's how it won't happen to you if you do the following, we really kind of further that discipline along. It sounds like you have a really interesting job where you don't even know the day is going to hold. Like tell us about an interesting day at work. Well, you know, I've had a lot of interesting days. Here's the good news. Being a public company CEO has its downsides. You know, you do your quarterly reporting. You talk to a bunch of shareholders. And I've always liked in that moment too. You know, if the Miami Doffins lost, I never got the call, damn arena and yell about it. Right? But you do get the call to CEOs and yell at them. And let's just say it and, you know, always have great quarters. Did our best though, believe it or not. But I can tell you what was the best thing about my job is that anytime Joe, I can get involved in any case. My phone would ring and I'd get things like, we think North Korea did this intrusion. And I'd be talking to my guy's gun, you've got to be kidmire. There's no way they did it. No, I think they did. You got to come see this. It's like Sherlock Holmes. I can tell you one where a government agency hadn't seen the SVR on a network in years. They were so good. The rules of engagement were, if we showed up to investigate the SVR, it's like they knew we were there and they never let us observe their trade craft. They just didn't do it. In August of 2015, one of my teams calls up, and they'd always heard me say, I've tapped the SVR a bunch of times and they just evaporate. They're ghosts. And they're like, they're not ghosts on this one. And their whole doctrine change. I remember I literally flew in. I was like, I don't know what's on my calendar today, but I'm getting the hell out of here. I'm fine to DC. I'm gonna show up. I'm gonna see what my team's doing. We saw it was no doubt in my mind I was looking. That's the SVR operating. They know we're seeing what they're doing and they didn't care. Those moments to me, the rules of baseball changed. You know, I had 20 years of responding to SVR. They never hacked it and then released data. They suddenly did that in August 2015. They always hacked for security reasons and all of a sudden we're responding to them hacking universities. I'm like, oh, they increased scope. And then they always did, in my opinion, admirable counter forensics. You're like, where are they? They're gone. They would always go away. It was almost like a gentleman's agreement. It caught us. We're out for a month. We'll be back at a month. But then they came relentlessly every day. Those sort of things have happened. And I'll leave you with this. I've had CEOs call some of the best calls I've ever had. I don't even know how to get my number. I'll answer my phone. I'll be driving on the highway or walking my dog, both of those have happened. We're like a Fortune 100 CEO goes, we're getting ransomed. They don't even say their name. They're like, we hear you're the guy to call. We're getting ransomed and a couple of expletives. We're not paying. You know what I mean? Did you just go, I get it? By the way, that's important to know. You used to go, okay, they're not going to pay. That's where they're at. They're aggressively taking a stance. But at the rails, you're holding a day. Because then they go, can you get people here? And you're like, oh, yeah, I think. And you usually have the rob Peter to pay Paul on those instances. But I've had many days where you get a call and the problem being presented to you becomes your 100% problem. I personalize it. So when I get a call from a CEO, I'm being ransomed and dammit, I'm not paying. All of a sudden, my internal dialects, like dammit, we're not paying. So it's a fun job in that way. I just kinda like you get to be a GIGO. You got somebody's got to show up and help these people. Nobody deserves to be hacked. Nobody deserves to be shut down. Nobody deserves to have their email posted online and read by the press. I mean, it's ridiculous. We've got thousands of cybersecurity professionals that have answered the call. And that's the good thing. So everyone in business knows your name because of that. Like all the talk guys are calling you. How do you keep up with that when there's hundreds of people calling you with different breakings going on? So one of the things that I've always had is the, I don't know, it's empathy, sympathy or all of it. I feel the same violation of it them does literally when they get breached. Nobody deserves it. I don't care. It's kinda like you don't deserve to be robbed because you had a few drinks at a bar and you walked out and you're a little bit susceptible to it. I've not responded to breaches where people were negligent. You know, some of the biggest breaches where you have someone beaten up, how could they let this happen? Like the story I just told you, almost every CEO I've met and every say so I've met is trying to prevent the inevitable breach. They're hiring good people, they're buying technology, we're getting better at it. And you know, so every time I get a call, it's kinda like it's good versus bad. I mean, it's good versus evil. It's like there are people with no risk of repercussions. During our podcast, probably over 1,000 Americans are gonna get duped, scammed and lose money in the cyber domain from folks that are untouched. - That's not touchable to our law enforcement. - Why are they untouchable? - They're in Russia. You know, there are other nations where they have a safe harbor. You know, North Koreans are hacking for profit, literally government agents in North Korea and uniform are hacking the steel Bitcoin. You've got, and we are the tackling dummy in cyberspace, you know, our consumers and our folks and our organizations. And it's frustrating people take advantage of the immunity. The fact that there can be 10,000 miles away, have scripts running and make money off of it. So there are a whole, probably thousands of people that make their living off cybercrackers. - Have you ever got any of those guys arrested? Or is this like-- - I think the FBI pursues them as much as possible. I think companies like, you know, Google and Microsoft and others in Amazon, everybody wants to impose risk of repercussions. We could always do better because that is it. That's why nations were formed, right Joe? Protect citizens from bad guys. - Yeah, I wanna reach out and get the bad guys up. - You guys. - I think you gotta do that, but it's hard to pull the levers. I remember, you know, when North Korea hacks into a company, I always scratch my head and go, what lever is there diplomatically? You know how I'm gonna know? And what lever is there for Russia right now? And I don't know if there aren't any, but you gotta make it, here's what I can tell you the win is for the United States. Anyone who hacks in the democratized West should not get away with it. That you have to impose risk of repercussions to those folks. The best deterrent for all cybercrime, I don't think you can deter espionage that to fuel gold through the gold post. Nations will spy. But when you look at the criminal element and ransomware and things like that, nobody wants to tolerate that, we have to have a structure in place or nobody gets away with it if there's a nation in the West. - Sounds like something good to work on. I wanna ask you a little bit about talent as well. - Sure. - So we're obsessed in Silicon Valley with talent and the very, very best other ones to build the top companies. And one thing you use to talk about is that, I guess there may be like 150 people in the world who really knew all this stuff, really well in cyber. And you, I guess you have like 40 of them in Mandiant. Like tell me about that. - Yeah, well, whenever I said it must have been a long time ago, because things have changed. Early on when I started the company, there was very few people responding to security breaches. I knew them all. You know, you had a small group at Verizon doing it at a company that was once called CyberTrust. You had a few other small groups doing it, Matt and Chicago, and we knew each other. You know, you could call them up, "Hey, what are you responding to? What are you seeing?" And, you know, But it's balloon since then so whenever I said that decades ago Now there's thousands of thousands of good folks, but here's what I can tell you when you're responding to breaches You're at the high end of the food chain. You have to have no windows. You have to know unix You have to know routers you have to know infrastructure if you don't know it You better read the freaking manuals and figured out because the stakes are high. We don't do security be compliant We do security to protect ways of life. We do security to protect our businesses and let them operate so I've responded to breaches Joe where people have asked will the company be solvent after the breach and that crowd shouldn't happen, you know So looking at talent Security you got to get it right and what I've learned over time is If you're doing brain surgery you want to brain-surgeon You don't want to throw a bunch of other people out 50 to 100 people that don't get brain surgery You're not gonna work aren't gonna make good brain surgeons That being said you want to scale the talent now I've kind of lived through that and you know when we talk more about AI talk about a way to scale talent its emerging tech Because we had to scale it the old fashioned way we would respond to breaches and Figure out the fingerprints and trace evidence of every breach we responded to that led to us having a threat intelligence unit That threat intelligence business became hundreds of millions of dollars force But it was really a side car to we just needed to scale You know we needed to shop and go who we're up against and look at the fingerprints It's this group and we can bucketize the trace evidence and just track people faster You know, but with emerging tech and the shift changing the AI my god you'll be able to scale expertise Well, let's talk about let's talk about that because you sold your company to Google sure and and and you know All of a sudden all these new possibilities have emerged all right so so like there's new thread What made you want to get back in the arena with AI? Well, I can tell you for all the founders out there I didn't sell my company And so if you build a great company and your public first off your public company you are for sale every day And your price is published out front and like like your house is for sale the for sale sign You know it is what it is But if you build a great brand and you're the best and will it's something things like getting bought by Google can happen Yeah, so that did happen, but you you look at Post Google and I enjoyed my experience there But when you're founder and a public company seat you and you get bought a lot of times You know you go in like a line and you come out like a lamb sometimes you're like I'm ready to change the world and it's hard to do that When you go to you know companies with a lot of incumbents and a lot of great talent You know, so there's always another chapter usually, you know, so I'm you know getting into that next chapter What's made it interesting to go in again because I think obviously you need a lot of money You've done really well like other new threats with AI or new facilities. No, it is impossible to sit on the sidelines You see the AI shift change comment. Are you kidding like oh, I could be no fads. You I could be an investor You know, baby. That's what you do all the time But for me I was sitting there going in security. I haven't actualized my dream jet We still have victim companies and you can see the future crystal clear right now in cyber You're gonna have AI agents on offense automating incredibly talented humans, you know like literally that brain surgeon analogy AI agents will be that and You're gonna have swarms of agents that can communicate and think and instantiate normal and learn and have total recall and Operate at a scale and scope where as we go from human led offensive operations in cyber space for crime and espionage to AI led agent led espionage and cyber crime That shift change is real and we've got to create systems that prepare us for it It sounds like even just a few months ago everything changed where the agents got good enough to work together It's better than people is that is that right? I think here's where I can tell you having you know We're working on this is we've got experts and we've got AI native programmers in the room together Yeah, what I can say is we're Almost every few days our experts are startled at What AI agents can do, you know writing on Python code and refining it when they find Remote code execution capabilities or vulnerabilities the amazing thing about AI shift change it reminds you almost like when we all went to cloud You know and we started using AWS or something where instead of calling an IT guy and waiting 15 days to get server set up Something was cheaper better and faster when we went to cloud and that's why cloud won out of you know doing everything on prem when it comes Day I think you're going to get a whole bunch of security capability. That's the same thing. It's going to be better more consistent and Costless I mean it's a win-win-win across every aspect of efficiency and cost that you look at But if these agents are surprising even you with what they're figuring out based on what you know They're getting cheaper every day too by the way Yeah, one of my big fears for 2026 and the reason why I have this chat is that these things are getting so much better that a lot of Operations and governments aren't ready for it and are ready for what's coming. Yeah, I think when So they're not right, but they know about it It's it's I haven't met a business leader that doesn't think AI is going to change cyber security They all know it and Sooner or later the beast is going to come out of the cage on offense Yeah, that's going to hit us in a way where we and it already is in social engineering like you will have spearfishing or fake emails designed to do people. Oh, yeah, that is context appropriate I get these all the time from the right people. Yeah, they're indistinguishable in reality from Emails you get I mean it's amazing what people can learn you're gonna start seeing social engineering automated Where six seconds of Joe Lonstayles voice is gonna be used to get a help desk to do something You know, so you're gonna have AI attacking on offense and it's asymmetric by the way That's the unfair fight. It is way more costly on defense Then it is on offense one person on offense can create work for millions of people. That's the asymmetry So you'll get a cost. I think AI will advantage the offense in the near term But everybody knows that and everybody's waiting to be able to We're gonna have a total shift change in cyber security where you'll have AI agents on offense Being the cheapest way to create that autonomous no human in the loop Confidence of that your defense can stop the most modern attacks, but that's years away and it's being developed now We have to develop it fast forward two or three years Joe You're gonna see an autonomous defense Crafted trained by the world's best cyber offense. You know the hyper talk platform just to put our listeners at a little bit of ease There's all these new ways that AI is going to be able to break into everything right you are you are quietly in touch With the very state of the guard with our government some of some companies and they're the comment you for help on this Yeah, everybody's getting ready for it and in reality no modern nation even the folks that can create this capability China Russia others will leverage it Even they don't want it really no one's ready for Everybody's gonna hold the beast in the cage for a little bit But if like someone in Eastern Europe gets access to an open Chinese model and they iterate on this Criminal element. It's not gonna be so there's three we categorize about you guys in three groups, right? There's there's a financially motivated there's maybe this anonymous Vandals and then there's a nation states like which one are you most word by 2026 and there's also thresholds too Like if you have ideological conflict that probably brings you off and it's only 80% of its potential But what if you have kinetic conflict? Is that unleash 20% or probably? There are certain industries that you would want as a nation's leader to withstand 100% of the cyber offense you want the grid to stay up you want utilities to function when your water to still be pumping you want Schools to stay you want lives to be normal So you got to figure out how do you protect critical infrastructure during times of real duress in the cyber domain? The criminal elements come in no matter what you know what I mean and every technical advance is embraced by a criminal element to make money into advanced Their trade craft. I think the first thing I would do is figure out how do you focus on critical infrastructure and make sure its risk profile can Operate through a full court swarm of AI comment and we're still early on in this But I think it's gonna happen incredible speeds so you're gonna have to see in Joe You know you're an innovator We're also gonna have to do massive innovation on defense. There is no question that in the future You have AI agents on offense run by the good guys to train the a on defense run by the good guys Well, if I was if I was a state with utilities I was in charge of I'd want to be hiring guys like you to show me how you break into my utilities and it so I can fix it Right, you should never the number one question every single CEO really asks when it comes to cyber security in many different forms is Are we secure that simple what's worst case scenario what can happen the only way to answer that question? Is in a safe and simple way you shoot the bullets at the best to see what you can stop you have to simulate wartime You have to simulate unfortunately in the cyber domain There's a pretty high-level percolating home of offense even during times of peace, you know You got to really make sure you can withstand the attacks that are out there And by the way, there's no the way to get on Varna's truth Joe if you want to know how good your security is You just got to test it you can't read the manuals and go with the 38 different products or run and we're good to go You really need to know is our defense That's been kind of duct taped together and massaged over many years Capable of a standing a modern attack so thinking about AI in terms of these attacks You're different alums a different capability different rules, right? So if you ask collage area next split It's really hard to get it to do it. They're very big on that some other models will I've heard XAI Although obviously won't do certain things this easier to get to do things the Chinese ones might be even easier like what's the situation here with this? I think you know models leapfrog too, right? So you want to you want to always I think regardless, you fast forward, the models may have gates that prevent you from doing things, but even those folks that make them probably need to remove some of the gating factors because it's so important to make sure there will be models that can think, learn, and do incredible things that aren't gated. That are going to be used by the criminal element. We don't want to sit there and use those models to create software that tests American organizations. So we want to use our frontier models. What I can tell you right now based on a lot of R&D in this space, the frontier models are doing an exceptional job already in helping test the security of networks. They're changing so fast, Joe, I'm very confident, regardless which frontier model you use, you're going to find it's outpacing humans doing the work. If you think about what software has always been the automation of human process, with AI coming, "Oh my gosh, you can automate human thought now." You can literally, in many ways, automate the complex step so there's no more if-then-else statements in software. This stuff learns. It learns when you train it. It starts surprising us. I can tell you one of the things that we did at my company where we trained an agent and we would just get a prompt and we'd type in questions and how clearly and how appropriately we would answer them after we trained it. Doing more than we expected sooner right now. I know we're not talking too much about your company because you're not putting it up there too much in public, but you're obviously hiring a lot of it. Really top engineers doing amazing things. What's the need for lots of engineers of AI's doing all this stuff? How do you think about that? Yeah, that's a great question because when I was at FireEye, we had four or five hundred engineers. I can't imagine having that many at this point. I remember we want to build the whole hyper-attack platform. Everything a nation state would build on offense. We want to build. People would be like, "You can't do that. You're creating weapons. We're creating them because you have to. It's what you're up against." We have to create it to create an autonomous defense that can withstand the swarm. It's common. That drone swarm and cyber will be coming. The difference with that total recall it has that humans don't have. The instantaneous communication between different agents that have different objectives so they can coordinate at a speed. Humans cannot. This has to be prepped for us. You have to build it. A lot of folks have said, "Oh, you can't build all that. You absolutely can. We'll prove that." I think you can build it. Here's why I will tell you. Parent contrast yesterday's engineer from Fire I Days to tomorrow's, well, today's engineer and AI. It's not 10x. It's more than 100x productivity with an AI native developer working on software. We've had over 100 commits in a day building our software. We have a different demo every two to three days. I never had that before. It is one day maybe Joe will have a metric there, but the productivity today feels to me like hundreds of times greater than he would. Even three or four years ago. That's amazing. You're obviously starting with a really, really top AI challenge. I'll make it up to Kevin Mandi and anecdotal. It's not 10x though. It's way more than 10x productivity. How does this stuff roll out in general on our society? Let's say you're going to build this. The governments are going to use it. The corporations are going to use it with a CEO who's listening to this. What should they be thinking about doing? CEO's want to know, what can I withstand? How good am I at security? Am I secure? The frontline headline I just read about on the breach. Is that, am I prepared for that? It's all the same question. How do I withstand an attack today? I've been in a lot of boardrooms and chief information security officers usually breathe their CEOs with these four-dimensional pie charts that show were green in these areas and were red in these areas and were yellow in these areas. The problem with that is a CEO doesn't know how to feel. If they see green, they don't believe it. If they see red, they're ticked off. They're like, why are we red and access control? If they see yellow, they're like, what's yellow? Some people change colors and not be alarmist. Here's reality. The only unborn is true. CEOs really want to do is can someone hack in and steal my email. Can someone hack in and get to our critical assets or covered data and steal it? Those things should be tested every time your network changes or the threat changes. CEOs get that and they want to test it. There's never been a way to do it without humans. Humans can only do one way in at a point in time. With AI coming, it's going to be, here's all the ways people can get it. They can get it all the time. You have to fix it because that is coming. The day where a human would break in and if you were 10 minutes behind the human on defense, you could stop the impact of a breach is going to end. There's going to be an agent that breaks in. Then another agent uploaded because it had remote code access, remote code execution, and that agent's going to work about a thousand times faster than a human. You have to compress that window of exposure down the microseconds. It's just coming. Companies get that. If you're a CEO, listen to this, it's called red teaming. You'll wonder, am I compliant? That's table stakes. If you're in a regulated industry, you want to be compliant. That's the start for cybersecurity. You want to follow standards or legislation. You want to benchmark yourself. You'll get that three-dimensional chart on how good your controls are and how well you will stand it. A lot of mature security programs, the CEOs get debriefed on a red team that has a real objective. Could you shut the trains down? Could you shut the water off? Could you impact the quality of a product via an intrusion? Those things, boards get that, Joe. Like could somebody break in? Yes or no? It's very binary. If the answer's no, feel good. At three to four former operators on offense couldn't break into your network in five to six days. It's pretty good. Feel pretty damn good. That's the best you can do, by the way. I don't know what else you're supposed to do. That does withstand third party inspection or something bad happens. As I see, you know what? I tested that five days ago. Great talent. They didn't find it. What more do you want me to do? My products that I bought didn't stop it. They couldn't find it. To me, red team, the network, and it doesn't need to, in the future, be red team everything all the time. For now, it would be reduced scope. There's apps that matter most, the customers that matter most are people that matter most and just see how secure that really is. And it is not just a compliant dashboard. That makes sense. We got to have the very best people seeing if they are right in, I guess. You know, I want to talk a little bit about optimism for the future. There's a lot of fear of AI right now. In public, obviously, we're talking about some scary things AI can do. What's the case for the public being optimistic about AI? How do you think about this? You don't even have a choice. AI is coming. It's enabling people to do amazing things, right? It just so happens in the cyber domain, it's the answer to both offense and defense. That's the reality. And Joe, unfortunately, the cyber domain being a contested domain like air landed in sea, it will get weaponized in the cyber domain. There's nothing we can do about that. This is not something people need to be concerned about because the future is obvious. The good guys do have to weaponize it because they can train the defense on it. If the good guys have the best weapon in the cyber domain, that means the good guys will have the best defense in the cyber domain. So that's what you want to do. If you're a football team, wouldn't it be great to have Tom Brady in his prime on the other side training your defense? You get pretty damn good at defense. So that's what we have to do. It will be computers on offense at compute speed trying to break in. So get ready for it and on defense, just having an autonomous way to respond. It's no different than arms throughout history. The English create the long bow and the French go, "Oh crap, what's that? We've got to come up with some defense against it." Unfortunately, technological advances, advanced criminal element, advanced militaries. AI is no different in the shift change. It's just how it's used. But the answers are obvious and we're going to be a part of building it. I love it as the answer is the good guys have to be stronger than the bad guys. Absolutely. And it really works, Joe. That's the thing. It really works. Get the good guys to develop the platform that can help us defend ourselves, period. Well, we're lucky to have good guys like you as leaders on our team. Thank you, Kevin. Thank you. Appreciate it. (upbeat music)

Podcast Summary

Key Points:

  1. Kevin Mandia, a cybersecurity expert, highlights the escalating threat of AI-powered cyberattacks, predicting widespread financial losses and unpreparedness among corporations and governments.
  2. He recounts his career from 1993 in the U.S. Air Force to founding Mandiant, emphasizing that nation-state espionage (from China and Russia) and criminal activity have been persistent threats in cyberspace for decades.
  3. Mandia explains that traditional antivirus solutions are ineffective, and effective cybersecurity requires proactive incident response and remediation, as breaches are inevitable against determined nation-state actors.
  4. He shares anecdotes about the evolution of threats, including a shift in Russian tactics in 2015 and the personal impact of responding to urgent crises like ransomware attacks on major companies.

Summary:

The transcription features cybersecurity expert Kevin Mandia discussing the severe and growing threat of AI-enhanced cyberattacks, warning that many entities are unprepared. S. Air Force in 1993, where he first encountered state-sponsored hacking from China and Russia, to founding the incident response firm Mandiant.

Mandia argues that traditional antivirus tools are easily circumvented and that breaches, especially from nation-states, are inevitable. " Sharing key experiences, he notes a significant change in Russian cyber tactics in 2015 and describes the high-pressure reality of helping Fortune 500 CEOs during ransomware attacks. The discussion underscores cyberspace as a perpetually contested domain for espionage and crime, requiring constant vigilance and advanced defensive strategies.

FAQs

Cyber threats are persistent and sophisticated, with daily intrusions from nation-state actors like China and Russia, and the rise of AI agents that are becoming even more capable hackers.

He started Mandiant in 2004 based on the premise that security breaches are inevitable, aiming to respond to every significant breach, determine what happened, and provide remediation solutions.

In 1996, he responded to a Chinese intrusion into military systems, and later, a Russian breach where they exported and ran U.S. weapons modeling software from Russia to understand its functionality.

Initially, Russian operators were dominant in the 1990s and early 2000s, but by around 2019-2020, China rapidly advanced to have great capabilities and stealthy network access methods.

He believes traditional antivirus is easily circumvented, comparing it to 'believing in the Easter Bunny,' and emphasizes the need for more advanced detection and response capabilities.

In August 2015, the SVR changed its doctrine by continuing operations even when detected, hacking and releasing data publicly, and persistently attacking targets like universities, unlike their previous evasive tactics.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.