Go back

Scaling AI Without Compromising Security: Part 1

17m 58s

Scaling AI Without Compromising Security: Part 1

In this podcast discussion, the hosts explore key trends for 2026, focusing on the convergence of MSPs and MSSPs, which simplifies customer support by integrating IT and security functions under one umbrella. They emphasize the dual role of AI in both amplifying cyber threats—especially through advanced social engineering attacks—and improving defense mechanisms, such as reducing incident response times from minutes to seconds. The conversation highlights the growing risk of human-targeted attacks, where AI crafts highly personalized phishing emails, making traditional user training less effective. To counter these threats, the speakers advocate for a layered security approach, including passwordless authentication and continuous innovation in defensive tools. The overarching goal is to help businesses navigate an evolving landscape by adopting integrated, AI-enhanced strategies to minimize risks and improve resilience.

Transcription

3554 Words, 19500 Characters

English
Welcome to ECI Pulse, a podcast where we break down the latest trends shaping the business world. I'm Rich Eatery, the Chief Innovation Officer at ECI, and today we're happy to be joined by Jason Kaufman, Principal Solution Architect at Tularis. In this series, we're exploring the key trends that will define 2026 for partners, which changing, why it matters, and how to stay ahead. We'll focus on the most impactful shifts, including AI-driven analytics, security, compliance, and the move towards outcome-based selling. Our aim is to help partners understand where the market is headed, what risks to avoid, and how to build a reputable sales motion around this innovation. We'll share practical examples, lessons learned with Jason and I both have a lot of, and actual insights to help you navigate this ever-changing landscape. Whether you're refining your strategy or looking for new ways to enable your team, this series is designed to deliver clear and valuable takeaways. Jason, thanks for taking the time to me with us today in chat. I think both of us love talking about technology, and there's certainly a lot to talk about these days, right? When it comes to the current marketplace for MSPs and MSSPs, and I think that's really a great place to start. What I see in the marketplace today is a steady convergence, really, of MSPs and MSSPs. When you think about going back several years where everyone always wanted that separation of church and state, as people always would say, but when you think about cyber, and I think more and more companies have started to realize this, cyber is really all about good IT hygiene, and your MSP really drives that hygiene, and that convergence now between MSP and MSSPs is real. We see it every day as we're an MSP and an MSSP, but we see ourselves as both, right? I think when you think about the evolution now and the hyper transformation going on in the marketplace with AI, having that convergence has never been more important. Yeah, and we're seeing the same thing. The only thing is we want to make sure that there's some due diligence on the separation of church and state within an entity. The SOC team is not the same thing as the NOC team. The team that's actively on the offense of protecting the cyber security is not the one that's defining the MACD work, but it makes it much more simplistic when they're under the same roof, because if you need to make a change over here, you see a gap or vulnerability or something. It's much easier calling within the same company to get that resolved, rather than, oh, hold on. We're the MSSP. We don't have access to this. Let's hang out the dial that's out of the company. It may not be 24 by seven and get them to make the changes necessary in order to get back up and running or make sure we patch this vulnerability. So, yes, definitely the convergence between them makes it much more simple on the customers. We also like saying instead of one throat to choke, one throat to hug, it's much more romantic. Yeah, that's a very elegant way to put it, but Jayce, you bring a really good point. I think it's something that people should really take notice of, is within the company. As long as they're functionally separated but integrated, it's the way that I always like to frame it, our knock team is separate than our sock team, but they know how to work together really well. They know how to escalate to one another, and they know how to escalate even beyond their teams, to other engineering type resources that might be needed, but they all are separate functions and have their own checks and balances along the way. Yeah, everyone says he always pitches that playbook. How do we escalate and how do we treat these different severity, priority alerts that come in? It's much easier when it's all under one umbrella rather than, oh, priority one, I need to pick up the phone and dial these. I need to have this communication plan to wake up the customer and let them know or having multiple entities within that runbook is much more difficult than it is. Let's just reach over to the other team and pull them in. It's under the same umbrella, so it's easy to do. Yeah, look, as a former CTO myself, I had, you know, when I was back on the other side of the fence, I had an MSP and an MSSP, and if I would get woken up at three o'clock in the morning, well, first off, I would be frustrated that no one else in my team ahead of me picked up the phone, but then I was up making sure that the handoff between my MSSP was happening, right? That someone else on the MSP side was picking up the ticket, they were doing whatever they needed to do on the endpoint, closed the port on the switch, whatever it might be, whatever our playbook was for that particular incident I was watching is the ticket being processed. I'm sitting there, you know, on my phone at like three thirty in the morning, and that simplicity where they could execute end to end is really valuable, right? And it's even more valuable now than it was when I was on the other side of the fence because the risk of gotten more dynamic, they've gotten more frequent, you know, more difficult to reign in, and with the advent of AI and all the hyper transformation where we're seeing in the marketplace, those risks are only going to increase. Yeah, and they're much more, they're much more fast when they land in expand, or they're just sitting there dormant doing their due diligence and determining a time to attack and make themselves known, you know, having that quick response time, that's why the whole AI sock thing is coming out and all that stuff is how quick can we, can we react to AI leveraging AI? So yeah, exactly. Our job is to make sure that we minimize the headache of the customer. And however that sees fit, and ultimately we're seeing that with the conjunction of the MSP MSSP practice, leveraging AI to compete and combat against AI. So I think exactly what you're saying, AI is not only a great benefit to have, but it's also maximizing the threats, because we're also having the threat actors that are now powered by AI. So how do we compete with that? And it's the fact of continuous innovation and continuous defenses versus how quickly can they, can they innovate for offenses? Yeah. Well, look, you bring up a good point, you know, I have the luxury of, you know, both overseeing our own internal AI solutions that we're doing to help, you know, really optimize workflows for our customers and really create a better client experience. I also have the, you know, opportunity to work directly with our clients on AI enablement, implementing the right AI technologies, implementing them in a secure, compliant way. But I think to your point around, you know, look, the environment and how dynamic it is and how it's moving, you know, for us, you know, AI is not really about cost, right? When it comes to internal use, AI is about speed to react. Like, think about, and I say this even to our clients in general, like over the last five years, like the pace of businesses just increased so much, right? It's really hard to keep up with just everything in and around your, your business. And you know, look, the threat actors know that they flood you with, you know, whether it's phishing emails, scanning of your external environment, and it's never been more important to be able to react faster, right? So I, I tell our clients, our investment with AI, you know, internally is really about being able to respond to these risks, right, in this environment in a much faster, like, salient way, right? And, you know, look, we're never going to eliminate human from the loop from everything. But if we could distill things down, if we could show something is benign versus malicious and give the socket analyst something to, to really dive into quickly, right, and take that risk, they used to take 15, 20 minutes to diagnose and remediate, and we could reduce that down to five. That's a big deal, right, because that five minutes could mean my K, someone else clicking on that same email or where things like that, right? So I think AI is helping the threat actors, but we also, right, as providers have to react in kind, right, with leveraging the same type of tooling to mitigate some of that risk. Yeah, you're severely mitigating the impact of a potential breach just by doing that, and you're enabling the SOC team to be, you know, much more veteran than they really are. It can take a beginning team coming in, and if you have AI that could pull all this telemetry together, it's doing the root cause analysis as far as it could take it. Hey, we've tracked it down this attack path all the way to this endpoint or this switch port or this firewall port, whatever it is, and then giving that data to the human to react to it immediately with all the data after, you know, going to the CBE reports, the MITRE Tech Framework, pulling all that data in and saying, hey, not only did we track the data back, but here's your next five steps that you potentially take, and what we've already done on your behalf. I mean, you significantly impacted how well somebody can react to something and how quickly they can, because all this due diligence and all this due care that's being done by the SOC analyst to pull this information, just to be able to do some form of action and react to something, it would take, you know, minutes, hours or however long it took to access all these different systems, now AI is pulling all that together within a matter of milliseconds or seconds. So yeah, your reaction time is boom, and that just severely makes it much more valuable for an MSSP that does this at scale. You know, we had built stuff to examine phishing email, like pre-AI, and we had to take it in from, used to take 18 minutes, we had gotten it down to eight minutes, and now with our more advanced tools, we added down to less than 90 seconds. So we can tell if an email was malicious or benign, we could then check 10 different sources, and we can remove that email from everyone in the firm's inbox, and we can do it all in 90 seconds. So we used to take us 18 crazy how able to collapse that. Now the bigger problem is all that stuff getting through, and that might be a separate podcast that you and I have to do around, like, how to mitigate some of that risk, but, you know, Jason, you talk with, you know, clients and partners a lot, right, Ed, you know, we started touching on the risk around AI, like, what are you hearing from partners and clients around the AI risk, and concerns they have, and what they're looking for from the new kind of generation of MSPs, MSSP's. I mean, most of them are actually surprised to hear where the major AI threats are. They're assuming it's a threat actor sitting in, you know, a basement somewhere with a hot pocket, you know, just going to town on some networking gear, leveraging some AI, doing some scanning. I mean, yeah, that is a threat, but the biggest threat is exactly what you were talking about, that email security, getting somebody that's already authenticated and has access to the systems because they were designed to do that, to do their job, hacking that person rather than some form of electronic or networking gear or something like that or a firewall. It's much easier to hack the human because of human air and give them some more tailored email that says, hey, we got you free Starbucks's Employee Appreciation Day from, you know, here's from the CEO and it's off by instead of an O in the email to zero, you know, the domain look alike, you know, those threats are the real ones that everybody needs to protect against because when you're looking at all this different telemetry points and the surveys that go out on how breaches occur every year, it gets higher and higher on which ones are attributed trace back to a human element that caused it. And it's all from, you know, now being able to search social media and search something to where you can get the background of somebody with just a couple of scripts within it within or an input within an LLM, you can say, you know, hey, give me some information on Richard. I want to, you know, produce an email that's custom tailored to him and it will pull all this data from the dark web, social media and all that stuff and make it very personable to where it actually, it seems like it's coming from somebody that knows that person intimately. So they're much more likely to click on it and then enter their information and now that's where we're getting into, you know, multi factor authentication, password list because, you know, you're significantly impacting how much less they could give out, but it's much easier to hack the person that it is to hack a network because everybody puts in all this, you know, all this mitigation techniques and all this budget into mitigating networks when they should be training users and teaching them what the power of AI is on the other, on the other side of the fence. And that's where we're seeing a lot of those like heads, you know, those heads in those reactions are like, wow, I didn't really thought of it that way. I should be worried about the accountant or the lawyer that just clicking on things and just doing their job and clicking on the wrong thing and giving access to somebody inadvertently rather than, you know, somebody trying to hack in externally and breaching from a vulnerability. I just had an opportunity a couple days ago last week, it was a six, not a six year, that was a different one. It was an eight user real estate firm to where they're more in the general construction area, but what happened was there were six different iterations to where the accounts payable person sent a different, you know, direct deposit to a different account because they thought an email came from the CEO and they never thought to pick up the phone or walk over the CEO's office to verify, you know, pick a different medium of communication to verify it. That's really the correct, you know, transaction. And they sent out six transactions, totaling $500,000 each one was incrementally more before they figured it out. So, I mean, luckily they got a lot of it back after getting with the FBI and, you know, we started working on mitigation and all that stuff, user awareness training and what's new in AI, but they still didn't get everything back. And that's significantly, significantly impact the business bottom line if, you know, uncontrollable costs that just go out the window without being part of any revenue coming in. And unfortunately, that's what AI is now in the threat actors. The social engineering aspect now is gotten so complex, right? It used to be before you could read these emails. They were misspelled, you know, just super like, you know, generic, right? And you could train users and they were able to sniff them out, you know, pretty easily. But to your point now, email. Yeah, exactly like the Nigerian friends, right? To your point now, AI is so powerful. I remember we had some interns working over the summer and I said, Hey, what's really useful to me is that I have a meeting come in that's externally. Can you create a series of agents that can like debrief me on who I'm meeting with, what the meeting is going to be about, give me details with it. And I'm really interested in our clients, right? So if it hits our client list, here's how to do it. I laid it out. And it built something really quick and it came my office one day and it was like, they may have built it in less than a day. And they like, what do you think of this? And I tried it out and I'm staring at it like in shock and they're like, Oh, is it really that bad? I'm like, No, it's that good. And now I'm thinking like what the threat actors right on the other side can really do. Like the amount of data I'm able to get just by going out and scraping the internet and being able to construct like a concise agenda for a meeting. It's crazy the how powerful these tools are. So you can get these emails that are really convincing, right? Like, you could say, Hey, you know, so and so in the accounting office, it was great, you know, at a team dinner last night, because maybe they straight, you know, linked in or other social posts about like a team dinner, Hey, by the way, I need you to get this wire out to this client. Here's the information. Can you get this done as soon as possible? Let me know when it's complete or if you have any issues, right? Any talking last night, whatever it might be, right? And like, it's so convincing and it's the CEO and it creates a sense of urgency and all those things you see in those emails. And it makes people act like, you know, the example that you gave. That's why I think it's really important that, you know, as technologists now, we really need to understand the threat landscape and think about defense and depth, right? And you mentioned password lists, right, as, you know, as an item there, you know, we're pushing to get all of our clients on password lists over the next, you know, 9 to 18 months because, you know, emails are going to get through no matter how good it is. If you can begin to think about, well, if they don't have passwords anymore, there's no way to capture an account. There's no way to capture their password. So now I'm eliminating one part of that risk, right? And you can begin to kind of pierce into the stack and say, okay, if I can get better tools on the back end to recognize things like new domains or like where does content come from and I can tell if something's malicious or benign, you can begin to build a slightly better, you know, defense structure around some of these things. Yeah. And all the, like survey teams out there, like Gardiner, Frost Solven, you know, all those big name players, they're all determined, like redefining what defense and depth is and what the new perimeter is. It's no longer, you know, that edge appliance or the cloud infrastructure. It is the persona. So how do you, like, how do you defend that persona and you take away a lot of the ways that they can make a mistake? Many different, you know, from mid market up to enterprise, even SMBs are starting to talk about, you know, how do we, how do we remove passwords from the equations? Because now we're starting to get to, you know, getting, getting our cybersecurity insurance redone and getting a new policy and all that stuff. And it's moving away from having multi factor authentication and very strong passwords, there are at least 12 characters and 15 different types to, let's just remove that all together. It's severely mitigate the threat landscape to where somebody doesn't have anything to get out. It's much tougher to give out your biometric scan than it is to give away something that you know, which is just a username and password. So they significantly decrease the, you know, percentage chance that they're going to have a payout because of removing passwords out of the equation. So I think we're going to see that and significantly increase as well to where that's going to be a forced mitigation technique, which is, you know, let's just remove passwords all together. If you want to have something you know, it's different than a password. It's going to be something that, you know, triggers after like a biometric scan based on a risk score or something like that, rather than just, you know, 12 characters.

Podcast Summary

Key Points:

  1. The convergence of MSPs (Managed Service Providers) and MSSPs (Managed Security Service Providers) is a significant trend, driven by the need for integrated IT hygiene and cybersecurity.
  2. AI is accelerating both cyber threats and defenses, enabling faster response times and more sophisticated attacks, particularly through social engineering.
  3. Human error remains a major vulnerability, with AI-powered phishing emails becoming highly personalized and convincing, increasing the risk of breaches.
  4. Passwordless authentication and defense-in-depth strategies are emerging as critical measures to mitigate risks and enhance security posture.

Summary:

In this podcast discussion, the hosts explore key trends for 2026, focusing on the convergence of MSPs and MSSPs, which simplifies customer support by integrating IT and security functions under one umbrella. They emphasize the dual role of AI in both amplifying cyber threats—especially through advanced social engineering attacks—and improving defense mechanisms, such as reducing incident response times from minutes to seconds. The conversation highlights the growing risk of human-targeted attacks, where AI crafts highly personalized phishing emails, making traditional user training less effective.

To counter these threats, the speakers advocate for a layered security approach, including passwordless authentication and continuous innovation in defensive tools. The overarching goal is to help businesses navigate an evolving landscape by adopting integrated, AI-enhanced strategies to minimize risks and improve resilience.

FAQs

The podcast highlights a steady convergence between MSPs and MSSPs, driven by the realization that cybersecurity relies on good IT hygiene, which MSPs provide, making integration more important than separation.

It simplifies operations by allowing integrated teams under one roof to quickly address vulnerabilities and incidents, reducing communication barriers and improving response times, often described as 'one throat to hug' for better accountability.

AI helps both threat actors and defenders; it enables faster, more sophisticated attacks like phishing, but also allows MSSPs to react quicker by automating threat analysis, reducing response times from minutes to seconds, and enhancing defense capabilities.

The biggest threat is AI-powered social engineering, such as highly personalized phishing emails that exploit human error by using data from social media and the dark web to create convincing, targeted attacks.

Organizations should implement defense-in-depth strategies, including user awareness training, advanced email security tools, and moving towards passwordless authentication (e.g., biometrics) to reduce the risk of credential theft and unauthorized access.

Passwordless authentication, like biometrics, significantly reduces the threat landscape by eliminating passwords that can be stolen or phished, making it harder for attackers to compromise accounts and helping meet insurance and compliance requirements.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.