Breach Ready Radio
Breach Ready Radio is a series of candid conversations with the practitioners, researchers, and security leaders who are changing how defense actually happens. These are the people building new approaches, experimenting with new ideas, and pushing security operations forward in real environments.
Each episode explores what they are working on, what they are seeing in the wild, and how security is evolving across the SOC, threat intelligence, AI, and incident response.
The best insights usually come from the stories. The investigation that took an unexpected turn. The tool that changed how a team works. The moment someone realized the industry needed to rethink an old assumption.
We talk to the people behind modern defense. What they are building. What they are learning. And how security operations is changing in real time.
Hosted by Sean Ferguson, Securonix.
Breach Ready Radio
Shadow AI, Zero-Days and the New Attack Surface with Cody Pierce | NeonCyber
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
AI adoption is moving faster than many security teams can observe, govern, or control. As employees connect new tools, upload corporate data, and use personal accounts for work, shadow AI can spread across the business with little visibility.
Cody Pierce, CEO & Founder of Neon Cyber, joins Sean Ferguson on Breach Ready, Board Ready Radio to examine how security leaders can support AI adoption while managing the risks it creates. Drawing on 25 years in cybersecurity, vulnerability research, and startup leadership, Cody offers a pragmatic view of AI hype, browser security, human oversight, and the guardrails businesses need now.
The conversation explores:
• Why observability must keep pace with AI adoption
• How shadow AI exposes corporate data and identities
• Why attackers are shifting toward OAuth tokens and identity compromise
• How AI could accelerate phishing, vulnerability discovery, and zero-day activity
• Why a critical CVE may pose little risk to a specific environment
• How cybersecurity founders can validate customer pain before building a product
How much visibility does your security team have into employee AI use today? Share your perspective, and subscribe for more candid conversations with the leaders shaping modern security operations.
Listen to more episodes: https://podcast.securonix.com/
Learn how Securonix helps organizations strengthen security operations: https://www.securonix.com/
Explore browser-based AI security, shadow AI visibility, and workforce guardrails from Neon Cyber: https://neoncyber.com/
Welcome And Meet Cody Pierce
SPEAKER_00Welcome back to Breach Ready Radio. Today I'm joined by Cody Pierce, CEO and founder of Neon Cyber. We dig into how AI is changing the way employees work, how attackers operate, and why security teams need better visibility, stronger guardrails, and a faster way to respond as the attack surface keeps expanding. Let's get into it.
SPEAKER_01Cody Pierce, I've been cybersecurity 25 years. I'm now CEO of Neon Cyber, working on AI security and guardrails in the browser.
SPEAKER_00How did you get to where you were right now? What kind of were the steps that made you lean into more AI as you evolved?
SPEAKER_01Well, I think part of cybersecurity, especially for myself, is just the constant change of technology. There's always something new. Um, and part of cybersecurity is kind of understanding what's new, how that affects risk, and then you know, doing research, performing uh, you know, understanding it at a technical level and then extrapolating that into security. So, you know, just being having done this since I was a a teenager, uh, I've always been driven by uh novelty and new technologies. It I think it's really fun. And so with AI, I mean it it's just a it's one of those kind of C changes in technology. And we've gone through, you know, the internet to dot com to cloud to, you know, all these different huge changes. And I think those are the ones where I really like to dig in and understand the technology and what it can do and and again, you know, make help people be more secure through technological changes. So, you know, I'm I'm excited. Of course, there's trepidation with AI, but I think having been through a lot of those big technological shifts, you know, allows me to to help people. Um, and so I really have a lot of empathy and this is just the the next big wave that we have to ride, and and I'm happy to dig in and try to offer up some solutions or offer up some help or even just you know sharing with the community about what does this really mean? You know, what are what do we think this is going to look like in the next one year to 10 years?
AI Hype Versus Practical Reality
SPEAKER_00I'm immediately gonna drop into the hot take there because you mentioned the dot com, the rise of the internet, all really pivotal. But the pattern that we saw with that is it got really, really hyped up and then kind of came crashing back down to reality. Do you kind of see that with AI right now, where it's it's being very hyped up to be able to do all these things. Everything is a genetic, you have the agents that can do, you know, do parts of your work and make you faster. Do you see that we're coming? I wouldn't say a bubble, but I don't think a bubble is going to burst, but I think the dust will settle and then some of the reality will come in and the truth behind what some companies can do and what some companies can't start to kind of be seeing, or what the expectation of AI really is gonna be seeing.
SPEAKER_01Yeah, I absolutely. I mean, it's not I don't like the idea of like bubbles and crashes. I think that's a bit of a black and white way to think about it. I think with anything new, you're gonna have a lot of with technology, there's just there's it's nuanced, right? It's not ever a silver bullet, it's not ever this, you know, it's gonna fix all our problems. And I think what happens in that hype cycle is you get the dreams and the promises included in the reality, right? And the dreams and promises take 10 plus years to really manifest. But there's absolutely practical uses now, and I think as a practical technology, it's gonna continue to change the way that we think about you know, risk or maybe automating the mundane things, especially in security. Um, there's gonna be a really nice evolution on how we operate. And I am a pragmatist and and a realist, and so all the things about you know automating every piece of our life, like fine, that's might happen. But certainly in the next five to ten years, there's there's gonna be a a huge shift. I mean, it allows you to do, you know, to have I think what the internet kind of promised, which was you know, all of uh and again, this this may be a little bit of that dreamer in me, but uh, you know, all of human knowledge kind of accessible in a natural language way. And the ability to also use like the tool calling for agents is powerful, right? And so if it just stayed the same as it is today, I think it's still uh a sea change in the way we we do certain types of work. And then all those things that are you know futuristic and sci-fi will kind of probably get over that and wait, be more patient with it. And then the you know, the practical piece is we'll adopt it just like we did with cloud. You know we adopted cloud, we wanted to put everything in the cloud, we wanted to run infrastructure as a service on Amazon. Sometimes you realize, hey, I'll just run, you know, I'll just have an EC2 instance with like a virtual machine running something I would have ran at home instead of all these different microservices. You know, it kind of ebbs and flows. And I think the same thing will happen with AI.
SPEAKER_00That's interesting you bring that up too, because I remember seven years ago, alert logic, it was very much we had the we had double ICPs. We had the on-prem, the hybrid, and then we had the cloud. And now that almost the on-prem is almost non-existent within very like specific niches and use cases. And AWS hosts what is it, like 75% of the world servers now? It's like a mix between them, Snowflake and um and CrowdStrike, right? Uh correct me if I'm wrong there. They're a big oh as Azure too. Yeah. Which is insane to think. Like seven years ago, that was kind of where we would move, and now it's just common not. Yeah, just spin up a server, spin up a blanket or stuff.
SPEAKER_01Well, it's just economics, right? I mean, if I've worked in data centers and racking and maintaining and failover, you know, I got my start as a Unix system administrator working for HP on HP UX. And you know, certainly there's always gonna be on-prem, and I think maybe even AI is gonna make more kind of go back to some on-prem. Um, but a lot of that is driven by economics. Um it's just much cheaper, easier to maintain, easier to get good results faster. Um, and I think that kind of is is related to AI. If you can get results faster and um cheaper, uh people are gonna move that way.
SPEAKER_00And then I would I would I would say I'm more of an optimistic skeptic, I'd say. Like I like I like where it's going, and but I understand there there there are risks involved, and that kind of comes into you with the with the governance and the guardrails in the same way that we're kind of talking about outside with human in the loop. There has to be human in the loop when we're when you're not just deploying this agent uh production live to go run amok. Growing up during the internet, you know, the deep web, and uh I hate calling them both separate entities when they essentially are really the same thing. The deep web and the dark web was just the internet, it just existed there. There were no rules as the Wild West. And then you started slowly having these guardrails being put in place and and things moving off. You had uh open FTPs with hacks and malware involved there. So it's kind of us where I'm seeing AI right now, but also optimistic that similar to how the internet ran at similar to dot com and and and cloud computing, that those risks will be mitigated over time to where it just does become that standard. Yeah, you can run this AI and here's the guard girls involved with it, and here's your one person that's going to be watching it and making the decisions on mission critical things.
SPEAKER_01Well, I think I think uh what did you say? You were an optimistic skeptic. Skeptic. Yeah. I think that's just encapsulates cybersecurity, right? Like we're what what we're trying to do is uh uh adopt technology safely. Like it's not, you know, there's obviously uh deep, deep technical expertise, but what we're trying to do is make sure that we start out with a basics, we don't create more problems than we're solving, but uh you have to stay a little bit optimistic, right? Or or you're gonna be the security person that just says no to everything. And then people aren't gonna really want to to work with you, right? So I love the way you put that, and I I feel the same
Observability And Human In The Loop
SPEAKER_01way. With any new technology, it's I'd like to just say, hey, you know, the basics stay the same. You have to have observability, you have to have the ability to intervene, you have to have the logging, you have to have all those things, you have to see what you're trying to secure, and that becomes hard, especially when you include people who are excited to use new technology. So it may be one of the first times that we've had so uh fast adoption of a new technology, and security people haven't necessarily been able to get the observability into what's being adopted. Um because now you can have HR uploading documents to Chat GPT, right? And that security risk is accelerated because there's a new there's new promises every day with AI that may or may not be BS, but your departments and your company are gonna be excited to design a new website, to push a new website through Lovable, to you know, ask Chat GPT uh to rewrite an HR policy. Like those are things that are happening now and we see it all the time. And kind of to your human in the loop, which I fully agree with, um you have to just approach it from a uh a hygiene perspective and and build that observability and build those kind of systems because you don't really know the future. You don't know what technology is gonna win, you don't know if it's open AI or anthropic, you don't know what your CEO is gonna require, your CTO is gonna require, your CIO is gonna require. So you really need that dynamism to say, all right, I've got good observability, I know how to respond, to be that human in the loop, and I just get more automated and faster at understanding these things so that I can make those risk-based decisions for the business.
SPEAKER_00And that's a good point because the the risk is almost twofold. So you have the attackers right now who don't care about guardrails. And no less guardrails the better. And then they can utilize AI to minimize the amount of work that they need to do. And then on the other front that you were talking about, there is that human behavior analytics, but not malicious of just excitement and getting things in there. And nothing is foolproof, as you know, technology. There's no foolproof, there's always downtime in cloud computing. You know, the internet had its own things, the dot com, half of them went away, you know, when that when that kind of got over the whole hype cycle. Uh, but I think we need to get the hallucinations down a certain percentage before we start having the same right policy.
SPEAKER_01Oh, you why the news are supposed to be Yeah, it's we're we're just not ready. There's no I don't think people who have that skepticism um believe that you're gonna just have all this automated and it's gonna be perfect. But the problem and the risk is that a lot of people trust that it is going to be right, or maybe they don't understand the nuance of the you know, the intricacies of writing a policy or the intricacies of uploading data or the intricacies of all those things. So you mentioned kind of speed, and I think that's a big part of it, right? You've got to have the tools and capabilities to operate at scale with speed. Um often very difficult for cybersecurity.
Consolidation To Match AI Speed
SPEAKER_01So, what I kind of like to recommend as a you know, next 12 months for companies is you really need to consolidate, right? You need to consolidate your data, you need to consolidate your alerting, you need to consolidate your identity security. Um, you need to be pulling all that in because as AI does mature and and you are uh getting the observability you need, that centralization is gonna allow you to also speed up your response, uh, speed up your reviews, speed up all those approvals, uh, because that's what's gonna allow you to match the speed of what your users are doing, and in in a lot of cases, the speed of what attackers are doing. So it's always a dance with cybersecurity, but I think we've, at the end of the day, we've we have to move at the speed of business. And I've never seen businesses move this fast with a new technology that has all these nuanced problems.
SPEAKER_00At the same time, too, as you know, you're a founder of a company, you were having a lot more startups pop up now, too, because of this speed, because of this capabilities of things that they were able to do before to at least get off the ground or now getting off the ground. Um, to add to your two, I would say from my perspective, at least internally, and then talking to other colleagues too, um the process documentation is starting to fall off too, which is which is alarming because yes, the Chat Chat GDP, the LLMs, they're doing the process for you. But when you have these people leave, that process goes with it, it goes with their history, it goes with their chat. So then you have a now another layer of complexity internally on that. Um that's great. Yeah, definitely it's we're in a very, I'd say, pivotal interesting world. And one of the articles that I read too, it was certain lawyers who basically ran the Chat GTP to go find cases and do research and hallucinated every single case, and none of the dockets existed, which is wild. Oh, you have people with Harvard degrees went through law school, one of the hardest things to do, are now so excited about it and and and relying so much on it that there's no due diligence now being being done to that. Which rightfully so. It is, it is, we are in a life-changing technological era right now.
SPEAKER_01And that's probably where the the hype cycle starts to come down a lot, right? Like probably um I'd say with lawyers, they're gonna be really good at understanding when something has hallucinated. I think there's gonna be less understanding across other types of work. And again, you just you you kind of need that visibility. So as we, you know, add in guardrails, add in the ability to understand prompts that people are pushing to AI and security teams can can you know review it and um potentially add better policies or better kind of AI uh you know, reinforcement learning or something like that. But uh it's gonna be difficult, but I I do think that it's it's something that the companies are gonna adopt and and something they're gonna stick with. So it's uh I think imperative for security to understand that yes, it's hyped right now, but it's not going away. So we've got to manage the reality that that we're dealing with, and that's you know the hard part of of cybersecurity, but also why we uh why we keep doing it.
Adopting AI By Usage Quadrants
SPEAKER_00What would be your suggestion for a company now adopting AI to become more uh adept at using it and understanding the guardrails to put in place and the hallucination potential it's a good question.
SPEAKER_01You know, every company is different, and every company has different risk profile based on what they have to protect, what they you know want to protect, and what they might need to protect. So and I think there's also two different layers of AI usage. So we are much more on the workforce side of AI usage, which I like to think of as you know, the the end users interface into AI over the web. Then you have developers and other people who are doing it, you know, um through an IDE or something like that. So you certainly want to split your adoption into a couple of different quadrants, right? You want to do the workforce and their usage of AI on the web, you want to do your developers and their usage with coding, maybe your MCP servers that you're using, things like that. You kind of want to move those into different buckets of technology so that you can then build in your observability. So for us, I mean, it's definitely on the workforce side. So, you know, understanding which you know what technology is accepted by policy, had your guardrails there, and make sure that the right people that are allowed to use it can use it, block other people. But at the same time, we we're seeing an explosion of shadow AI usage. So you need to constantly be, you know, monitoring the applications that are used in your organization and making sure that is a part of your you know usage policies. Uh, but again, there's you know, you've got to think about your developers and MCP servers and stuff like that. So that's kind of a good starting place.
Shadow AI And OAuth Visibility
SPEAKER_01How would you describe shadow AI? Yeah, I think it's it's for again, you know, in in what I deal with every day, shadow AI is definitely, you know, AI SaaS applications that are unknown to IT or security. So you know, we think we've asked everybody to use Claude. We have corporate cloud accounts. Somebody is using their personal account for Chat GPT. That's something that needs to be known very quickly if it's on a corporate device, right? And so I think that's we think of it as like a you know a catalog of of SaaS applications and a subset of those, uh, which would be like Shadow SaaS, subset of those would be you know, shadow AI. And we see it a every single day where um what's I think important on for security is you know, if you're using anthropic or or open AI, the corporate version won't train on your data. The personal versions will. So there's some again, some nuance to every single SaaS provider and AI provider that has some real relevance to to security. And so having that monitoring and that observability that I mentioned before, you know, if you're using the right tools, then it should start to build out that uh catalog for you. And then you can go in and say, all right, this is the approved one. I'm gonna block the ones that aren't approved. Um, and so from the workforce side, that's that's kind of how we do it.
SPEAKER_00Which is important too, because in the world of integration right now, it feels like everything can API into you know the big three. And now you have this almost spider web of shadow AI operating together.
SPEAKER_01And then uh the the problem that gets gets harder at the developer on that developer quadrant, right? I think you know, I can quickly connect Claude to an MCP server that has access to real customer data. And that goes that still goes through OAuth in the browser. So that's another maybe layer of observability, is you need to start really understanding how your OAuth uh is being um you know accessed across your production systems or your your vendors on those production systems. So if I have a super base or sell MCP, um I still have to use a browser to to get OAuth into that. So that type of observability really needs to happen with a security team just to understand not just the uh shadow AI usage, but the shadow AI authentication through typically OAuth is how everyone's doing it. I think the days of like API keys are going away um in in certain instances.
SPEAKER_00Oh
AI-Driven Phishing And Identity Theft
SPEAKER_00well. Do you with Shadow AI, do you spent I'll say speculate? So I I'm sure there's pretty hard to find proof. Do you speculate that in phishing campaigns or whale phishing, that hackers or I'll just say threats in general are using Chadget DP to crawl and pull information from a company that potentially might have some leaked information from those public accounts or the personal accounts?
SPEAKER_01I mean, I think it's hard for me to kind of wrap my head around like what leak is when you're talking about some of the AI, whether it's training on your data or or whether you're leaking it. I certainly know for a fact that attackers are using AI to um copy sites or to highly target um through email phishing or LinkedIn phishing or something like that, and the ability to kind of crack.
SPEAKER_00that uh that website the phishing site um is happening now and kind of to add to one of my previous points they're also a lot of them are moving away from dropping malware and moving into compromising identity so they'll do a no auth request to your Microsoft um you know tenant uh so that they get a token and once they have that token then you know all your corporate data for that person can be exfiltrated that happens a lot now um and I think that's an interesting change from just trying to drop malware on a system and speaks to going more towards the identity layer and the layer seven application layer um but you know attackers think and in speed right and access and so they're absolutely adopting whatever they can to to improve their um you know opse and and make it look more authentic right and grab tokens instead of having to drop malware and we were talking about this off screen too the hardware is advancing you have something like the Marauder right now which is really just a Raspberry Pi that you can go bring into an airport have AI spin up the airport login for the Wi-Fi and say hey free Wi-Fi and then just sniff packet sniff the entire thing whoever wants to go there and clicks on the wrong thing connects. And it's that quick rather than needing the HTML knowledge or having access to something like Dreamweaver when it did exist.
SPEAKER_01Yeah yeah that's I mean you know attackers are salivating over that because it does it does multiple things right it gets the language right you know it gets the the ability to to that speed because attackers are are change techniques all the time when something works you know they're gonna automate it they're not gonna just sit there old school and you know find one person that they want to try to attack they're gonna cast a wide net and yeah the ability to to clone a you know a captive portal is really easy for a for AI. AI is understands natural language certainly understands HTML and the web so you know everything that could have been an indicator that you had a signature for or you know some kind of telemetry or detection for uh that was based off of just malformed English or you know suspicious things on a website like those will go away.
SPEAKER_00It'll look exactly the same um it'll function exactly the same and that's just gonna be something we have to deal with just crazy that we're gonna have to evolve and adapt to that um this is gonna date us a little bit uh probably in the future but it is a hot topic right now and I wanted to get your thoughts on Fable 5 and Mythos 5 being
Jailbreaks, Safety, And Model Opacity
SPEAKER_00grounded.
SPEAKER_01Oh well yeah I mean um from what I understand the narrative is that people were able to jailbreak it. And I think in that case you get a lot of kind of export control concerns. It's a black box for all intents and purposes. So the blast radius or the fallout from something like jailbreaking it is completely unknown. So I think it is you know I don't necessarily will I don't think we stop progress. I don't think we kind of overregulate progress but there is a moment when you say okay we need to know more about how you're protecting this we need to know more about what what it means when it's jailbroken. On the flip side attackers are there's whole uh you know Discord channels and whole like you know channels that are dedicated to jailbreaking uh models which is gonna just continue so it's probably I think probably good to pause but if it's anything besides looking at it from a safety perspective which may be the case you know it's inevitable. So how do we face that inevitability? Yeah I I like that take on it.
SPEAKER_00I mean we again we were talking kind of gaming off off screen too it's it's similar to that the nothing is unbreakable. You have something called de novo which is like the end all be all encryption for gaming and then now it's just getting cracked left and right day one. So nothing there's nothing unbreakable. And eventually you're right it's almost like looking at understanding what the fallout will be and then how do we mitigate that or at least put in processes in place to deal with that if it happens.
SPEAKER_01The hardest part again it's opaque and that is going to be a struggle for AI foundation models providers. They're gonna have to do something to make it a little less opaque so that you know what and it is difficult with trillion parameter models. Like it's beyond our comprehension how complicated they are and and what they know and and how they kind of understand those attention mechanisms but there's going to have to be some give on the vendor side and say you know this is the guardrails we have in place this is how we do um do those guardrails this is the geo fencing that we have uh there just needs to be probably some more transparency because it is the first technology that that's that's this powerful that is hard for you to go and look into right like we talked about the cloud and the internet stuff you could still dive deep like as a a security person or whatnot we have no way to evaluate the models at at scale to understand how they'll truly impact us.
More Zero Days And Smarter Prioritization
SPEAKER_00And so there's going to have to be some give and take interesting yeah and my theory is I'd be curious in yours too I think when these become ungrounded do you suspect we'll start seeing a spike in threat intelligence information and CVEs and zero days coming out.
SPEAKER_01Absolutely yeah yeah I I I spent 15 almost 20 years in vulnerability research exploit development the ability to find vulnerabilities is exponentially easier now. So the ability to find and select a vulnerability that is easier to exploit is going to be cheap and accessible to anyone and now there's a lot of there's a lot of nuance behind that but um zero days are are absolutely going to increase um the ability for like non-nation states to do it is gonna is gonna be available the barrier to entry is going to decrease you know patching has never been good for the defender it's awkward hard and slow which is the opposite of what security practitioners want. So we're gonna have to have a real kind of uh a real community effort to understand what that's gonna look like when zero day comes out every week um and we can't patch systems that fast we can't rebuild software that fast. I don't have a solution I I made a LinkedIn post on this unfortunately I don't have an idea so you know it's it's gonna take a lot of smart people to try to kind of figure it out. It's also gonna take massive changes from security vendors right to to understand this this uh problem that defenders have and so having the not having done that work I promise it's it's going to become a rapid influx of zero days. Now and again I could talk about this forever it's one of my favorite topics what I have to remind people is like every vulnerability is not as critical as most people say right like one to two percent of vulnerabilities get exploited. And of those very very few actually have high impact across our business. So it may look like something where we get better at understanding our exposure whether that's you know AI helping us look at our code bases and our firewalls and our uh our cloud footprints and then being able to say hey this vulnerability the zero data came out actually not exploitable in your environment. You know and so the idea that I'm going to patch all these critical vulnerabilities, I've been saying this for my whole career and it's never manifested like you don't have to patch everything right you only need to patch it if that exploit vector is available and you're exposing that piece of software. And that's been really hard to do with you with just human analysis. I think as again as as security practitioners and our abilities increase it might look more like something where you know we have a critical but we're able to validate and ensure that our software is not you can't reach that code path. So in the same way that attackers are finding vulnerabilities across every open source package browsers and uh servers and or you know like um Nginx and things like that, we're gonna have to get better at saying hey that code path is actually unreachable. So it may be a critical but I can check that risk box and say we've ran our analysis across all of our code and our infrastructure I think the risk is actually really low.
SPEAKER_00That's crazy. That you mentioned that too like that that there is there is the criticalness of of vulnerability but like I said if the door is already shut then you don't need to worry about it.
SPEAKER_01And it's a bright mice like honestly like on a hot take it's garbage like for most of the CVE you know C VSS like I appreciate having that ability for defenders to focus their time because there's just too much work to do. But if you look at every critical vulnerability as critical and the sky is falling you know your likelihood of being exploited is could be very very small if not impossible. And again that nuance because it's it's deep technical work for human to do and we can't scale across the business to say you know I I promise or I at least feel 99% sure that this is not going to affect us, you can't bubble that up to the CEO or the CIO or CTO right so we you know um we we take those raid beings and I think it's good and I think it was a good thing to do. But I'll tell you like it is not it does rarely does it mean the sky is falling for your business. Now if it's if it's the thing the the vulnerabilities that we know SSH browsers yes we can make that call uh but there's thousands and thousands of vulnerabilities I can help I'm just not that may say critical but are not critical to you.
SPEAKER_00And I think that's the distinction that we've got to really raise up the technology for I also I I think with the CBEs too like what we're what we're at least I am starting to see it too I'll say our threat research team as well it's the it's the observational threat research that's getting that that people want to read that people are really interested in and it's watching the groups actually act out a zero day and then seeing what they're targeting and almost taking this bird's eye view from it and then breaking down how they're doing it. So not only are you are you touching on kind of like what you're saying hey are we patched for this is there actual criticality is there is there not but you're also seeing the the mentality and and almost the pack movement of that hacker group at the same time and I think that makes a really great intelligence.
SPEAKER_01Well and and that's the way I mean that's the ultimate way to determine if something is worth exploiting right you've you've got to turn that map around and I did this for a decade at a at a high level attackers are going to pick the best bang for their buck right and they're gonna get good at finding those knowing that that there's a patch gap knowing that there's um you know there's if they're not inside the organization you know there's gonna be something that they really like to use that covers most organizations. They're pragmatic about it. And so they're not going to go find a really niche exploit for some really niche piece of software. They may do that later after they've discovered it or they've checked off all their boxes but they're going for speed scale reliability and that is often you know if your threat research team is seeing it that completely bumps up the priority right that's proof. And we haven't had a lot of that proof outside of threat research to help drive decisions in the business. So you know that's absolutely the the right way to do it I think from a um priority perspective. But unfortunately concern would be am I seeing everything and you know is my intelligence um relevant and that's important for you know intelligence seems to to build that in as
Hacktivism, Startups, And Closing CTAs
SPEAKER_01well.
SPEAKER_00In that same vein um there's been kind of a lack of hacktivism happening. I was kind of curious on your thoughts on that are you s have you have you heard of more hacktivism happening?
SPEAKER_01Because you mentioned the best bang for your buck and it almost seems like hackism started taking a back seat when the the effect that they're trying to do kind of stopped or wasn't as important to the people that they were trying to send the message to so I'm a huge cyberpunk and you know kind of futurism nerd and I think if you you know if you look at like just how digital our world is and the fact that you know AI and other technologies reduce the barrier to attack or to influence or to whatever it may be, I think you're absolutely going to see that becoming more available to people who may have a little less uh skill um but have motivation and intent, right? All those things are going to be democratized a lot more because of AI and you know just to guess is I I think it will go up. I mean we just geopolitically you know screw people are unnerved and that causes them to want to do something and it's such a digital world deep fakes you know whatever with AI you can do misinformation we see that now and while that may not be you know the the traditional hacktivism I think it's pretty quick that we're gonna be able that people are going to be able to you know use this technology to do a malicious end. Right if you think about like um a a web penetration test right you don't need like AI can penetration test a website and very very soon if it's not here already you could pick a company if you were you know wanting to do some hacktivism you could pick a company and just have AI do some a pretty good penetration test right whether that's local police or whatever it may be. And so and it doesn't cost any money and you can obfuscate who you are easily so I think it would it it will increase um for all those different factors.
SPEAKER_00Oh very great take thank you all right we're gonna full circle it um I'll ask you on the the the final question if you're building a cyber company from scratch tomorrow what customer pain would you want to start with first? Would you bring your message?
SPEAKER_01Uh that's a good question. I've this is my second startup um and the customer pain is obviously where you want to start right people buy software to sleep better at night to work faster to be more precise um the technology is less important to buyers at the end of the day and and coming from someone who is loves loves technology you know I think any any hacker anybody in cybersecurity likes to get in the weeds um that's often not the problem right that that's not the problem is is not a better you know endpoint protection or not a better firewall or you know not not any of those kind of things so you have to really meet the business opportunities across your you know ideal customer profile. So the first thing if you were going to start a cybersecurity company I would say the technology should be driven by your understanding of the problem and your validation of the problem so you must must decide the persona that you want to help um and cybersecurity is all about helping and empathy. So you know you're not gonna create a technology that that applies to banks to Fortune 50 banks like you would for small to medium business. You know who do you want that your customers to be do you want a thousand customers or do you want two customers? Are you in a regulated you know or is your technology going to be in a regulated industry like banking or healthcare or are you going after really high-tech fast moving startups? So kind of before you do anything if you have an idea you really have to see like you know is this a problem who is it a problem for what is their um you know what is their budget how big is their security team that'll cut away a lot of ideas that sound cool on paper or maybe sound cool from a technology perspective that don't necessarily have a market. And then read interview ask people ask friends you know join a Slack channel join a discord channel um you know you'll you'll start to understand the the problems as you talk to people more um you know ignore a lot of marketing that other people are doing and then you really have to be careful with with the technology that you're building because people can build so fast now you have to make sure that your technology is something pretty unique if you're going to solve a problem that no one else is solving. So you know your user interface is not that unique anymore your um you know you're alerting or not that unique anymore like you know focus on what you think you're you're good at and um it's very very hard work but I'm an advocate for for any startups and I'll the last thing I'll say is startup founders and cybersecurity are very friendly. We want to help we want to share just kind of back to the hacker kind of ideals. We just share information. So there's plenty of people that want to help who've been there done that and it's always great to surround yourself with mentors and and and people who will just tell you honestly like you know that idea is a feature in another company's product and they're already working on it.
SPEAKER_00That's great. And definitely something to mind too so you have a lot of new founders you have guys who have ideas who want to become founders and I love your take too on the understanding that things can be spun up fast and there's no more uniqueness. And I I start seeing that in brand when ChatGTP came up those almost like logos started getting really similar and I can almost pick one out from a Chat GTP. And while it is unique it has those tells telltale signs. Messaging the same way too people are just using Chat GTP unless you really come down and train it constantly about tone, voice messaging you're gonna sound just like your competitors who are also using ChatGTP are also using Claude. So it's that's a great amazing take there.
SPEAKER_01And not the I will say that you know cybersecurity should you you no matter what you build, if you're a startup, you still need an identity that's unique. And I think that kind of goes back to the product as well or the or the problem you're solving. And of course by all means go for gold and try to reinvent all of cybersecurity but you do need a unique voice. It's a trust based and relationship based uh industry so while you can build fast I would be careful on the public facing image and messaging to not look like you didn't think about it and didn't invest. Try to try to be different uh it's gonna stand out a lot more exactly to your point. As a brand person thank you anything you're excited coming up yeah neon cyber I mean check us out neoncyber.com um everything related to securing your workforce in the browser with AI usage discovering shadow AI enforcing guardrails helping your policies helping you say yes to to adopting it um and we do a lot on the traditional browser security side with identity security and um and phishing uh anti-phishing I think what what what I'm excited about is you know just this technology shift um we're gonna keep going deeper into how people use AI and giving security teams that visibility and control um because it's coming and I want to help people I want security people to not say no I want them to feel like they can say yes um and have some semblance of of control uh which is sorely lacking right now with the adoption that we see across every company size you know like like plumbing manufacturers are adopting AI um so we're we're really excited check our website out uh as the brand guy like we're real real proud of the way it looks and yeah just hit me up if anybody is interested great thank you so much Cody for taking the time and appreciate you coming on Sean it's been fun many thanks for listening at Secure Onyx we help organizations strengthen security operations with Unified Defense SIM powered by agentic AI.
SPEAKER_00In Breach Ready Radio you'll find candid conversations with security leaders about the decisions, pressures and experiences shaping modern security operations. You won't get an hour long product pitch. If you enjoyed the conversation subscribe wherever you listen to podcasts for more insights from the people leading security through change. I'm your host Sean Ferguson and we'll see you next time