There's sort of like a coin for security. And on one side, there's a deterministic rule-based approach and the other side of the coin wasn't completely empty. We've been doing machine learning for decades or more than a decade, but that was always very niche oriented and very kind of inside the black box of the security solution and what the AI revolution has done is that other side of the coin is now reaching its equal balance with the deterministic sides, but it's underdeveloped as a technique in security right now, but obviously there's tremendous investment and innovation going on.
So we're going to have this like full fledged security analytic coin, if you will, with both techniques equally available, you can apply each technique to where it's best and so I think that makes it foundational. Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm analyst and advisor with KuppingerCole Analysts. My guest today is Matthew Gardiner and we want to talk about AI and its role for cybersecurity, but first of all, hi, Matthew. Good to have you. Thanks. Glad to be back. Love the show. Great to have you.
And it's always the really interesting stuff that you cover. So you're lucky in covering all the sexy topics. And before we start, first quick reminder, if you have any questions about anything that Matthew will be talking about, or I will be talking about in this episode, please feel free to reach out to us. Please feel free to leave a comment on YouTube in the comment section. We are really looking forward to your feedback and to shape the next episodes and just give you feedback. And for today, it would be how AI influences cybersecurity.
You Matthew, you have written me an advisory note that has a long title to chew on, so it's from deterministic to probabilistic security, why AI is foundational to cybersecurity. And that hints at a change and security teams have worked for decades in building deterministic controls. Why is this changing? What is pushing the change here?
What is, yeah, why is this happening? Yeah, this, this sort of, the advisory note came out of the leadership compass I'm about to publish on the emerging AI SOC. And I had this big section on why AI and security, which really didn't fit into a leadership compass. So I pulled it out and then created an advisory note. So why is it changing?
I think largely it's changing because the approach that we've been largely using for the last decades, deterministic rule-based, you know, you have a vision or foreknowledge of what an attack might look for, look like, and thus you want to detect it in the case of a threat detection, sort of run its course. It's, it's, it moved the industry along, you know, to where we are. So I'm not saying it was a bad idea. It was a good idea, but the environment's changed. Attackers have changed, you know, the amount of telemetry has changed.
And then the approach of using the data instead of having a predefined rule has been emerging for years, but it's really obviously, you know, come on to the fore in the last couple of years with the rise of AI in general. So it's essentially an opportunity to use a new approach to a problem that really we haven't been able to completely solve using the traditional approach. But nevertheless, every system that we are now using and every online service that I'm using has this now with AI button. So you can do something that adds a bit of value. Your statement is completely different.
You say AI is foundational to cybersecurity. So it's not just an add on like now with AI or now with blockchain, but it's really fundamental for that. Why is that so important for you?
You know, it's, there's sort of like the coin for security. And on one side, there's a deterministic rule-based approach, which I mentioned we've been using for decades and the other side of the coin wasn't completely empty.
It was, we've been doing machine learning for decades or more than a decade, but that was always very niche oriented and very kind of inside the black box of the security solution and what, you know, the AI revolution has done is that other side of the coin is now reaching its equal balance with the deterministic sides, but it's underdeveloped as a technique in security right now, but obviously there's tremendous investment in innovation going on.
So we're going to have this like full fledged security analytic coin, if you will, with both techniques equally available, you can apply each technique to where it's best for best fits. And so I think that makes it foundational, meaning it's going to have at least an equal place against the traditional deterministic rule-based approach. There's some tension about how far it can go. Is it going to replace deterministic approaches? Is it going to be, you know, cohabitate with it yet to be determined.
But at the end of the day, I think it's a core approach that now can be applied to the sort of problems we've been having and haven't been able to solve using the traditional approach. This also means changes for those who are actually doing it. So this change, this shift from deterministic to at least as an add-on, as you said, probabilistic or as the second half of the game, how can people and people, I mean, how can they prepare for that?
How, what, what will change for them? So what does it mean and how to accommodate with that?
Yeah, you know, it, there are pluses and minuses with both approach. So I'm not here saying that AI is the magic approach to everything. It has the trade-offs, like all engineering.
So, you know, if you think about the weaknesses or the strengths of, of the AI based approach, it's based on data. You don't have to have foreknowledge of an attack or an exposure. You train the system and it, it essentially discovers or it tries to discover whatever it is you prompted it to try to detect. The downside of it, it's very data hungry.
It's not, it's not deterministic, meaning it varies. The same input provides different outputs over time.
It is, has runtime costs that are still being determined. Are somewhat unpredictable.
So there, there are trade-offs. At the end of the day, I boil back, I boiled this down to what you need as a system engineering approach. You can't just rely on this analytic component being perfect. You need to rely on your total system of process mitigating the potential risk of that analytic being incorrect or imprecise.
And so we, you know, we need to look at a whole process, a whole system to become comfortable, the trust that the, you know, the answers that it's giving us are worth acting on. And you mentioned, and I think that that is not the issue. You mentioned that it's data hungry, but with the changing infrastructures, the architectures that we are working with today, I think when there is something really around that, it's a lot of telemetry, there's a lot of data.
I've talked about this with you and with Alex earlier to say, okay, there is so much information or noise, how can you really get to the, to the core and to the really important information? Does this telemetry explosion really change the case for AI?
Does it, is this the silver bullet or at least the vast volume? Yeah, I mean, it's, it's the strong argument for pivoting to this approach in that, you know, in a deterministic model, you have to understand all your and you have to build rules to consume and, you know, manipulate it appropriately. And then new data elements arrive and you have to do that over again, or your data becomes inconsistent or inaccurate in some ways that might break the deterministic model or make it more fragile. Essentially the AI based approach doesn't care much about all that.
It's like, it will consume everything you have. And if you have more, it'll consume that. The downside I was referring to is this is the cost.
I mean, there is a cost of generating and managing data and applying it into a model. So that is a downside, but I think largely the data explosion and the telemetry explosion is a large reason why, why we're seeing this, you know, renaissance of analytics using, using AI. You've done the research in the, in the leadership compass, which is coming out.
You've, you've condensed it into the advisory note. So you should have also evidence that there are still use cases or issues, known issues where traditional methods are still better than AI. Do you have any examples for that? I think sometimes we can say, okay, it's not always AI.
Yeah, no, for sure. It, I mean, an old AI researcher I used to work with years ago told me, if you can write a rule, do it.
You know, if it's just that simple, meaning if this, then that, then this, bingo, you know, you don't need to be, have a throw AI at the problem. The problem we have is, is that we've covered those bases more or less in, in security for, for years. And there's still these, you know, inability to detect sophisticated, slow moving, multi-step threats, for example. And so the beauty of that is you just pump lots of different telemetry and alerts into this, into the AI, trained AI system, and it can more effectively detect those, those attacks.
And so there is early signs that it fills the gaps that the deterministic approach hasn't been able to fill. But that doesn't mean that where determinism is good, rules are good, should be replaced.
I mean, just keep operating those as, as we have been for years and just bring on this new technique to compliment it. Right. And that brings me back to something that, that I said earlier. So we have all these tools that typically have this now with AI, AI factor on it. And when we look at the actual products that vendors are providing, I assume that one could fear that it's still the same technology, but with a new branding and it just a bit of added functionality.
There's some red lights, some warning signs that, that buyers should look into or take as a warning signal when it comes to looking at the products that they have, if they don't read your leadership compass, of course, is it still, we, in German, we say, Alter Wein in neuen Schleuchen, which translates to old wine in new bottles. Is there a danger for that right now?
I'd say, interestingly enough, that's, it's historically true, but much harder now. So for example, the example I'll give you is machine learning, which has been in use for more than 10 years is in the black box and it's in the end user. Doesn't see it.
So you, you know, again, it might be old vine and in a new bottle. Now with, with, you know, AI chat bots and AI agents, it's right into the face of the users. And so you can't really sneak, you know, at the end of the day, they're interacting with the systems, the data, they're watching the agents function. And so if you have an old vine and new bottle, you're going to get exposed very quickly. So I'd say that's was a problem. Historically, you know, the AI magic in the black box and, you know, inability to verify one thing or another. Now it's much, much harder.
I assume it'll probably still happen, but at the end of the day, as a buyer, you get to use these systems and they either perform to your expectations or they don't. And I think you have mentioned that. And I think that's true.
It's, it's really much closer to the end user of the platform, for example. So it's really transparent that these new developments that we all love and use all the time also have, have reached the cybersecurity platforms.
So these, these new capabilities of AI will come when it comes to generative AI, for example, does not only change the user experience, but really the way things operate. So it's really changing as a whole. And that cannot be fake.
Yeah, no, it, and, you know, as in the early emerging AI sock, for example, it's not like they're just turning it on and saying, and then going to lunch, you know, they're sophisticated socks are using it. They're experiencing it. They're applying it. They're testing it there, you know, it's, it's early adopter phase.
So, you know, the proof will be in the pudding. So at the end of the day, you know, they're, they're using it maybe more for triage, you know, as opposed to automated response, because once the response has happened, if you've done the wrong thing, you know, damage can ensue. But if triage is supporting, you know, a senior analyst, they can, they can catch it, they can get experience with using it. And that's sort of the state a lot of the buyers are at right now is, you know, testing it in production, essentially. Right.
And when they're testing it in production, what are the domains that they should look at that? Because we just said cybersecurity, which is very generic, but there are lots of different domains in the process of dealing with cybersecurity from, I don't know, from, from threat detection until final response and documentation.
So where, where does AI from your analysis really shine? Yeah, I mean, in the advisory note, the referencing, I give a quick summary and a number of security domains, but I'd still say the front lines, the lead adopters are the, are the security operations center people that the threat people are primarily responsible for threat detection and response. That's where AI has been used for the last couple of years and where the AI agents are really blossoming, you know, for triage, for investigative support, for malware analysis, for you know, some levels of autonomous responses in some cases.
So you can imagine those are all like sort of defined work that a traditional human analyst would have to do. And so now you're breaking up those work products into agentic functions. And that's where a lot of pain is in security is, is how to sort of keep track with the alert, you know, flood of alerts and investigative processes that historically have been human dependent, trying to get to augment that, those processes with agents.
So it's basically a long way of saying AI is in every security domain, but I'd say if I were wanting to look closely at where it's leading, I would say it's in the, in the, you know, the reason we focus the leadership compass in that domain. The role of an analyst is not only to look at the bright side, but also at the dangers, at the, at the hidden challenges that come with a new technology, especially when it's so unpredictable, like AI is, or can be. Try the same prompt in chat GPT five times and look at the results and you will see what happens.
And if this happens in cybersecurity there, yeah, at least there should be some, some mitigating measures. So you highlight clearly in your advisory note, also challenges and limitations. What are the risks that are introduced into cybersecurity through the use of AI?
Well, ultimately there's, there is an error rate. Sometimes refuters is hallucinations, you know, anyone's using this have gotten in some form or another gotten mistakes that they have to catch. And that's, that's where we are is that you have a system that can automate a lot of things that are very hard for humans to do, but just like humans that the, the results are not perfect. They're not always as expected. And so you have to build in guardrails, which we talk about a lot, whatever that is, human centric guardrails or automated guardrails to mitigate the risks of those mistakes.
And so I think that that's why, like, for example, on the sock, people are working with triage. It's a big pain point. Lots of alerts never get investigated. So an AI system can investigate them all. But at the end of the day, the results of that triage can still be presented to a person if, if, you know, as you're gaining experience.
So at the end of the day, that's where you need to build the confidence and trust in the overall system by gaining experience and having the early adopters and the early vendors of these technologies working together to try to mitigate, obviously the errors, just like, you know, it's, it's like in the self-driving cars, you know, they didn't invent a self-driving car and then roll it out into production. They started on test areas, you know, make up, made up cities on a test track, and then they moved into real life, but they had a guy behind the wheel so that they could override the system.
And so those took many years to improve the system, gain trust in it, know where, you know, where the failure points are. So we're sort of in that stage right now where we have a driver behind the wheel in the AI sock and they're gaining experience and vendors are gaining experience and the systems will improve, hopefully to the point where we can have much more autonomy in the process, but we still have a number of years to go for that, I think. Right.
But that's, that's an interesting thought to, to really consider this also as, as a process where you develop trust into the solution while you're working with it and slightly or slowly reducing the, the, the, the number of incidents where there has to be a human in the loop, but it's, it's really understanding the system better and achieving trust. A classic case in the sock is, you know, you have domain controllers where like, if you take those, take those off the network, it's catastrophic for the network.
And then you have end user systems where if you kick me off the system, you know, it's annoying to me. And so it's sort of like a drive self driving car. If you run over the cone, it's not that big a deal. If you run over a person, it's a much bigger deal. And so you have to sort of, you know, what they use is whitelist, like don't ever, you know, quarantine a domain controller without a human decision, but maybe you kick Matthew Gardner off the network at 2 AM because maybe it's not really me, but what's the downside.
So, you know, you're, you're doing a risk assessment in that case on responses. And so that's the kind of thinking that needs to be applied is that certain automated responses, mistakes don't matter that much. And other automated responses, you know, mistakes are, are catastrophic. And so that's the kind of guardrail mindset that needs to come into these systems. That's interesting because we've talked about the shiny new capabilities. You've talked about the, about the challenges that come with the use of a, of a new technology. You described how trust can be achieved over time.
So now if we look, if we translate that into an actual introduction process and implementation process within an organization, what should enterprises look at? What steps should they take if they want to do this right?
What, what would be the right first steps to go? Yeah, it's funny.
And again, I'll, I'll refer back to the AI socks and since I haven't been focused on, but what's the first use case that they often apply it to. And I've been saying triage, cause it's sort of like the front end of the pro of the process, but more specifically, what they usually do is user submitted suspicious emails, so that, you know, that box that you're supposed to send the suspicious email to thinking that maybe it's phishing often those boxes never get looked at just because it's, you know, a low, a low value process.
So often the first thing they do is they put the triage agent focused on assessing those suspicious emails. So obviously you're churning through a lot of hay to find the needles. And that's obviously what the agents are really good at is they don't, you know, they don't, they don't take time off and they don't get tired, but it's a real, like, if you have a box where you're sending emails and you're telling employees to do that, it really, it really is important that you actually evaluate it, that you actually communicate back to the user, like, thanks.
That was a, you know, malicious or thanks. That wasn't malicious, but thanks for sending it anyway. So that's a kind of use case where it has this low impact in the sense of if it goes wrong, it's not that big a deal, but you gain trust and you're actually solving a fairly high friction process that usually is under, under developed in most companies.
So, so then you do that one and then you apply it to other alerts. Maybe, you know, you have alerts off your firewall, but maybe they're really noisy though. Okay. If you historically didn't action those very often, well, put the triage agent on that. And now it can hopefully filter out the ones that, you know, matter versus the ones that don't matter. And so then you just sort of build these use cases one by one.
And you, you know, eventually you're moving more towards investigations and then you're moving towards mitigation and then you're moving towards response, but that's, that's the sort of cycle that I see organizations going through. It's a really a phased approach and starting with the low hanging fruits and then developing trust and continuing from there.
Yeah, it's perfectly logical. That's how we would do any, you know, any new thing, right?
Right, right, right. So now the really unfair question to the, to the analyst who did the research, I think this is not a minor trend. This is being added to the products of any vendor right now. So the cybersecurity market is changing. The question is how will it change over the next, I don't know, two years? I would not have predicted what we have right now, three years ago, but maybe you can do better.
What, what do you expect us to see in two years? I mean, you're seeing this explosion of innovation in every domain and both with the traditional vendors, they call them the platform vendors have been around for a while as well as new startups. And so there's like this Renaissance is happening. Obviously not everything's going to succeed. You have this dynamism is, you know, you're there, these, these technologies are going to be applied in places where they work and where they don't work very well. And so that, that marketplace is sorting itself out.
I actually just published a blog on pricing. Interestingly, we usually talk about technology, but I think there's a great opportunity for how these solutions are valued and how they're, how they're priced to the customers in the sense of instead of using like users and hosts.
And well, in some cases in the old days, CPUs, you know, which are very, very rough proxies to value in most cases. Well, you know, imagine these agents are doing very specific work products for you.
You know, maybe in substitute for human labor. So you could actually say, well, maybe I'll price it one half of the human that you would have to hire to do that job. So that becomes a, a economic case for the buyer where the value of the job becomes the value of the agent. And so the co-commercial side of the business could be changing at the same time, the technology side could be changing.
So that's, yeah, I think the pricing is really, really an important part because we tend to look at functionality and we of course look at the, the newest, the newest sexy technology, but it needs to arrive also in a decently priced manner within the organization. It has to be a good deal for both sides ultimately. And so when you have a sort of inexact pricing scheme, some people are, some organizations are getting a valuable thing for two less money, and some are unable to do it because it costs too much.
But if, if you're actually splitting the value created and quote fairly based on whatever the market sorts out, you can have a win-win. And so I think that that dynamic is, is still early. People are, you know, feeling their way and new pricing system is not one you just turn on and switch to it.
You know, you have to, you have to ease your way into it, but early signs that that's happening. I'd also say that the sort of platform versus, you know, best of, best of breed versus suite or platform, that argument is never really gone away. It's been an argument in security for as long as I've been in it, but now it's, you know, it's re-energized now with this startups versus the platform vendors, both doing AI into their solutions. I don't think we'll resolve, you know, anytime soon that argument, but I would say the platform vendors are not asleep to this change.
It's not like they're being caught by surprise, let me put it that way. But maybe the, you know, the startups will be faster, more innovative, less bound by established technologies. So there'll be a, that sort of struggle in the marketplace that buyers will have to contend with. And this is also interesting for existing customers. When the platform changes so dramatically that they signed up for two years or five years ago, that is also a change that is more or less forced onto them, or can they stay with the original platform?
For the most, at least in the AI SOC side, it's not like they're eliminating, eliminating the traditional functionality. They're augmenting it. So you can ignore essentially the AI components if you want. You're happy to do that. But ultimately they're, they are integrating it into the solution. So it'll be there. In some cases, it's, it's a functionality that's included in whatever you've licensed, so it's there. So if it's useful, you might want to use it. In other cases, they charge more for it.
So you might want to decide whether it's something you want now or not, but, you know, they're not like, they're not switching over, you know, the whole point of that two-sided coin is the deterministic rule-based systems are being complimented. By the probabilistic AI-based systems.
And, you know, for at least as far as I can tell, they're going to be used in a, in a complimentary nature for as far as the eye can see. One final question before we close down from my side, I'm very much interested in, in data privacy and, and data governance and regional requirements when it comes to, to where, where can I store data or can I run the system myself and AI always screams at me and says, you need to be in the cloud, otherwise it doesn't work.
Is there a choice at vendors to say, okay, I want to have this either run in a specific region of the AI part, because this is critical data. That's telemetry can be highly critical. Or can I even run the AI on my own data center? Is this an option or has this gone away already?
No, there's definitely the option out there. I'd say, clearly on, on, you know, thinking of AI as another SAS application.
Same, you know, you know, in different, in, in different geographies is, is a thing with the AI provider. So if that, you know, checks your box, that's enough. There are some vendors that have, you know, on-prem and essentially, you know, in your, in your private cloud deployment there's trade-offs of course, you know, like anything, so if you're, if you're taking the model and using it yourself, it's up to you to update it and, you know, as, as new versions of it come out.
So I'd say it would be very, I'd be very selective if I was going to run that myself, because you're, then you're not leveraging the whole massive industry that's being invested in right now. And that's actually one of the, the, the big things I see as AI is applied to security is that there's billions or trillions of dollars being spent in this sort of domain, and then there's the security application to it that rides on the coattails of all those investments, both in, you know, data centers, but whether models, et cetera.
And so I would hate to see the security industry fork itself off from all that. Then you're missing out on the, on the large investment. But if you have a SaaS deployment that you're happy with from your sovereign perspective, the AI deployments can sit, essentially sit right on top of those in exactly the same model. So there will be options. Great. Thank you very much. Before we close down again, the reminder, questions, comments, send them to us. We're really looking forward to them.
Before we close down for listeners who are interested, interested in your research, the leadership compass that's coming up, the advisory note that's already out there, where should they look for that and how can they find it? We'll definitely go to the Cooper-Dracot analyst website. The advisory note, you know, deterministic to probabilistic security has been there for a little while since last month. I'm also blogging actively on this. So anyone can go to our blog site and see not just from me, but from, from all the analysts and advisors on this and many other topics.
And the leadership compass you mentioned, maybe be out by the time this is, is, is pushed out in production, but with mid-April, if you're interested in how AI applies to security operation centers and the different vendors that are playing in the market, you know, that leadership compass is something I've been working on for the last five months. So I'm looking very much forward to pushing publish and moving on to the next topics. Great. And final sentence, if you have questions to Matthew and you want to talk to him in person, you have the opportunity at EIC in May in Berlin.
So if you don't want to write a comment, if you don't want to send a mail, but just have a coffee with him, reach out to Matthew at EIC in Berlin in mid of May on Alexanderplatz. So looking forward to meeting you there, Matthew, and looking forward to having lots of great discussions at our conference. Thanks for being my guest today. My pleasure. I'm looking forward to Berlin as well. That will be, I'm, I'm always looking forward every year. So that is the event to be there. And I always say, if I would not have to go there, I would love to go there. So I do both.
See you at EIC if you can, if you can. And reach out to Matthew or any of our analysts for our recent research.
Thanks, Matthew. I'm looking forward to having you back soon.