All right, thanks for having me here today. So, for around 10 years now, I've been trying to figure out where all this AI stuff is going. And what I want to talk about is what I've figured out so far, and what I think we should do as a result. And I'm going to do that by sort of showing how I've kind of stumbled my way towards this conclusion.
So, background-wise, I'm firmly a security person going back to 1999, actually. Spent my whole career doing that, offensive security, pen testing, web app sec, threat modeling, stuff like that. But the general container here is security assessment. And when I do a security assessment, going back for, you know, a couple decades now, I do it in kind of an unconventional way, which kind of gets at the heart of this whole talk here.
So, what I do is I start with the head of the company. I talk to the CEO, COO, head of legal, and I do interviews about, you know, what the company does, like what is their core business, like how does information flow, what do they consider the biggest risks, and stuff like that. And then I move through the organization, talking to lower levels, all the way through management, all the way through to the people at the bottom who are actually doing, you know, most of the actual hard work.
And then as I keep gathering this information, I start filling in an elaborate diagram of the company and the workflows and how information moves through the system. And I start noticing things like vulnerabilities and things kind of jump out. And what's really interesting about this is it ends up turning into like the best view of the company that they've ever seen.
So, a lot of people come in and they'll fix something on the diagram or they'll add to it or whatever, and they start taking pictures because it's a good visualization of their company. But ultimately, I'm trying to figure out what they're protecting and how they're doing it.
So, after a week or two of this, I then do a technical assessment afterwards, and I start asking more questions. But the key idea is taking all this context from the interviews and findings and putting that into a single place. And that is how I start my security assessment, is starting with all this collected context about everything about the company. And that's kind of how I view security assessment.
So, in a separate thread of consumer tech, in 2013, I started getting what I believe is a picture of where all this AI tech was going. And at the time, I called it IoT-powered AI.
So, the context I was using was Internet of Things. So, I put out this not-so-great book. Definitely don't go read this. I have it as a blog post. It's much better as a blog post. But it was called The Real Internet of Things, and it outlines a few core ideas.
So, the basic ideas are you have digital assistants that know everything about you, and they constantly advocate for you. That's step one. Step two is everything gets an API, including people and objects and actual businesses and our digital assistants. And your digital assistant basically uses those APIs and services in the world to interact with them on your behalf, constantly advocating for you.
And then the next piece is that when augmented reality starts happening, which we're starting to see with companies like Meta and Google and eventually Apple, your DA will then present to you context-aware things inside of your augmented reality. And finally, the last idea is that once you have this network of services for, like, a security program or a city or a country or something, when you have sufficient AI to be able to look down at the state of those services, humans will be able to define goals and have the AI help us move towards those goals.
So, those were kind of the four pieces. So, that was fun. Then in 2018, I got a job at Apple doing information security stuff, but the team that I came in with was actually the machine learning team.
So, I had to refresh my horrible math and learn a bunch of machine learning to get started. And I ended up getting exposed to lots of practical AI there and ended up building a security product there with three years at Apple.
So, in early 2021, I left Apple to go build AppSec and vulnerability management teams at Robinhood with Caleb Syma. And there, I did a talk at Black Hat about building vulnerability management based on company context, specifically the context of asset management, which turned out to be yet another piece of this entire puzzle. And after doing that, I decided it was time to build things on my own and do consulting.
So, I went independent with unsupervised learning in middle of 22. And turns out that was just a few months before ChatGPT came out.
So, obviously, when that happened, I went and told everyone about this. I basically told them, stop what you're doing. You've got to go into AI. This is very, very important stuff. You got to go do this.
So, the first place that my head went with all this gen AI stuff is security assessment. And I started thinking of the way I've been gathering all this context over the years and how it's kind of been a central theme through everything that I've done. But I pretty quickly realized that it's much bigger than security assessment, and actually much bigger than security itself. It's actually more about context first. And then the questions we ask about the context come afterwards.
So, in March of 23, I wrote this post called SPQA, which is state policy questions and actions. Basically, you have the current context for a company or a program or whatever. Then you have a policy, which is what you're trying to accomplish. Then you have questions that you're continuously wanting the answers to. And then you have actions that we or AI can take to kind of make those things happen.
So, I'm starting to zero in on this concept even tighter. And that got decent traction, but I really wanted to demonstrate this.
So, I started working on like a demonstration of this. So, for another talk at Black Hat that year, I put together a fake company called Alma, which means soul essentially in Spanish, and gave tons of context, like I gathered from my security assessments, but even more.
So, I got the company's mission, how they differentiate from competitors, the goals, where they do business, the risk register, all the team and the members of the security team and their skill sets, our IT stack, like all the technology that we use, the dev teams, how the dev teams push code, like everything I could gather about this company. And then I asked questions, just like I do in the security assessments.
So, you could actually manage an entire security program like this. I'm already doing it for customers, because you could do planning from there. You could do threat modeling from there. You could actually output reports from there. You can send emails. You could do all sorts of things, because all that context is in one place. And what's really cool about it is you can actually respond to one-off security questions, because you know, even if you have a database of good answers for your security program, the question that comes in is always slightly different, right?
Well, this system is able to handle that. So, this is an example of a CISO making a statement about no more connections to a particular sensitive resource. And we're asking the question, should this connection be allowed? And we have AI respond back with context.
No, it should not be allowed, because the CISO just said that no more connections should be allowed to that particular resource. So, this is an example of like a real-time update to context.
So, throughout 23 and 24 and into this year, I've been building more and more stuff circulating around this central theme of state management, managing the state of things we care about. With context, and then using AI on top of that.
So, later in 23, I built this app called Threshold. It basically takes like 3,000 different sources, and it independently rates those things. It has context of what I consider to be quality, and it's using that context to do the rating.
So, that's another sort of piece along this way. Currently working on another product like this that's very much in the context of this project that's very much oriented around this context idea. Another thing that I've had for a number of years is called Helios, which this thing is attack surface management, but it's actually been very Unix-y and very sort of script and automation-based in the past. What I'm doing currently is converting that into an AI native way of doing it. With S3 and basically putting everything into a central location and managing that state.
So, once again, actions running against context. And the last one I'll mention is like a daily brief for intelligence for myself, similar to what a lot of world leaders get every morning. It basically looks at all these different information sources. It collects predictions that they're making or observations that they're making, brings it all together, and then runs an analysis and says, hey, what could be happening? What could be happening in the next couple of weeks, based on what all these smart people are saying in open source intelligence, national intelligence, etc.
So, all of these are kind of separate ideas hovering loosely around this concept of context in AI. So, I felt like I had things pretty unified in a theme. But just a few weeks ago, I was like, hold on, I think I'm missing the bigger thing.
So, I think I have a much simpler way to think about all of this, which I'm calling AI state management or unified entity context. And of course, that won't be the real name that people use because Gartner will come out with their own name, and that'll be the actual name. But if we look at cybersecurity, this is a good way to look at this. If we look at cybersecurity specifically, and we look at some use cases, there are a lot of really interesting patterns here.
So, for a SOC analyst, we're looking at data across lots of different logs, threat intel reports, identity systems, endpoint data, and all these different things. For incident response, it's a lot of the same stuff, but you're trying to create more of a narrative around what happened and determine the scope. With pen testing, you're also collecting lots of information. You're trying to put those pieces together and demonstrate impact. Same with the red team, except for you're even more concerned about like the larger implications and impact.
With vulnerability management, we need to understand the organization really well. Otherwise, it's hard to do remediation.
So, you have to hit all these different data sources. For program management, you need to be in project management, project management, budgeting strategy, time management, lots of different sources once again.
For GRC, you have to know what all we have to be compliant with and why and what the gaps are. And the common issue with all of these is the ability to see multiple parts of the organization in context at the same time. And then to connect those pieces together. And this is what makes security analysts and incident responders and red team are so valuable. It's not actually a single task in the problem that's difficult. It's actually integrating it all together. That's the problem.
And I'll go more into vulnerability management as an example because I've been in that horrible world for a long time. And I would challenge you, what is actually so difficult about vulnerability management? Is it finding vulnerabilities? Is it making a dashboard of vulnerabilities? It's not actually either of those. It's actually finding a way to go from the vulnerability to what application it's part of. What engineering team is responsible for the application? What repository does that app come from, right? What DevOps workflow do those engineers use? How do they work day to day?
What is the best way to get them affixed to the actual right person? And you might think that's easy, but keep in mind the engineering team is constantly changing. Their tools are changing. There's reorgs all the time. So this is constantly in flux. So here's a really provocative question. How much of our inability to do a good job at vulnerability management for the last 15 or 20 years? How much of that is a security problem? And how much of it is actually an organizational knowledge problem? And now ask that for other areas of security.
But it's more crazy than that because it's not actually only a security thing. The software and security, well, the software verticals in general are all based on asking specific questions to a set of data and giving you an output. HR software collects HR data and asks HR questions. And then there's an HR interface for showing the results. Project management software collects project management information, asks project management questions, which goes into some sort of project management UI or UX.
Do we really think that these are going to need their own separate databases, their own APIs, and their own interfaces? I don't think so. I think all of that starts to go away and we end up with this. Which I'm calling unified entity context. So if you're an individual or someone is a company and they're trying to manage and help an individual, you have your history, your belief system, your aspirations, your favorite books, your traumas, your relationships, your salary, blood pressure, friendships. And I understand I'm talking to a European audience.
So I understand privacy is much more important in Europe. So I understand there's going to be friction to combining all these things together. Unfortunately or fortunately, depending on your perspective, this stuff is going to be so compelling that I think in most cases, it's going to push through that friction faster than we might imagine. But we collect family goals, financial goals, your upbringing, medical history, strength and fitness. And then you could ask questions like, is my relationship working? What can I do to improve the family? How can I improve my health? And things like that.
If you're a company, it's back to the stuff that we had in the context before with the fictional company Alma. So it's IT goals, state of all IT systems, state of our cloud environments, Slack messages, backgrounds and skills of all the team members, how much money we're trying to make as a company. All this becomes like the baseline for everything. Once you have that, then you have the smartest AIs available with the largest context windows available. And you look down at that universal context that could see a snapshot of everything in the company all at the same time.
And that's really powerful. So let's think about this real quick from an attacker defender perspective within information security. I've got this concept called AI CAD, which is AI capabilities for attackers and defenders. And the basic idea is to imagine what attackers wish they could do if they had more resources. So one of the primary questions I get asked is where to spend money on AI for cybersecurity. So this ACAD concept is one way to answer that. It basically says, what would attackers do if they had lots more resources?
So that turned into a project where I'm building all these different attacker capabilities. And what are the defender capabilities to block them? And then based on all that recon and enumeration, all these different activities that are gathered by the attacker against the target, they would then update a target unified entity context. So the idea is all of that was the most important thing, right? These capabilities were the most important thing. And then this target context was kind of the secondary thing because it's just kind of a container.
But after thinking about it a lot more, I think it's actually this. The accuracy and the freshness of the target context is actually the most important because the ability to attack and exploit hinges off of that. And this is where that takes us. The top priority of attackers will be having a better AI state management or unified entity context model of your organization than you do. It will be a competition between your attackers and you between who has the most accurate and most up-to-date context for your organization. And this is really, really crazy.
Basically, I think most people have the AI thing completely backwards. Instead of cybersecurity or finance or whatever being at the center, with context and AI being like features that you add on top of it, I think it's actually the opposite. The context of the entity that you're attacking the context of the entity that you are managing becomes the most important thing, along with the AI that's operating against that context. So software verticals kind of go away. And software and service verticals just become use cases on top of the state management, on top of the unified context.
Now, that was a lot, but watch this. Here's a really crazy idea to think about. What if all our decisions are hard because we lack the context and narrative? Think about a decision about whether some behavior is malicious or not. Think about a junior analyst trying to figure this out. They have 27 different data sources to pull data from. They have to do mappings and correlations. It's really hard. But now imagine a principal engineer doing prep for them and actually collecting a timeline and producing an elaborate diagram. Then they show that to the junior analyst.
Even an extremely junior analyst can now answer the question. So maybe the problem isn't the difficulty of the task, but the difficulty of filling in the context that paints the picture. So this is why I think, and this is just, this is not database. This is just a diagram showing this flow. I think unified entity context or AI management of state actually ends up being the most important thing in a company because this becomes the substrate of everything that sits on top of it. So the natural question is, what does that mean for us?
I think if you're building a company, you need to be thinking very seriously about how to get UEC data for your customers. Because you could have the best Vuln management scanner, but if your competitor has access to all the developers and their team structure and their GitHub repos and their dev pipelines, they're going to be better at remediation than you. So you want to avoid getting beat by someone who just knows more about the customer organization than you do.
If you're a VC or any type of investor, I'd be looking at companies that are thinking more about building this type of deep context about their customers and avoid betting on companies that ignore this deep context. And if you're a defender and you're trying to determine what AI to build, you should start building your own UEC context for your company, because your attackers are going to have a version of this and your version needs to be better than theirs.
And finally, if you're just trying to figure out where things are going, just imagine this whole AI state management and unified entity context thing as a lens that you could use or not use to interpret new AI developments. Basically, it's one way of interpreting the news about AI that hopefully makes some sense. Thanks for your time. Thanks very much, Daniel. Very interesting presentation. Such a shame that you weren't able to make it this year to interact with the EIC community here in Berlin, because I'm sure there would have been lots of questions.
I don't have any questions right now from the audience, but I just wondered, in what areas do you see AI state management offering the most immediate strategic value? Is it enterprise IT, governance, or something else?
Yeah, I think it's actually enterprise IT. I think the combination of all these different data types in one place is going to allow company leaders to answer questions that they've never been able to answer before, and I think that's going to be the main advantage.
Okay, great. Thanks. Please give it up again for Daniel Miesler. Thanks.