EVERY SPOKEN WORD
50 min read · 10,033 words- 0:00 – 1:06
Intro
- KMKevin Mandia
You don't have a defense unless you have a great offense to go up against. You wanna be the Baltimore Ravens defense of 2000. You kind of wanna have your practice offense really push you. That's what Armadin's gonna do. We're gonna be the all-star team on offense coming at you so you can train your defense with what we're doing.
- DGDavid George
You built Mandiant, a great success. Why did you decide to get back on the field?
- KMKevin Mandia
I don't wanna sit out the AI shift change when I've done 30 years in security and the whole damn thing's about to change. [laughs] What AI does in a microsecond would take 70 humans. They can't even do it. It's apples to oranges.
- DGDavid George
This is a tsunami like has never been seen before in security.
- KMKevin Mandia
The whole, "Let's slow down the models. We don't want cyber risk," too late. The open models are already good enough. At Armadin since January of this year, we have found over 90 zero-days at customer sites all in production.
- DGDavid George
This is not, like, rinky-dink companies. Like, these are, like, Fortune 500 companies. The differences or similarities between nation state attacks compared to AI today, and then where you think AI can be in a couple of years.
- KMKevin Mandia
On the defensive side, we're gonna say, "We're being attacked by these models, but we're not sure who's behind them. Is it a nation? Is it a human? Is it-"
- 1:06 – 4:19
Why Kevin came back to the field
- DGDavid George
Kevin, thanks for being here.
- KMKevin Mandia
No, thank you.
- DGDavid George
Okay, so you built Mandiant.
- KMKevin Mandia
Yes.
- DGDavid George
Obviously a great success. Um, many different chapters. You know-
- KMKevin Mandia
Mm-hmm
- DGDavid George
... it ended up, you know, inside of Google-
- KMKevin Mandia
Right
- DGDavid George
... ultimately. Um, why did you decide to get back on the field?
- KMKevin Mandia
It's a good question. And, you know, I don't know if I decided it, and that'll sound weird. But I met with David Slater and with Travis Lanham, the other founders, and Evan Pena I knew. Uh, you know, I, I could say they started this company. They are the founders, you know? I met them. They had the idea. They pitched me on what they wanted to do, and I saw the talent in them. Like, Travis is a generational talent. David Slater's, and I mean this in a positive way, freak of nature. [laughs]
- DGDavid George
Yes. Yes.
- KMKevin Mandia
You know? Like, these guys are, are really, really good. Evan Pena is exceptional at what he does. And when you meet that team and you talk to them, the whole time I was listening to what they were doing, I was thinking, "I wanna be a part of this." You know, I don't wanna sit out the AI shift change when I've done 30 years in security and the whole damn thing's about to change. [laughs]
- DGDavid George
[laughs]
- KMKevin Mandia
You know, that's great. Everything I did is dead, and then everything else is new. Uh, but meeting that team and they were starting the company, and me realizing, "I'm a, I think I'm a real good fit with these guys, um, to accelerate the need." Like, what Armadin is building, every company needs now. And I, I was like, "This team that can build it, and I think I can answer the now." Let's... You know, 30 years in security, you meet a few people. Let's go to those people and say, "We've built what you need."
- DGDavid George
Yeah.
- KMKevin Mandia
You know? So I almost felt compelled to do it. I know that sounds weird, but I would not have founded a company again in my s- you know, in mid-50s
- DGDavid George
Yeah
- KMKevin Mandia
... and I was doing venture. It wasn't like, "Oh, I'm an entrepreneur and I love starting companies." That's not it. And it wasn't, "Oh, I'm not a VC. I'm just an operational guy." That's not it. I met the team and went, "We have to do this."
- DGDavid George
Yeah.
- KMKevin Mandia
I mean, that's really it.
- DGDavid George
Yeah.
- KMKevin Mandia
Yeah.
- DGDavid George
And this whole AIC change was happening, right?
- KMKevin Mandia
Totally. Absolutely.
- DGDavid George
Like, that's the catalyst, right?
- KMKevin Mandia
Yes.
- DGDavid George
So-
- KMKevin Mandia
Yeah
- DGDavid George
... tell us about what Armadin does.
- KMKevin Mandia
So Armadin leverages frontier models and AI on offense to test do you have exploitable risk? And the re- and that's what we do today. We call it Armadin Red. But we s- when we started the company, Travis and, and David Slater and Evan all knew the future of cybersecurity is gonna be, A, the good guys have to build the offensive cyber cannon and shoot it at networks to make sure those networks can withstand these attacks, 'cause they're the ones that are coming. But we also knew it's gonna be AI on offense built by the good guys working and training with AI on defense built by the good guys, and you have to have both. So our act one was we gotta be the best in the world at finding exploitable risk.
- 4:19 – 7:18
What AI attacks look like today
- DGDavid George
Yeah. Tell us about the nature of the capabilities of AI attacks today-
- KMKevin Mandia
Yes
- DGDavid George
... and then where do you think it goes?
- KMKevin Mandia
Well, great. Th- so the nature of them is, first off, we're getting a weird window in time where we're seeing them, but not at the same level you'd expect. Like, I've seen nothing like what Armadin's already built in the wild, which is there's 25,000 agents all in concert, all working together, doing really, really smart things without going on bizarre phishing trips. Because when you respond to an AI attack, you can tell it's AI very quickly. At least I can, because I've done a, you know, I've thought about a lot of offense. I've responded to a lot of attacks in the past that were led by humans.
- DGDavid George
Right.
- KMKevin Mandia
And a human goes to point A, then to point B, then to point C through their intrusion. AI does little things, like four or five differences, but one would be it'll break into point A, then laterally move to point B. Next thing you know, it's trying to break into point A again. [laughs]
- DGDavid George
Yeah. [laughs]
- KMKevin Mandia
You know what I mean?
- DGDavid George
Yeah, yeah, yeah.
- KMKevin Mandia
It's like, I get the drone swarm-
- DGDavid George
[laughs]
- KMKevin Mandia
... but you can probably coordinate it and think a little bit better, and that's, that's where it's at today. It'll get better and cleaner. Um, but the differences are, first and foremost, uh, w- the scale of what AI can do dwarfs humans, like in ways humans don't even get.
- DGDavid George
Right.
- KMKevin Mandia
Um, so you have a scaling problem in that humans could always find only one path into a network.
- DGDavid George
Yeah, they had to be selective-
- KMKevin Mandia
Yeah
- DGDavid George
... because they had to-
- KMKevin Mandia
You bet
- DGDavid George
... devote their limited resources-
- KMKevin Mandia
Yes
- DGDavid George
... to one direct path, right?
- KMKevin Mandia
Yes. And it, and then, uh, so scale, uh, is, is a challenge. Speed, ridiculous. What AI does in m- a microsecond would take s- 70 humans. They can't even do it. It's apples to oranges. And then so what was always lacking is, is AI creative-
- DGDavid George
Yeah
- KMKevin Mandia
... or effective? But when it comes to what we do Uh, we don't need the fanciest model. We're not trying to speak 400 languages, you know, with our models and all that kind of thing. What Armadin's doing on offense is we're finding vulnerabilities, exploitable risk. That is code. That's a structured language, a structured process. Because it's structured, AI's gonna be great at it.
- DGDavid George
Right.
- KMKevin Mandia
Right? So I really think it's already here today, like the whole, "Let's slow down the models. We don't want cyber risk." Too late. The open models are already good enough and, and these things are coming now. It's just a matter of the minute you have anonymous availability of GPUs, you'll see far more criminal attacks. [laughs]
- DGDavid George
Oh, interesting.
- KMKevin Mandia
Yeah, you know what I mean?
- DGDavid George
Yeah, of course.
- KMKevin Mandia
But until you can attack anonymously and, you know, it's hard to do crime when people know your name.
- 7:18 – 14:34
Nation state vs AI drone swarms
- DGDavid George
Okay. So you, your experience in working in the security industry for 30 years, you, um, probably saw a fair amount of nation state attacks-
- KMKevin Mandia
Right
- DGDavid George
... right?
- KMKevin Mandia
Every day.
- DGDavid George
So every day.
- KMKevin Mandia
Yeah.
- DGDavid George
So talk about the differences or similarities between nation state attacks. And I use that-
- KMKevin Mandia
Yeah
- DGDavid George
... just to say the most-
- KMKevin Mandia
Totally
- DGDavid George
... sophisticated, most-
- KMKevin Mandia
Right
- DGDavid George
... you know, m- m- most w- whatever, most successful-
- KMKevin Mandia
Mm-hmm
- DGDavid George
... if you will, types of attacks compared to AI today, and then where you think AI can be in-
- KMKevin Mandia
Right
- DGDavid George
... a couple of years.
- KMKevin Mandia
So e- everything's gonna change rapidly, right? And, uh, but I can tell you, nations on offense have never, in my opinion, they've never really been... When you're hacking for espionage and for security reasons, you hack with what I would call kind of a sniper round. You're not spraying and praying. For the most part, modern nations on offense restrict their targeting, and they go deep at very specific things, like 30 defense contractors or .mil, you know, and they go hard at that. Kind of think of it as, you know, that sniper round. With AI, I think it becomes more like a drone swarm. You know? It becomes a little bit different in the cyber domain, and I think even modern nations are thinking, "What will our protocol be? If we want to attack this company, do we swarm it and just burn tokens on it?" Because AI's gonna do a lot of things humans just wouldn't.
- DGDavid George
Right.
- KMKevin Mandia
You know? So it's a little sloppier, a little louder, but it's more effective.
- DGDavid George
But it's more comprehensive.
- KMKevin Mandia
Yeah, that's the problem.
- DGDavid George
Right? Like that's-
- KMKevin Mandia
You got it.
- DGDavid George
Yeah.
- KMKevin Mandia
It's more effective probably. 'Cause if, if the... And so there's gonna be so many things a nation's gotta think through right now, and their whole doctrine will shift as, as the AI shift change comes. Like, how does AI change what our mission is? Do we m- maybe use the cyber domain differently? Do we drone swarm sometimes, sniper round other times? How do we balance the two? Does it depend on risk, target, how surreptitious we wanna be? 'Cause right now, AI is not a surreptitious action on offense-
- DGDavid George
Yeah
- KMKevin Mandia
... unless you've done a ton of post-training. You got a, maybe a human in the loop really looking at, are we doing smart things? Because if you just go, "Hey, here's a prompt. Hack," you know, "abc.com," AI's not gonna do it in a surreptitious and smart way. And I think even if you ask it to, it's still not going to-
- DGDavid George
Yeah
- KMKevin Mandia
... till it's been really trained-
- 14:34 – 18:36
Why pen testing is dead
- KMKevin Mandia
on you.
- DGDavid George
Yeah.
- KMKevin Mandia
Mm-hmm.
- DGDavid George
It's interesting. So, um, you would kind of... Armadin, I don't know, a year ago, would probably be placed in the category of pen testing.
- KMKevin Mandia
Mm-hmm.
- DGDavid George
And you and I share history and a relationship with George-
- KMKevin Mandia
Right
- DGDavid George
... at CrowdStrike.
- KMKevin Mandia
Right.
- DGDavid George
And so they famously redefined the category from AV to EDR.
- KMKevin Mandia
Yeah.
- DGDavid George
And of course, they did it-
- KMKevin Mandia
Right
- DGDavid George
... incredible things.
- KMKevin Mandia
Sure.
- DGDavid George
But the category redefinition-
- KMKevin Mandia
Right
- DGDavid George
... um, was on the back of major infrastructure changes-
- KMKevin Mandia
Right
- DGDavid George
... and product changes.
- KMKevin Mandia
Mm-hmm.
- DGDavid George
Um, you know, and allowed them to create a product category that was far greater and bigger-
- KMKevin Mandia
Right
- DGDavid George
... than AV. Um, talk about pen testing.
- KMKevin Mandia
Right.
- DGDavid George
What is the historical view of pen testing, and why that's not what the future is?
- KMKevin Mandia
Yeah, couple things. I mean, you had to do it, right? It was kind of like first gen AV, you have to buy AV. And I think when you look at Armadin, we will be as ubiquitous as AV because you have to have that AI force field of AI on offense training AI on defense. You have to do it, and you can do it, so why wouldn't you? And, um, so you look at that, and, uh, it- it's... Pen testing to me is always just scanning for what's already known, and it doesn't prove whether you're really exploitable or not.
- DGDavid George
Right.
- KMKevin Mandia
So it's always created a larger list of vulns that don't matter.
- DGDavid George
Right.
- 18:36 – 21:22
Autonomous defense explained
- KMKevin Mandia
coming at you would do.
- DGDavid George
Yeah.
- KMKevin Mandia
[clears throat]
- DGDavid George
So, um, you talked, you, you mentioned earlier, you know, obviously that's Armadin Red.
- KMKevin Mandia
Yeah.
- DGDavid George
Um, you mentioned Armadin Blue.
- KMKevin Mandia
Mm-hmm.
- DGDavid George
Talk about Armadin Blue.
- KMKevin Mandia
The Armadin Blue is like we can't, David, just show up and say, "Hey, you know, you're vulnerable. See you later."
- DGDavid George
Right. [laughs] You know? Yeah, yeah.
- KMKevin Mandia
And hey, the true north for every CISO should be effective autonomous response. We gotta build that. And, and we knew all along you can't just say, "Hey." We, we wanna be the best in the world at finding exploitable risk. That's-
- DGDavid George
Yep
- KMKevin Mandia
... goal number one. But then goal number two, and be the best in the world at doing something about it. And that means Armadin Blue. And Armadin Blue will be take the information about exploitable risk and work with the defense plane, you know, whether it be endpoint EDR or firewalls, and create compensating controls at speed.
- DGDavid George
Yes.
- KMKevin Mandia
So that if we find an attack five minutes before someone else using a model finds an attack, you're already safeguarded. And these safeguards are gonna be rudimentary potentially out of the gates, right?
- DGDavid George
Yep.
- KMKevin Mandia
Over the next few months. A year from now, they're just gonna be there.
- DGDavid George
Yep.
- KMKevin Mandia
Because the whole cyber domain is progressing at a speed where you're gonna have to defend autonomously.
- DGDavid George
Yep.
- KMKevin Mandia
For better or for worse.
- DGDavid George
Yep.
- KMKevin Mandia
You know? I, I'd rather have a bad patch d- stopping a bad guy from getting in than have an intrusion.
- DGDavid George
Right.
- KMKevin Mandia
You know what I mean?
- DGDavid George
Yeah.
- KMKevin Mandia
So you gotta take your lesser of two things, and one's much more manageable. You never want an unknown person with arbitrary access on your network.
- DGDavid George
Yeah. [laughs] Yes.
- KMKevin Mandia
You know?
- DGDavid George
Yeah, very-
- 21:22 – 27:04
The future of the SOC
- KMKevin Mandia
You know, if I'm a CISO, I do believe my true north is effective autonomous security. You wanna keep your best people engaged. You wanna automate the processes that work for your organization. But you are absolutely saying, "What survives in the AI age and what doesn't?"
- DGDavid George
Right.
- KMKevin Mandia
And I think we're still working through that process. I think there's whole processes in the SOC that'll just go away, and for whatever reason we're automating [laughs] right now.
- DGDavid George
Yeah.
- KMKevin Mandia
You know, it, it, over time y- I can tell you this. If you have humans in the detect-and-respond loop, you're gonna be too slow.
- DGDavid George
Yes.
- KMKevin Mandia
You know what I mean? It's just not gonna work well.
- DGDavid George
Mm-hmm.
- KMKevin Mandia
So you have prevent, detect, respond. Prevent's gonna be governed by AI, and detect and respond is gonna be done by AI. And the goal in cybersecurity has always been if you have, you know, you wanna prevent [laughs] -
- DGDavid George
Yeah, of course. Yeah
- KMKevin Mandia
... you know what I mean? You don't wanna detect and respond. So I just see the constant narrowing of the window of every phase to the point where, you know, we're really not doing a lot of detection and response, 'cause the window to do it is-
- DGDavid George
It all happens too fast
- KMKevin Mandia
... is almost, you got it. It's a little bit too fast. So but you still gotta have that onion peel to some extent of systems backing up systems and assuming failure somewhere.
- DGDavid George
Right.
- KMKevin Mandia
You know? Like even Armadin creating the force field, sooner or later somebody's gonna get around it. Someone's gonna create an exploit before we find it somehow-
- DGDavid George
Yep
- KMKevin Mandia
... some way, on a platform or s- or a, um, or an app that we just haven't assessed yet. It hasn't been in production at a customer site, and so we haven't looked at it. And someone else finds it. And when they do that, you will wanna have a trap behind saying, "We've got unauthorized access or unlawful access to a system." Those traps are ... They're, you just can't have a human there.
- DGDavid George
Yeah.
- KMKevin Mandia
I mean, it's just gonna ... Because we've already done it at Armadin. When we break in and have agentic-aware internal command and control, it proliferates at a speed that is shocking. You know? Like I remember as a human you're, like, typing on your keyboard, "I wanna go laterally move with this passphrase from here to here."
- DGDavid George
[laughs]
- KMKevin Mandia
And you're so slow, and you're doing one thing at a time. This thing just does a thousand things at once. It's just like pff everywhere, and you're like, "Whoa, okay, gone. Got the example."
- DGDavid George
Yeah, so the re-
- KMKevin Mandia
Yeah
- DGDavid George
... so the, so the-
- KMKevin Mandia
[clears throat]
- DGDavid George
... each one of those steps of the process-
- KMKevin Mandia
Yeah
- DGDavid George
... has to be automated. Can't be a human in the loop.
- KMKevin Mandia
Yeah. It's as bad as this. I mean, I don't have great analogies. It's like the balloon popped, you know? [laughs]
- DGDavid George
Yeah.
- 27:04 – 35:44
Lessons from the Hugging Face incident
- DGDavid George
Yep. What about the Hugging Face incident? I'd love for you to talk about the-
- KMKevin Mandia
Y- you know, it's-
- DGDavid George
... the learnings from that
- KMKevin Mandia
... I've given that a lot of thought. I mean, I'm certain at OpenAI they're like, "Oh," or at a regular, they were like, "Oh, we coulda done this and this, and it wouldn't have happened." You know what I mean?
- DGDavid George
Yeah.
- KMKevin Mandia
So they've already figured it out. Uh, it's been my experience, in every sh- technical modality shift, we underestimate the adversary's capability, and in this case, we underestimated the model's capability because, you know, when you really read it post-facto, ah, they could've stopped that, you know?
- DGDavid George
Yeah, yeah.
- KMKevin Mandia
And, um, they could've put guardrails on it, some deterministic things, and, uh, and I think they realize that now. But I think when you're in a race, it's almost like a lunar landing race, right?
- DGDavid George
Yeah, yeah, yeah.
- KMKevin Mandia
The AI race. And you have R&D people, and they're doing the work to create models in a way where even those CEOs are like, "We can't slow it. Let's get the government to help us slow it," you know? [laughs]
- DGDavid George
Yeah.
- KMKevin Mandia
That means you can't even control your own innovation, right?
- DGDavid George
I have views on that, but we c-
- KMKevin Mandia
Yeah, yeah
- DGDavid George
... we could take that to another time. Yeah.
- KMKevin Mandia
And so when you have... And I get that. R&D people are, like, chasing that innovation, and it's really hard to package them within, like, security, experienced security people that have the skillsets to cage that thing.
- DGDavid George
Yeah.
- KMKevin Mandia
You know? And it's hard to marry those two up because the security people don't understand the AI as well, and the AI people don't realize... One of the things that we did in our model, I mean, make no mistake, Armadin has made the beast that we're all worried about.
- DGDavid George
Right.
- KMKevin Mandia
We've made a model that attacks. We made mu- many of them. We have a system that attacks production networks and is highly successful breaking in. Well, is it safe? Well, our guys instinctively knew we gotta have obviously a secure, you know, we gotta have a hypervisor. We gotta secure this thing. We gotta lock it down host-based. We have to have a proxy. It knows the proxy. It's proxy aware. That's fine. But then our guys did something, and even I was like, "Nice job." They passively, surreptitiously look at every single prompt done. Do we like it? Do we not like it? And the majority of the time, if we kill an agent, it's probably nothing to do with safety. It's that the agent's wasting money.
- DGDavid George
Yeah.
- KMKevin Mandia
You know what I mean?
- DGDavid George
Yeah, that makes sense.
- KMKevin Mandia
So kill it. It's off on a goose chase we've already done or don't wanna do. But there were so many layers of validation that the agent was doing the right thing. And the other thing was assume every layer of your security will fail, and y- you have to have deterministic rules that eliminate certain activities. But what I did learn reading those incidents, it does take domain expertise to secure agents behaving in certain domains.
- DGDavid George
Yeah.
- KMKevin Mandia
You know what I mean?
- DGDavid George
Yeah, it's a great point. Yep.
- KMKevin Mandia
So I get that. So, like, it, it, like, without a cyber background-
- DGDavid George
It's validating. It becomes validating. Yeah
- KMKevin Mandia
... I get how you're gonna make... You're gonna test something and go, "Oh, didn't think of that."
- 35:44 – 47:34
Building a company at AI speed
- KMKevin Mandia
finding zero-days.
- DGDavid George
Yeah. I wanna shift gears now to, uh, your philosophies and mindset in building a company.
- KMKevin Mandia
You know, they're different. Yeah, so couple things there. Like, the first time I built a company was 2004, and I wouldn't have said I was an entrepreneur. I started Mandiant in '04, February, and it was self-funded and profitable. And we were successful because in hindsight... It's like you almost learn nothing at the time-
- DGDavid George
Yeah
- KMKevin Mandia
... and then you look back and go, "Oh, I did learn right then and there" because of the pain usually. But, uh, I, I me- You know, I look back on Mandiant now. We had a premise nobody actually believed in '04 because our first website said, "Security breaches are inevitable," and nobody believed it.
- DGDavid George
Hmm.
- KMKevin Mandia
And I don't even know how much I believed it. And, uh-
- DGDavid George
It's a pretty good tagline
- KMKevin Mandia
... oh, by the way, [clears throat] I'm slightly off. Our first headline was, "You cannot solely rely on preventive measures." And that was so boring, but that's the same as security breaches are inevitable.
- DGDavid George
Yeah.
- KMKevin Mandia
You know?
- DGDavid George
S-
- KMKevin Mandia
Can't rely on defense
- DGDavid George
... better, better ring on the security breaches headline.
- KMKevin Mandia
Yeah, I got it wrong because I'm not a marketing guy. But anyway, so security breaches are inevitable. And the premise was- That let's respond to every breach that matters so we have first mover intelligence on how to prevent it happening again.
- DGDavid George
Yeah.
- KMKevin Mandia
And so the first model of intel in all of cybersecurity was antivirus. You know, it was like we look for malware-
- DGDavid George
Yeah
- KMKevin Mandia
... we have signatures for it, and if we miss, David George has to find the malware and submit it to us so we get better.
- DGDavid George
Yep.
- KMKevin Mandia
And that's a bad model. My mother's not finding malware on her laptop.
- DGDavid George
Right. Yeah.
- KMKevin Mandia
You know what I mean? It's just gonna eat her laptop alive. So that model was bad, so we decided a better model, because I had responded to breaches, and the reason I was responding to them is AV was easily evaded. And so we were like, "Well, let's learn all the, you know, let's second layer AV, 'cause it stinks."
- DGDavid George
Yeah.
- KMKevin Mandia
And that's what George now owns.
- DGDavid George
Yeah, of course.
- KMKevin Mandia
You know?
- DGDavid George
Yep.
- KMKevin Mandia
So let's second layer AV. You still have to have AV, though. I beat it up, but the reality is, is you still need it, um, or something that replaces it. So the second layer of defense was required. So AV was imaginal line to here, then you extend imaginal line with something that can learn and think. And, uh, so we wanted to do that. And I actually look at Armadin as just the third wave of intel. Like, why are we waiting for a victim and learn from that? That's ridiculous. You've gotta find your own problems first. Don't wait for, you know, defense contractor A to be compromised and then quickly share the information to make sure it never happens again. Now, that model still needs to exist for the things that are somehow get there, that beat you, but, um, we got that model now, and it's just not good enough. So back to your question, uh, you know, Mandiant was f- self-funded. There's not a l- I don't know of self-funded companies these days [laughs] David.
- DGDavid George
Well, the speed-
Episode duration: 47:49
Install uListen for AI-powered chat & search across the full episode — Get Full Transcript
Transcript of episode cJsHel27Z6M
