‘AI introduces a new set of problems’ in cybersecurity: Securonix CEO Toby Weiss | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


It has been just a couple of months since Toby Weiss took over as the CEO of enterprise cybersecurity software company Securonix, headquartered in Texas. He has assumed the role at a time when AI is transforming the threat landscape, with autonomous agents escaping a sandbox during an OpenAI safety evaluation and compromising parts of developer platform Hugging Face’s production infrastructure. It demonstrated the sheer randomness of cybersecurity challenges due to AI. Weiss, who was in India recently, spoke to Nirmal John about AI’s impact, human accountability, India as a vital engineering talent hub and more. Edited excerpts:

Will the deployment of AI in various use cases lead to more consolidation in the fragmented technology landscape that is cybersecurity?

Just yesterday I was talking to the employees about this. In 2009, there were hundreds of security vendors and the discussion was how it was going to consolidate. The consensus was that this is going to consolidate like crazy and there’s going to be five major players because no one wants to deal with all these vendors. Fast forward now. I just went to the Black Hat conference in Las Vegas. It looks exactly the same. There are just as many vendors, except every booth said the same thing. They all said AI security and some variation of it. I really felt an enormous empathy for a customer who was walking around.

Will AI simplify? I don’t think so. This is a new technology that is moving faster than anything we have seen. Enterprises are adopting it rapidly. Security departments want to naturally say, hold on, let us get our hands around it. But the business value is too big for enterprises to slow down [on AI adoption] right now.

Now not only is AI a new technology, it is a new technology that is very good at finding security vulnerabilities. The stories of last month [the Hugging Face incident] have got everyone terrified.

What I saw at Black Hat is that you now have a ton of new companies saying how we can secure AI. You have existing vendors saying let us expand and make our products more AI. AI introduces a new set of problems. So, I honestly don’t think it’s going to change the story in the short term in terms of the fragmented nature of cybersecurity.

It is fascinating what happened around Hugging Face and OpenAI. Are we putting too much trust without truly understanding these systems?

I’m from the Bay Area. You are on the street for not more than 30 seconds and you see Waymos [self-driving cars] whizzing by. It wasn’t really that long ago that people were very scared. The talk in my neighbourhood was, would you go in one? Do you trust one?

But when I get in an Uber, I really don’t know what’s going on in that person’s brain. In fact, we don’t even come close to understanding how the human brain works. And, yet, it’s sort of safer for us and we trust it.We do know how AI works. We might not be able to understand in our heads the millions of weights and the model and the particular decision it’s making at that moment in time. I think it’s really not whether we can trust it or not. It’s about whether it is the better way.

In cybersecurity there’s also a reality that you almost have no choice. The bad guys are going to be using it, so if you are an enterprise, you can’t just say, well, I don’t trust it. You have to implement it.

How has the incident changed the conversation around cybersecurity and AI in the Valley?

I think what’s probably changed in the last month or two is the conversation about how much regulation we should have. Do we need an industry consortium like in some aspects of finance where companies get together and self-regulate before the government does?

There’s another group that says we need to slow things down. So I think the discussion has really been about how do we govern it.

The fact that it was a Chinese model that helped Hugging Face makes it even more interesting from both an open-source and geopolitical point of view.

The way the technology is built, the same AI won’t give you the same answer each time. So from our perspective, it’s incredibly important to have many models. To have choice. You are going to need other tools in the toolbox.

What’s your vision for Securonix in the middle of this flux?

I think we are at an inflection point now where the number of events is going to skyrocket. The organisations, of course, are going to increase their spending, but they can’t handle this problem manually.

Our vision is to help our customers be prepared for security in the age of AI.

India is now a decently sized market for cybersecurity products and is a major engineering talent pool. How is the market for you?

We do extremely well in the India market. From a sales perspective, close to 15% of the revenue comes from India. I think part of it is also because we have a big local presence.

The founders of our company were very eager to invest early in India from an R&D perspective. I’m probably more excited about the market opportunity than the talent. The talent’s already there and it’s great.

What is the percentage of business in India that’s coming from government versus private enterprises?

Oh, good question. It’s mainly private.

——————————————————-


Click Here For The Original Source.