Both Sides Got the Same AI, So Cyber Defense Must Automate
Episode Summary
Attackers and defenders now reach essentially the same AI tools, separated by what Staffan Truvé estimates at three to six months. On his reading that does not necessarily change the balance of power, and he puts it no more strongly than that: defenders keep the advantage of knowing their own systems and holding the source code, while an attacker works the black box from outside. What changes is the clock cycle. Both sides can find vulnerabilities faster than before, which he says pushes defense past what people can do at the speed now required and into what Recorded Future calls autonomous threat operations, detecting, prioritizing and mitigating at machine speed. Prioritizing does not go away, because only around one percent of vulnerabilities are ever used in a real attack. Asked what an executive should fund first, he declines to name a budget percentage and names the backlog of known, unpatched vulnerabilities instead.
Key takeaways
Assume a threat actor is three to six months behind you, and treat that as the working estimate he gives it as rather than a measurement. He scopes it further: they will not have the closed models, but they will have open weights models, and while they may not have the exact top-notch hardware they will be close
Do not concede the advantage you still hold. Defenders have the insider knowledge of their own systems and the source code, and an attacker has to look at the black box and work out how to attack it from there
Expect the clock to change rather than the balance. He is careful about this: it is not necessarily clear that any of it changes the power balance between attackers and defenders, and the only thing that can be said for certain is that the clock cycle goes up
Plan for defense to move past human speed. He describes an era where it is beyond human capability to act at the speed that is necessary, which is the reason he gives for working on autonomous threat operations, or autonomous defense, whichever term you prefer
Keep prioritizing even after you automate. Detect, prioritize and mitigate is one sequence, and he is explicit that even working at full machine speed you still have to decide which threats are the most imminent, judged on which systems you most want to protect and which attack vectors are most likely
Do not expect AI-written code to arrive safer. His position is that AI now exceeds human capacity at speed but not necessarily at the skill level, so you should expect at least as many vulnerabilities in AI-written code as in code people wrote
Separate authenticating an agent from authorizing one. Authentication he treats as broadly the same problem as for humans; authorization is the tricky part, and the question he puts is whether an agent that spins off a swarm of sub-agents may hand them the same authority it holds itself
Fund the backlog before you fund anything new. Asked for a budget percentage he declines to give one and gives an order instead: the known vulnerabilities already sitting unfixed come first, because on his reading the likelihood of their being exploited is going up dramatically, and next generation testing tools come after
About Guest1
Staffan Truvé is the Chief Technology Officer and co-founder of Recorded Future, the threat intelligence company, which he started in 2009 and which is now part of Mastercard. He holds a PhD in computer science from Chalmers University of Technology, where he now sits on the board, and was Chief Technology Officer of the data visualization pioneer Spotfire. He has chaired AI Sweden and Qamcom Research and Technology, served on the board of the Swedish innovation agency Vinnova, and sits on the board of WASP, the Wallenberg AI, Autonomous Systems and Software Program. This is his second appearance on the AI Realized Podcast: his first, on why threat intelligence belongs on a board agenda rather than only an IT one, is episode 32.
In this episode
| 00:00 | Welcome, and the introduction to a second conversation with Staffan Truvé |
| 01:39 | Have threat actors moved to next generation AI attacks yet? |
| 02:26 | Why the strangest events so far have come from the AI platform companies themselves |
| 03:02 | Fifty thousand CVEs, under one percent exploited, and where the bottleneck sits |
| 03:30 | Attackers and defenders reach essentially the same tools, three to six months apart |
| 04:53 | The power balance may not change. The clock cycle goes up |
| 05:11 | Beyond human capability, and the move to autonomous threat operations |
| 05:29 | Detect, prioritize and mitigate, and why prioritizing survives automation |
| 06:27 | Why the lag on known, unpatched vulnerabilities is so long |
| 07:41 | The two OpenAI models that broke out of a test environment |
| 08:25 | No reason to think AI-written code is safer than human-written code |
| 08:49 | The air gap that was not one, and how the model got out |
| 10:01 | Longer chains of reasoning, and the model that cheated because cheating was faster |
| 11:11 | Is the Mythos moment what ransomware was, and what should a board do about it? |
| 12:01 | On everyone’s agenda now, and where he thinks the significance is overestimated |
| 13:27 | His main point: this was foreseeable, so nobody should be surprised |
| 13:40 | The internet of agents, and why passwords and multi-factor are not enough |
| 14:52 | Authenticating an agent is the easy half. Authorization is the hard one |
| 15:05 | May an agent give its swarm of sub-agents the authority it holds itself? |
| 16:05 | The reviewer who can flag a problem but cannot stop the deployment |
| 17:19 | Deception networks, or next generation honeypots |
| 18:09 | Fake copies of your real system, and what the attacker has to spend to find the real one |
| 18:37 | Every decoy is also a sensor |
| 19:54 | Will there be security-only models? Maybe, but he is betting on the general ones |
| 20:32 | Homomorphic encryption, and the design space for creative defenses |
| 21:40 | The bad guys collaborate, so the defending side has to as well |
| 22:19 | The one thing an executive should do differently, and why it sounds salesy |
| 23:26 | Why he will not give a budget percentage, and what he says to fund first |
| 24:29 | Insikt Group and The Record: what Recorded Future publishes for free |
| 25:49 | The leadership problem is a lack of imagination |
| 26:50 | Remember this: it is happening now, and next year is too late to start |
In Guest’s words
“It’s not necessarily clear that this changes the power balance between the attackers and the defenders. The only thing we can say for certain is that the clock cycle goes up.”
Staffan Truvé (04:53)
“And I think, we are therefore coming into an era where it’s beyond human capability to act at the speed that’s necessary.”
Staffan Truvé (05:11)
“Even if you are working at full machine speed, you still need to prioritize.”
Staffan Truvé (05:29)
“I don’t think there is any real reason to believe that AI-written code is safer than human-written code.”
Staffan Truvé (08:25)
“I think the thing is that we should not be surprised about what’s happening now. That’s my main point, actually.”
Staffan Truvé (13:27)
“Is that agent allowed to give all its sub-agents the same authority as it has itself?”
Staffan Truvé (15:05)
“Let’s take our actual system, let’s build a bunch of fake copies of it.”
Staffan Truvé (18:09)
“The beauty is of course that each one of those deception systems becomes a sensor.”
Staffan Truvé (18:37)
“Since the bad guys collaborate, we have to collaborate on the defending side as well.”
Staffan Truvé (21:40)
Resources
Staffan Truvé and Recorded Future
Staffan Truvé on LinkedIn: Where he posts. Asked how to follow him he says he has no regular feed and puts things on LinkedIn when he sees something interesting
Recorded Future: The threat intelligence company he co-founded in 2009
Autonomous Threat Operations: Recorded Future’s name for the approach he describes: detecting, prioritizing and mitigating continuously rather than at human pace. He names it on air as autonomous threat operations or autonomous defense, whichever you prefer
Insikt Group research: Recorded Future’s in-house analyst group. He points listeners here first, describing a policy of having their own analysts do the research and write reports, with a lot of it free
The Record: Recorded Future’s cybersecurity news site, which he calls the media side. He recommends it as a free resource for tracking trends in cyber, and notes it carries no advertising
Referenced in the conversation
Assessing Claude Mythos Preview’s cybersecurity capabilities: Anthropic’s own evaluation, published 7 April 2026, of the model both speakers call Mythos throughout this episode. It reports zero-day discovery across operating systems and browsers and a sharp rise in autonomous exploit development
Episode 32: Threat Intelligence Is a Board Question, Not an IT One: His first appearance on the show, published 15 November 2025. It covers what threat intelligence is, how capability and intent are weighed, and who in a company owns it
Ideas and terms discussed
Autonomous threat operations: Detecting, prioritizing and mitigating threats at machine speed, on the argument that the necessary pace has passed what people can sustain
Deception networks: His own term for a fleet of convincing fake copies of a production system, presented alongside the real one so an attacker spends resources finding which is which. Each decoy doubles as a sensor on how the attacker works
XACML: An access control standard he recalls as roughly twenty years old, for expressing delegated authority, including the right to delegate authority onward. He raises it as prior art worth revisiting for agent authorization
Open weights models: Models whose weights are published, which is what he expects a threat actor to have even when the closed models are out of reach
Air gapping: Running a system with no network path to the outside. The OpenAI incident he discusses is his example of an environment believed to be air gapped that had restricted access instead
Related AI Realized episodes and events
Threat Intelligence Is a Board Question, Not an IT One: Staffan Truvé’s first appearance, from November 2025, on what threat intelligence actually is, how capability and intent are weighed against each other, and who in a company owns it.
Your AI Agent Is Not the Risk. Its Authority Is.: Yogita Parulekar on scoping what an agent is permitted to do rather than what it is capable of, which is the question Staffan Truvé raises here and does not claim to have solved.
Keep the Data Inside Your Perimeter, and the Agents Too: Claudionor Coelho Jr on what leaves an organization when agents talk to each other, and on keeping both the data and the agents inside the boundary.
Never Surrender Agency to the Agent: Shomit Ghose on the risk surface that opens up as agents are given more room to act, and on where the bounds belong.
Frequently Asked Questions
-
Attackers and defenders have access to essentially the same AI tools, separated by roughly three to six months. Staffan Truvé, Chief Technology Officer and co-founder of Recorded Future, scopes that estimate rather than leaving it flat: a threat actor should not be assumed to have the closed models, but should be assumed to have open weights models, and while the exact top-notch hardware may be out of reach, the gap is close. His conclusion is that vulnerabilities can be discovered essentially equally fast on both sides. He adds one asymmetry that runs the other way and stays in the defender’s favor: defenders hold the insider knowledge of their own systems and the source code, while an attacker has to work the black box from outside.
-
AI does not clearly shift the balance of power between attackers and defenders, on Staffan Truvé’s reading, and what it changes instead is the speed. His words are that it is not necessarily clear that any of this changes the power balance, and that the only thing that can be said for certain is that the clock cycle goes up. Both sides can find vulnerabilities and build new attack vectors faster than before, so the defending side has to test its software and mitigate what it finds at the same pace. He returns to the same point later in the conversation when explaining why he is looking for other ways to improve defenses: if speed is all that changed, an advantage has to come from somewhere else.
-
Autonomous threat operations is detecting, prioritizing and mitigating threats at machine speed rather than at human pace. Staffan Truvé of Recorded Future describes it as the direction the company took once it became clear that the speed now required has passed what people can sustain, and he notes the name is interchangeable with autonomous defense. The three parts are one sequence rather than a menu. Prioritizing in particular survives automation: even working at full machine speed, someone still has to decide which threats are most imminent, weighed against which systems the organization most wants to protect and which attack vectors are most likely against them.
-
Most vulnerabilities are never exploited because most of them cannot be used on their own, and only around one percent are ever used in a real attack. Staffan Truvé explains that whether a vulnerability is usable at all depends on its conditions: some require physical access to a machine, and some require that an attacker already holds some access to a system and is using the flaw to escalate privileges. Weighing those conditions against which attacks a given threat actor is likely to run is what produces a prioritized list of what to fix. The framing that discovery is commoditized and the bottleneck has moved to prioritizing is Christina Ellwood’s, put to him from Recorded Future’s published position; his own answer is narrower, that prioritizing survives automation because exploitability has to be weighed. He echoes her one percent figure as something like one percent rather than confirming it.
-
AI-written code should not be expected to be more secure than human-written code. Staffan Truvé’s position is that AI has reached the point of exceeding human capacity at speed but not necessarily at the skill level, so a team should expect at least as many vulnerabilities and problems in AI-written code as in code people wrote. He is answering a question about whether a team building with AI from the start should have a different risk profile from one maintaining old code, and his answer is that it should not. The practical consequence is that new code written fast still needs the same testing as everything else.
-
Authenticating an agent can be handled much as authentication is handled for humans, and the hard part is authorization. Staffan Truvé separates the two deliberately and says the tricky question is how to express what an agent is allowed to do, particularly once an agent can spin off a swarm of sub-agents: whether that agent may hand its sub-agents the same authority it holds itself is the problem he puts on the table rather than one he claims to have solved. He points at prior art rather than a new framework, naming XACML, an access control standard roughly twenty years old that covers delegating authority and delegating the right to delegate it. The second half he names is human oversight of a swarm, and Christina Ellwood adds from an AI Realized governance roundtable that a reviewer who can flag a problem but cannot stop a deployment is a common and easily fixed gap.
-
A deception network is a fleet of convincing fake copies of a production system, presented alongside the real one so that an attacker has to spend resources working out which is which. Staffan Truvé describes it as his favorite idea at the moment and as something Recorded Future is working on, framing it as the next generation of the honeypot. His illustration is a thousand versions of a system with nine hundred and ninety-nine of them fake, and the more genuine each fake is, the more of the attacker’s resources go to the wrong place. The second effect is the one he calls the beauty of it: every decoy is also a sensor, so an attack on a fake system teaches the defender how that attacker works and feeds back into protecting the real one. He notes AI is what makes this possible at the necessary scale and realism, and that attackers will in turn work on spotting a fake.
-
There is no percentage of the IT or cybersecurity budget that Staffan Truvé is willing to name, and he gives an order of spending instead of a figure. Asked directly for a share of the budget, he says he would be hesitant to give a number as such, and that the methodology matters more than the figure. First comes the backlog of known vulnerabilities an organization has not yet fixed, because the likelihood of their being exploited is going up dramatically. Next comes access to next generation testing tools, from OpenAI, Anthropic or the newer companies in the space, so that the defending side is on par with attackers at finding vulnerabilities. Standard cyber hygiene, including getting authentication to a level that is good enough, runs underneath both. This differs from the answer he gave on episode 32, where he cited 5 to 10 percent of the IT budget as the range commonly quoted. There the question was about funding a standing threat intelligence function; here it is about what to fund first in response to AI-driven attacks.
-
A lack of imagination is the biggest leadership problem in AI adoption, on Staffan Truvé’s answer. He describes meeting people who say AI will at least never do a particular thing, and finding three months later that it does, and he is candid that he hears it inside his own organization too. His counter-assumption is broad: that everything humans currently work on will be possible to automate in some way at some point. He does not treat that as a bleak conclusion, on the grounds that it also puts a new set of tools in people’s hands to do new things with.
-
[00:00] Christina Ellwood: Welcome to AI Realized, the podcast for enterprise executives leading AI adoption. From tackling security, data, and operational challenges, to navigating organizational transformation, AI deployment offers a unique opportunity to redesign organizations from the inside out. I'm Christina Ellwood, your host for today's episode, and today we're talking again with Staffan Truvé, the CTO and co-founder of Recorded Future, the threat intelligence company now part of Mastercard. Staffan's been building AI since the mid-1980s, when he co-founded and has co-founded more than 15 software companies, including the visualization pioneer Spotfire. And for the last 17 years, he's been organizing the entire internet for threat intelligence. He holds a PhD in computer science from Chalmers, was a Fulbright scholar at MIT, and sits on the Royal Swedish Academy of Engineering Sciences. He's also chaired AI Sweden, and served on the boards of Vinnova and the Wallenberg AI program. So he sees this from the lab, the boardroom, and the national security level all at once. When Staffan talks about where AI-driven attacks are heading, it's worth leaning in. He was with us last fall just as agentic attacks were becoming real, and in the months since, we've watched an AI model breach classified systems, and two others break out of a lab to hack a rival. So there's no better one to help us make sense of it than Staffan Truvé. So Staffan, welcome back to AI Realized.
[01:37] Staffan Truvé: Thank you. Good to be back here.
[01:39] Christina Ellwood: We're delighted to have you. When you were here last fall, you said the reason that threat actors hadn't moved to next-generation AI attacks was just simply because today's methods were still working. You ... I think you said specifically there's nothing but motivation to stop them. So it's been eight months. Do you think that motivation has arrived?
[02:00] Staffan Truvé: It's at least definitely getting closer. But it's... but at the same time it's interesting that the most crazy things we've seen, if you like, is actually what's been done by the, the two big AI platform companies themselves. We haven't still actually seen anything in the wild which matches those kinds of events that they have been talking about. And it's, I think- I think that's remarkable ...
[02:23] Christina Ellwood: I think
[02:24] Staffan Truvé: it is- Yeah. I- ...
[02:24] Christina Ellwood: why do you think that is?
[02:26] Staffan Truvé: I think... And then we talk about this a lot, right? And I think they are themselves both fascinated and a bit scared of what they're building. You know- ... they're also, of course, sticking their neck out. You can't help feeling that part of this is actually marketing, to- ... talk about how powerful the new models are. And now, of course, it's been kind, it's been interesting to see how that has maybe backfired a bit. You know- ... how administration in the US, for example, has started to think about AI as a much, much more strategic resource. For good and bad, I would say.
[03:02] Christina Ellwood: Yeah, in many ways, sovereign AI is rising in significance. So Recorded Future's argument is that AI has commoditized finding the vulnerabilities. Fifty thousand CVEs last year, but under 1% were actually exploited. So the bottleneck is now prioritizing, not discovering. Exactly. So walk me- No, exactly ... through what autonomous threat opera- operations actually changes for a security team today
[03:30] Staffan Truvé: so as you said, or let me back up a bit maybe, so it's of course very interesting. Now, first of all let's agree that the defenders and the attackers have access to essentially the same AI tools. There is probably a delay of, let's say, three to six months in what capabilities you can or you have to expect that the threat actor has access to. Assuming that they won't have out-- have access to the closed models, but they will have access to open weights models. They might not have exact, a-access to the exact top-notch hardware, but but pretty close. So we have to assume that vulnerabilities are disc-- are possible to discover essentially equally fast on the attacking and the defending side.
[04:09] Christina Ellwood: Okay.
[04:10] Staffan Truvé: Of course, the defenders still have an advantage in that they have the insider knowledge, if you like, of their systems. We have the source code. The attackers have to just look at the black box and try to figure out how to attack it. But what's-- But with both sides then, so the, the attackers can move as fast as they could in terms of finding vulnerabilities and building new attack back vectors based on that. So on the defending side, we need to do exactly the same then. We need to at speed, at scale, test all our software and ensure that we mitigate whatever vulnerabilities we find. Sometimes you might be able to patch the code. Sometimes you might have to protect your systems in other ways. Worst case, you might temporarily even have to shut down some systems before you figure out how to protect them. And what this, this means is that to us, it's not necessarily clear that this changes the power balance between the attackers and the defenders. The only thing we can say for certain is that the clock cycle goes up. So you need to act faster both-- And let's talk from the defender's view. You have to act faster, essentially. And I think, we are therefore coming into an era where it's beyond human capability to act at the speed that's necessary. So that's why we entered into this direction of focusing on autonomous threat operations or autonomous defense, whatever you prefer to call it Which essentially means-- Yeah, exactly. Exactly. No and that means that we need to both detect, prioritize, and mitigate. Because even if you are working at full machine speed, you still need to prioritize. You need to decide what are the, the most imminent threats, and that's of course based on what you're-- what part of your systems you're mo-most concerned about protecting, but also what are the most likely attack vectors. Because as you mentioned, just one, something like one percent of all vulnerabilities are actually used- ... in, in real life attacks. And that depends both on how they can actually be used. Some of those vulnerabilities might require physical access, they might require that you already have some kind of access to a system to escalate privileges, for example. So by, by looking at all these different things and also looking at what what we think are the most likely attacks to be used by the threat actors we can actually create a prioritized list of what to mitigate.
[06:27] Christina Ellwood: So this is the first step. It strikes me it makes logical sense, right? That no matter how fast you go, you still have to be working on the right thing first. So that's very sensible. But it always strikes me that the-- there's this lag in our repairing our known vulnerabilities, right? We know just based on the, the testing that has been done, there are vulnerabilities in our existing systems we haven't yet addressed that could be exploited. Why is the lag so great once you know you need to go test your existing systems for such vulnerabilities? What's causing the lag in addressing those? 'Cause that seems like the low-hanging fruit.
[07:09] Staffan Truvé: No, you-- Let's say that maybe up to, half a year or a year ago, I think just the, lack of developer capacity was the main cause for that lag.
[07:19] Christina Ellwood: I see.
[07:20] Staffan Truvé: Of course, the, of course, the interesting thing is now that we can, already today and definitely going forward, we have to expect that more and more of these things will actually be able to patch with AI coding or AI-assisted coding. So there, there is reason to expect that you should have no excuse, so to say, to actually not being patching as soon as you detect new
[07:41] Christina Ellwood: vulnerabilities. But again- speaking of no excuses and our big models being one of the most the, the frontline news cases that Mythos, first of all, we had OpenAI had said that two of its models broke out of a secure test environment- ... and attacked and hacked into Hugging Face so that it could cheat on a benchmark. That seems like a preventable situation, especially for people who are using AI first approaches to developing their systems. How do you think that squares against... we all have lots and lots of code that was written a long time ago that we can understand that we need to go look at with a different lens, but brand new code that was written with AI in the first place with an AI first team seems like we should have a different profile
[08:25] Staffan Truvé: I'm-- I don't think there is any real reason to believe that AI-written code is safer than human-written code. I think we're at the point now that AI exceeds human capacity at speed, but not necessarily at the skill level. So I think you have to expect that there is at least as much vulnerabilities and problems with AI-written code as with human-written code, actually. So of course, there are gonna be bugs. And then, to have to address, as you say the most recent OpenAI incident. Only having read the public material there, what strikes me first of all is that they didn't do a great job of air gapping their system because what they said is that they... as it appears then when you read their report, is that they ran this model in what was supposed to be a completely offline air-gapped environment. But in reality, it wasn't since since the model actually managed to find a, if I recall now correctly, it found a, a vulnerability in one of the pa-package handling systems, which it then used to break out. So- ... true air gapping would have meant that there was no access to the internet, of course. Now they just thought it had restricted access.
[09:28] Christina Ellwood: For sure. Yeah. Again, this is like-- and these are people who, supposedly know what they're doing when it comes to building these kinds of systems, and I guess that was my point, is that for people who are learning how to do this versus people who are supposed to be experts in it- we still have very similar vulnerabilities, and I think it's for exactly the reason you said, which is there's still no substitute for the quality and the controls associated with evaluating the vulnerabilities, and that is human first in many ways with AI autonomous agents being a, a way to implement, but not a way to replace the judgment and the analysis in the first place.
[10:01] Staffan Truvé: No. And I think one, one thing worth mentioning here and thinking about is that, as you said, of course, AI detecting vulnerabilities is one thing. The other thing is, of course, the fact that the chain of reasoning capacity has gone up. I think that's what's dramatic about Mythos and the latest GPT models and so on, is that the complexity they can show in reasoning. If you look at this as one of those standard benchmarks now where an AI to reach its malicious goals has to go through thirty se- if I remember correctly, thirty-two levels. Thirty-two steps.
[10:33] Christina Ellwood: That's what
[10:34] Staffan Truvé: I recall too. To be able to- It
[10:34] Christina Ellwood: might even been higher than that. It might have been thirty-seven.
[10:37] Staffan Truvé: Yeah. On that order. Anyway so that's the ability to go through that longer chain of reasoning to succeed at a goal is clearly what made this OpenAI model able to break out, not that it sees the whole complexity from the start, but at least it could set up a goal. I think it's-- there's also a kind of cute thing to this, the fact that a very human way in you like, if you task a model like in this case With solving a problem, the way it actually tried to attack it is to cheat in a sense, you know, because as you said, it went out to actually try to find a solution, the answer
[11:11] Christina Ellwood: Yeah. That's the combination of both the goal and the efficiency require... or not requirement, but guidance. So if you're gonna do it the fastest way possible, cheating is obviously faster than doing it in a more methodical way. So Mythos also presented another example of vulnerability. So when Anthropic reportedly found that Mythos could exploit vulnerabilities in hours that were sufficiently high level or, impactful vulnerabilities, that the Fed and the banks raised the alarm and that held back a general release. And last fall, you had said that ransomware was the thing that finally got AI risk onto boards' agendas. Is the Mythos moment the new version of that? And what should a board actually do with this alarm?
[12:01] Staffan Truvé: First of all, yes, clearly Mythos has escalated, taken this to a whole new level of escalation. I've been out now on the road here for a couple of months actually talking at all kinds of places, and it's on top of everyone's agenda. Public sector, if you go to large corporations anywhere essentially it's the defining moment, I think, in, of AI threats ma- being raised as the top-level awareness. So in that sense, this has been great in terms of people actually seeing this as a real threat now. At the same time, I think, it's... we are overestimating the significance in in one sense, because if you look at the, the models, the kind of threats they can detect, it's, I would say, another, let's say, next generation of tools we already had. And it's interesting. I've talked to several people who've been using high-end mod- models now to do vulnerability detection and finding problems in their code. And to a fairly large extent, they find the same things that was found with more traditional testing tools. But but there is definitely the next generation in what we're seeing now, of course. So in, in one
[13:04] Christina Ellwood: sense, we can say that- That's interesting. So you're saying they really aren't finding new vulnerabilities that wouldn't have been found with the previous versions? Then why the alarm?
[13:12] Staffan Truvé: No, but they are finding new vulnerabilities as well. Okay. But but I think we, we can also view it as the next generation vulnerability detection tools.
[13:21] Christina Ellwood: Okay. Okay. So
[13:22] Staffan Truvé: when I say- I'm
[13:22] Christina Ellwood: I'm just trying to put it in perspective.
[13:24] Staffan Truvé: Exa- exactly. I think, some... so it's... so I think the thing is that we should not be surprised about what's happening now. That's my main point, actually. Yeah. We could for, we could foresee this. I think, essentially when we talked last time- we were already at that point saying that something like this would happen. And now we're here.
[13:40] Christina Ellwood: We're gonna, we're gonna ask you for your next prognostication too. What you think the next thing is gonna be. You have also talked about in quote, "Internet of agents," and about how in the long run we have to rethink authentication. That passwords are dead and even multi-factor may not be enough. And so given Mythos and this week's breakout, what does the next generation of defense actually look like, say, twelve months out?
[14:05] Staffan Truvé: No, the, the best we've... 12 months, it's an eternity at the moment, right?
[14:08] Christina Ellwood: I know it's an eternity. You can make it shorter if you'd like, Staffan.
[14:11] Staffan Truvé: No, but I think, es- essentially, as I said, I think essentially the, the big thing for us right now is to automate the defenses so that we can match this n- expected, I would say, next wave of AI-driven threats, agentic threats, if you like.
[14:24] Christina Ellwood: How do you think, ... agents should be given authoriza- authentic... How should we authenticate agents? How should we give them authorization? Because this actually came up in our in our governance roundtable. So we had executives come together to talk about governing agents- ... at scale, and this idea that we basically give the agent whatever authority the individual would have had to do a similar task and access to the same tools, et cetera, and that was a flawed model. Do you wanna talk a bit about that?
[14:52] Staffan Truvé: It, it-- and it is a hard problem, I think it's one thing just to say that you're giving, let's separate, let's break it down a bit, right? So first of all, authentication. Essentially, we have to do similar kinds of authentication as we do for humans. The-- and then and then when it comes to authorization, I think that's the tricky part. How do you express what an agent is allowed to do and how... Especially if you assume that we're gonna have networks of agents. You have an agent who's gonna spin off a swarm of other agents. Is that agent allowed to give all its sub-agents the same authority as it has itself? Yep,
[15:27] Christina Ellwood: this is exactly what they were talking about, yeah. Yeah.
[15:29] Staffan Truvé: Yeah. No. So I think, and there are actually pretty old, there are standards which are, like, twenty years old. If I remember correctly off the top of my head now, there's one standard called XACML, which is the standard for how you delegate authority, including how you delegate the right to delegate authority. So I think, maybe it's time to revisit some of those existing models for how we do this. But I think both doing that and also figuring out how do we actually give humans the ability to have oversight over swarms of a- of agents.
[16:05] Christina Ellwood: Yeah. Can I also add to that? That this, again, came out at the roundtable, that when you give someone the authority to review what they're doing and what have you, they also need to have the ability to shut it down.
[16:18] Staffan Truvé: Yes,
[16:18] Christina Ellwood: exactly. And it was surprising to me that this was conceived as a common problem, that the review-- the human in the loop can flag it as a problem, but they cannot prevent it from being deployed, and that seems like such an, an, an odd conundrum to put the reviewer in a vulnerability that is easily solved.
[16:37] Staffan Truvé: Yeah. No, and I think, in, in a sense, if you go back, to let's call it classic computer science, it's the same problem you have if you're launching a process on your system and then that process spawns off sub-processes. It's of course the same thing. It's nothing new in that sense. It's of course the, the autonomy, the flexibility, and the ability to do unexpected things, which is the difference from this, let's call it AI-enabled, LLM-enabled generation of processes as compared to the last one. And the expanded context. Yes. Yeah. In those cases- Exactly ... you had a very narrow context that they were operating within.
[17:11] Christina Ellwood: Yeah. So do you wanna predict what what we're gonna see in the next generation of defense or the next generation of attack?
[17:19] Staffan Truvé: So I-- o-one of my favorite ideas at the moment is that, as I said, if we assume that that we're just speeding up things and we're not changing the power balance there, then I think we need to figure out other ways to improve our defenses. So my, my favorite at the moment which we are of course working on a bit, ... is to build what I like to call deception networks, which you could at one level think of as the next generation honeypots. So let me explain a bit. So what that means is that, first of all, the attackers are of course resource constrained. First of all, it's not gonna be cheap for them to run large models and to do high sort of big scale attacks. That's gonna cost. So any way we can reduce their expected return of investment is a way we can prevent... sorry to defend ourselves better. I'm sure. So what I mean by... Yeah. So exactly. So exactly. So what deception networks is, the idea is essentially that, let's take our actual system, let's build a bunch of fake copies of it. This is essentially, you can think of it as the next generation honeypot, essentially. But if you present now not your, just your real system, but let's say a thousand versions of that, nine hundred and ninety-nine of the, of which are actually fake, the, the attacker has to spend resources trying to figure out which one is the real one. And the more genuine we can make them, the more resources they will spend in the wrong place. And the beauty is of course that each one of those deception systems becomes a sensor. So when the attacker goes after one of those fake ones, we will learn about their mechanisms. We will understand more about how they attack, so we can actually improve the defenses of our real systems.
[18:57] Christina Ellwood: That's an exciting
[18:58] Staffan Truvé: idea. And AI will... Yeah, and A-AI will be critical in doing this at the scale you need to do it, but also at the level of sophistication to make these fake systems realistic enough that they actually fool the attackers. Because of course, the attackers, again, in this constant arms race, will figure out how to identify what's a fake system.
[19:17] Christina Ellwood: Totally. But it's a game of staying one step ahead as always with any kind of warfare, right?
[19:23] Staffan Truvé: Yeah. Yeah. And We u- we used to say that the, what makes cybersecurity such a fascinating area is, to be in, is that you're up against very sophisticated and smart opponents, and they used to be-- we used to think of them as only human opponents. Now we're adding to that by actually having extremely smart AIs on the opposing side. So
[19:42] Christina Ellwood: we're- Well, do you think we're gonna see models be developed that are optimized only for security use cases? Essentially the chapters model?
[19:54] Staffan Truvé: Maybe. Maybe. I'm... But I'm actually a big fan of the idea that the, the general models will be so incredibly powerful that they will be good enough. It could be that someone wants to distill a more specialized model, essentially just to make it cheaper to run. But, s- same techniques that are being used today to, to scale down models so that you can fit them on smaller devices, fit them on your phone and things like that. So I can imagine that we will see that kind of downscaling maybe. But but otherwise, I think the general purpose, the power of the general purpose models is so big that I think we can expect that to be the, the standard tool going forward.
[20:32] Christina Ellwood: One of the things we're, we saw recently is the use of this is from a specific startup that is using homomorphic encryption to encrypt tokens. What's your thought about that type of approach where you pull back the, the vulnerability to the the beginning the sort of moment when the AI is engaged?
[20:54] Staffan Truvé: Probably, one of many ideas we need to look into. I think there's there's a great design space at the moment for creative ways of the deception was another example of that, creative ways of using both old and new technologies to improve our defenses. And I think, this is, a- and as we said, it's an arms race. We have access to similar tools so creativity and the speed at which we can innovate will clearly be an important component in who wins.
[21:20] Christina Ellwood: We've also been very successful in the world of cybersecurity by having essentially a collaboration, a, a coopetition kind of model where different companies' strategies are added together, if you will or work in tandem in order to elevate the level of security. Do you think that will continue? I
[21:40] Staffan Truvé: think it has to. My standard argument being that since the bad guys collaborate, we have to collaborate on the defending side as well. And there's been the-- And there's been improvements, there's still a long way to go, I think especially in public-private collaboration, we still have work to do.
[21:55] Christina Ellwood: Yeah, even in public-public. Indeed. So you've always described yourself... Yeah. You've always described yourself as a tech optimist who plays devil's advocate. The AI attacks our systems scenario you sketched last fall is now actually happening, so for an executive listening today, what's the one thing they should do differently because of it?
[22:19] Staffan Truvé: I think, first of all, this is actually a time to realize that you need to invest more. As I said in the the methodology for how to defend, we, I think we understand pretty well, but it all comes down to, to resource allocation. And, we hope that there is, and you alluded to that, that hopefully next generation software is gonna be better tested and so forth. So hopefully we're at a bump now where we need to invest significantly in, in securing our existing code base, our existing systems. So I think that's maybe the most important thing. I know it sounds terribly salesy to say that you need to invest more right now, but, Yeah,
[22:55] Christina Ellwood: I know. It's-- and especially when it comes from someone who has a vested interest in them spending more. I know, but it doesn't mean it isn't true. It doesn't mean it isn't true. Do you have a guide for people on how much they should be allocating, like a percentage of the X budget? I don't even know if we know what budget to look to for this at the moment because budgets are being affected by the AI. But if you were looking at it, say, just from the cybersecurity budget or just the IT budget, what kind of number would you gauge for people that they need to consider as compared to in the past?
[23:26] Staffan Truvé: I I would actually be hesitant to give a number as such. I think the, the methodology here should be to... first of all, as I said, many people already ha-- and we talked about it, already have a backlog in in, in known vulnerabilities they haven't fixed. So now is the time to do that because the likelihood that they will be exploited is going up dramatically.
[23:43] Christina Ellwood: So
[23:44] Staffan Truvé: I think that's the first investment. And then I think, as soon as you can get access to next generation tools for testing, whether they are from OpenAI or Anthropic or the new companies emerging in this space, I think you need to go there. Essentially you need to ensure that you're on par with the attackers when it comes to vulnerability detection. But of course, then at the s- at the same time, the, all the old standard cyber hygiene things about what we talked about before, making sure that you get to a level of authentication which is good enough and so forth. But I think, but I think, being prepared to spend more time and money on on, on detection and defenses, I think is absolutely necessary.
[24:29] Christina Ellwood: What resources do you recommend for listeners who wanna learn more about you and also about Recorded Future?
[24:37] Staffan Truvé: So Recorded Future has always had a policy of of having analysts, our own analysts do the relevant research and write reports. So there's a ton of free resources available from our Insikt Group. That's our own analyst group. Also, our media side, the record, is is great resource and a free resource even without advertisement for tracking interesting trends in cyber. So those are the most two straightforward things we offer for free. But otherwise, it's the usual thing. If-- I guess if there's anything which stresses me out right now, and I'm not very easily stressed out, it's the amount of stuff you need to follow, just to be able to feel that you're on top of what's happening.
[25:16] Christina Ellwood: If they wanna follow you, what's the best way for them to do that?
[25:18] Staffan Truvé: So I don't have any sort of regular feed. I try to-- I sometimes publish and actually, follow me on LinkedIn. That's a simple thing. Okay. When I see interesting stuff I put it up on LinkedIn. That's the most simple way.
[25:30] Christina Ellwood: Okay. So in the AI revolution what it takes to lead an organization, inspire them, overcome the internal obstacles and so forth have somewhat let's say they've shifted on what leadership skills we need. So what leadership skill do you find most vulnerable in your work today?
[25:49] Staffan Truvé: Leadership. I think maybe the, I think maybe lack of imagination maybe is is something I sh- I would like to point out. I meet so many people today who say AI will at least never do that." And of course, three mon- three months later, it's doing that as well. And I hear it, and I hear it within my own organization as well. Yeah. People say that it's, it can do this and this, but it will never do that." And I think we have to assume that... Essentially, I think we have to assume that everything we humans currently work on, will be automated in some way, possible to automate sometime, some way in the future.
[26:24] Christina Ellwood: Yeah. I think that's-
[26:26] Staffan Truvé: I think that's fair. But I think also, then we shouldn't, some people say that's a depressing thought, but I don't think so because we're actually... That means that we will have access to a whole new set of tools which will enable us ourselves to do new things as well,
[26:39] Christina Ellwood: yeah. I think it... A- and that's always been true with all technology e- evolution, too. So if our listeners remember one thing from today's conversation, what should it be and why?
[26:50] Staffan Truvé: I think what we already said, this is actually happening now. I think you need to spend time to understand what's happening, and you actually need to start working. It's no, no time to sit and say that, "Okay I'll do this next year." You have to start di- start diving in right now.
[27:05] Christina Ellwood: All right. Staffan Truvé, CTO and co-founder of Recorded Future, thank you for sharing once again your experience with us today on the AI Realized podcast.
[27:16] Staffan Truvé: Thank you very much. Very good to see you