{
  "video_id": "TYpg5oxSQ6Y",
  "channel_slug": "ibmtechnology",
  "channel_handle": "IBM Technology",
  "title": "Should you let OpenClaw pen test your system? Plus: Cybersecurity for ephemeral software",
  "duration_seconds": 2172,
  "url": "https://www.youtube.com/watch?v=TYpg5oxSQ6Y",
  "upload_date": "20260422",
  "transcript": "Security software firm Sophos let an OpenClaw agent run wild in an on-prem\nnetwork just to see\nwhat it might do. Panelists. Would you trust an AI agent to pen test your system\n100%? Maybe\nnot. I guess it depends on the system. No,\nI'm not gonna. I'm not gonna go that far.\nHello, and welcome to Security Intelligence, IBM's weekly cybersecurity\npodcast, where our expert\npanelists turn the biggest industry news stories into practical takeaways that you\ncan use. I'm\nyour host, Matt Kosinski. And joining me this week, as you've seen, we've got\nClaire Nunez, Creative\nDirector, IBM X-Force Cyber Range, Dave McGinnis, VP/senior partner, Global Cyber\nThreat Management, and\nKimmie Farrington, security detection engineer. Today, we're going to be digging\ninto\ncybersecurity in the age of instant software and the possibly uncontrollable\ngrowth of ransomware.\nBut first, we have to keep talking about Sophos's experiment. Does OpenClaw make a\ngood pen\ntester? Now, as you heard at the top of\nthe episode, the red\nteam over at Sophos recently ran an interesting experiment. They took an\ninstance of the open\nsource AI agent OpenClaw, told it to act like a red team operator and let it loose\nin a legacy on-\nprem network. They were looking to test a thesis put forth recently by Ross\nMcKerchar, who also\nworks at Sophos. He wrote, \"Even the most risk-on organizations with deep AI and\nsecurity\nexperience will likely find it challenging to configure OpenClaw in a way that\neffectively\nmitigates the risk of compromise or data loss while still retaining any\nproductivity value.\" And\nguess what? OpenClaw did a pretty good job. The team had to put some decent\nguardrails in place,\nbut it did find 23 actionable, high quality findings, according to the report.\nNow I'm thinking\nabout this a lot, especially in the context of stories like Claude Mythos\nescaping its sandbox\nduring testing or even OpenClaw itself, supposedly bullying a coder when they\nwouldn't\naccept its code. You know, once once you set an agent on a path, it can be hard to\npredict its\nactions. And so, Dave, I want to start with you by asking. You know, when you\nlook at what Sophos did\nwith OpenClaw here, does this exercise teach us anything about how we can make AI\nagents into\nreliable security partners who don't go off the rails? What did you take away from\nthis one? Of\ncourse. Right. Like red team is is an application thereof. Right? So if if we\ntake this right,\nlet's talk about what a red team is. Right. Find vulnerability. Ideally push\nand exploit that\nvulnerability. Yeah someone's going to do it. They're either going to be paid to do\nit for the\ngood side, or they're going to do it for the bad side. So are we going to just let\nthe attackers do\nit? Nah, I'm not going to happen. Right. So so the more that we lean into this, the\nmore that we\nlearn, the more that we figure out what it is. And, you know, don't pretend it's not\ncoming. And this\nis for all jobs. Not just security jobs, right? The better it's going to be, right?\nYou've got to try\nit out right and kind of figure it out. Like this cat is not going back in the\nbag. Right. We can't.\nThe milk has been spilled. Pick an analogy, it doesn't matter. They all work,\nright. So, so\nso my my take on this is. Thank you. Sophos. Right. I love that you did that.\nWe're doing some of that\nwork ourselves. Right. Like we built a harness. We put it on top of right. And\nwe're running it with\ndifferent models underneath to see, hey, is this better than my traditional\nscanning software? Is\nit better than my traditional pens? Like, what is it doing? You know, is the gap\nright? Right now\nthere's a gap. And as Sophos talks, it's 23. Like okay not horrible. What's it\ngoing to be like when\nwe talk about the next topic. Right. When we're having software generate all the\ntime and it's\nless static and it's much more, you know, transient, perhaps. We'll talk about that\nnext. Right. Like.\nLike to me? Yes. We have to lean in. It's exactly the right thing to go do so that\nwe learn. And I\nthought Claire and Kimmie made great points in the open. Right. Well, what\ncontrols do I want to put on\nit? Right. Where do I want to stop the process of: found hole—what do you want me\nto do about it?\nYou want me to patch it? Do you want me to? Right. Right. So? So we have to be\ndoing more of this.\nAbsolutely. I like that because especially, you know, recently there's\nbeen all this conversation\naround when should we use these powerful models? Who should use them? I mean, you\nknow, we had Claude\nMythos come out. We had GPT-5.4-Cyber. So like, there's all this discussion about\nwho who should\nhave it, who shouldn't. And Dave, you're echoing something that a lot of other\nfolks have said, you\nknow, Martin Keen and Jeff Crume, when I talked to them about GPT-5.4, which is\nlike, look, this stuff is\ncoming. So we might as well get in there and start using it and figuring out how we\ncan use it best,\nbecause if we wait, if we sit around and try to oh, well, I wonder what's going to\nhappen. The\nattackers are going to get it, they're going to use it, and then they'll beat us.\nAnd so it's like\nit's a speed run, right? But I do also want to go back to like you said, there's\nthose guardrails\nfiguring out what guardrails you want to put in place. And, Kimmie, I want to ask\nyou about this\nbecause something that came up during Sophos's experiment was right. They were\ntrying to make\nsure that that OpenClaw could find flaws but not do any damage. And they they\nfigured that that, you\nknow, they figured out that putting these, these boundaries around it did introduce\nwhat they\ncalled some friction into the process. Right? A quote from the piece is that \"the\nmodels we used\nregularly refused to cooperate due to concerns around malicious use.\" So it's\nlike you got to put\nthe guardrails in place, but then it can stop them from being productive. Do you\nhave any thoughts on\nhow we navigate this particular challenge of like, just enough guardrails that that\nthey can still\nbe useful at any takes there, Kimmie? I'll tell you from a detection engineer's point\nof view, OpenClaw's\na nightmare. And I can say that because as\nsoon as\nit became available to the general public, all of our network administrators, anyone\nwho has their\nown, you know, administrative privileges on their box went and downloaded a copy\nand started trying to\nuse it. And then we realized, oh, oh, hold\non. We weren't actually prepared for that.\nSo then we had to figure out how to block it. And that's turned out to be an amazing\nnightmare,\nbecause it has privileges and it looks it's a it's an agent that has been given\nprivileges\nintentionally to go and do things for you. So, you know, how do you put those\nguardrails on?\nThat's a really great question. This is what we've been grappling with, you know,\nsince the, since\nthe invention of AI. Honestly. But but certainly now OpenClaw has presented us\nwith this massive\nattack surface. and we have to figure out\nhow to keep it from running amok.\nRight. I think a big part of it, like you\nsaid, is to get comfortable with the tool,\nunderstand what it does, how it does it, and then understand where the potential\nopportunities for\nit to go off the guardrails could be. Right. This is going to be a learning\nexperience for\neveryone. But like you said, if the attackers get comfortable with it first.\nThey're the ones that\nset the pace for us. Then we have to. Then we're just spending all of our time\nchasing them and\ncatching up, right. So, you know, certainly encouraging everyone to use the\ntool,\nyou know, with, with human in the loop.\nDon't just let the thing go crazy.\nBut like, Dave started leaning into the next article about, you know, the\nephemeral software\nthat's going to be another nightmare. Sounds like. Yeah, we're doing we're doing\na lot of nightmares\ntoday, folks. But no, I like I like, you know, I think you're right, Kimmie, that\nlike, this is a situation\nwhere it's a learn by doing thing. And it's one of the things that I really like\nabout Sophos's\nexperiment was they were like, we're taking OpenClaw. We put it on an on-prem\nnetwork, the legacy\non prem network, so it can't really touch anything cloud based. It's kind of\ncontained. We put some\nguardrails around it to see, like what we need to do to make this thing operational.\nAnd I think\nthat's the only way you can figure it out. I don't think you can theorize your way to\nthis stuff. You\njust got to like you and Dave have said, get in there, play with it, see what works\nin a safe way.\nAnd you also brought up and I think I've quoted this like once per episode ever\nsince you said it,\nDave. And I'm going to say it again, you know, Dave once said, AI agents are the\nmost helpful\ninsider threats we've ever had. Like, I just love it because it really\nencapsulates what we're up\nagainst, right? Like, they're amazingly powerful and also like, super dangerous.\nAnd we're still\nfiguring it out. Claire, I want to bring you in here because there's another\nthere's a takeaway\nfrom all of this that that McKerchar puts out there, which is basically that it\ntaught him that\ncybersecurity teams are maybe better placed than anyone else to be at the\nforefront of AI adoption.\nI'm wondering if you agree disagree. How do you feel about that take what are your\nthoughts there?\nIt's such a loaded question, though, because I think about AI adoption. I think\ninstantly that\ntoo many people are doing it too quickly and not putting the right safeguards in\nplace, not testing\nit properly, but I do think that security\nhas a really useful use\ncase. It's not just asking, you know, ChatGPT to make you a grocery list,\nsomething that you could\nfundamentally do yourself. It is actually\nvery helpful in terms of, you know, making\nsecurity something that is maybe a little bit more, tangible for organizations\nbecause it is\nsomething that is expensive for organizations to implement and they don't\nalways want to, which is\nnot the right way to think of things. But that is how a lot of organizations think\nof things. I do\nthink that security can definitely bring\nin AI in a way that\nmakes sense to use, like in a way that makes sense, if that makes sense, like\nyou're using it for\nsomething that that can actually look at those repeatable workflows and look for\npatterns and\nthings like that. At the same time, though, I think there is a lot of nuance\nin in what a human\ncan do and look at. And I think there is a\nlot of nuance in in what a human\ncan do and look at. And I think that AI can't just be fully adopted as is for\nsecurity. Like, we\nobviously have to have a human still around and still kind of validating, still\nlooking like, does\nit make pen testing maybe easier and faster and maybe lower cost and more\ntangible, again, for\norganizations? Sure. But I think you still need a human who can look at things in a\nnon, you\nknow, one dimensional way. Absolutely. And I like that you kind of pointed out that,\nthat one of the\nthings that makes security so well positioned here is that, like AI can help\nus solve real\nproblems we have. Like for a very long time, for example, alerting and detection\nmoved faster than a\nhuman being could, right. And like that's an amazing place where AI can help maybe\nstep in. And\nso towards that end, I have to start wrapping this up for this segment. But I\ndo want to throw to you,\nDave, before we end it, which is that let's say a cybersecurity practitioner, an\norganization,\nthey're sitting here, they're listening. They're going, you know what? I want to\nstart bringing AI\nagents into my security workflows. Where do I start? What's the what's the step I\ntake? First, I\nfeel like you're the best positioned to answer this, Dave. So. So tell us, where\ndo you start with this\nkind of thing if you want to explore it. Quickly, great instincts to whoever's\nlistening that's\nthinking that they should do that. Good idea. Just like we said at the start.\nRight. So you you got to\nyou got to get started. And I also really like what you and Claire were just talking\nabout that,\nyou know, security is best positioned. We've always been overrun, right. Anyone\nwho's sat at a console\nand tried to keep up with events knows that. Man, I would really like an AI\nhelper. Can someone\ndo this stuff for me? Right. And we've talked about it, you know, on, I mean, the\nother times I've been\non. Right. Is it vulnerabilities? Is it right? You know, bug bounties. Like we've\ntalked about it in\nevery single aspect of security, right? So is it helping me process changes and\ndoing, like\na really robust risk. review of, oh, hey, I'm going to make this change to my\nidentity policy.\nWell, maybe I should run that past, I don't know, the rest of our security\nposture. Right? Like, what\nis our ontology change if I do this right? Firewall changes and just kind of static\naccess\ncontrol, things like that. The threat program, if I can if I can be so bold as\nto say it's a\ntarget rich environment. Right. Like everything we do in threat, we started\nwith pen tests. We can\ntalk about monitoring. We can talk about investigation. Right. We can do all that.\nBut and I\nthink the point that you and Claire are on is that security is actually very used to\nthis. Like\nwe have two things. One, we live in a world that's completely overrun with data,\nand we we can barely\nkeep our heads up. So we want these tools more than anybody else, and we know what\nwe want them\nto do. So the questions of guardrails and harnesses and things like that, that we've\nbeen\ntalking about, we're good at. The other thing is I'm going to say it nice and then\nI'll say what\nwe really are, right? Like we're experienced, really experienced, looking\nfor the holes, looking and\nquestioning like, well, why does it need to have access to this and that? We're\nparanoid. That's the\nreason why, right? Like, we live in a we live in a mindset that that is like, well,\nwait a minute, hold\non. Like, how can this hurt me, right? Like, what is it? Because that is what our\njob is, right? We're\nhere to defend our organizations. My case right through our services, our clients.\nRight. That I\nshould say, all of our cases, our clients. And so, like, we've just, like, I've got\n25 years of being\nparanoid and asking questions like, well, what about that? What about that? What\nabout that? Right.\nAnd then I always know that there's somebody else that knows something else\nabout somebody. Right? So\nyeah, I think I think the, the sum, to sum all this stuff up is this is all what the\ngood side\ndoes. Right. This is the defensive side. We're protective and things like that. And\nwe're talking\nabout putting guardrails and harnesses on LLMs that people will have. So I'll leave\nyou with this\nthought. How many LLMs exist in the dark web? How many live in open source that\ndon't have\nguardrails or care about putting guardrails, or will listen to us? We're\nreally continuing the\nnightmare theme, and we might keep continuing it, but I do I do before that,\nbefore that, that abyss\nthat you asked us to stare into. There's a lot of extremely good information and for\nfolks to\nfollow. So I'm going to I'm going to close out the segment on that note. But before I\ndo, I just want\nto throw it to the viewers. If you're watching on YouTube, comments are open. If\nyou're experimenting\nwith AI agents in your security processes, tell us how you're doing it and how it's\nworking out.\nPut that in the comments. But we got to move on to cybersecurity in the age of\ninstant software.\nNow, Bruce Schneier, a man who probably needs no introduction in cybersecurity\ncircles, published\nan essay by that same name, Cybersecurity in the Age of Instant Software, earlier\nthis month in CSO\nOnline, exploring how the rise of AI- coded, instant, ephemeral software might\nchange patching\nand vulnerability hunting forever. I'm sure I won't do it justice, so I recommend\nthat everybody\ngo find this essay and read it. But the gist is AI is getting so good at writing\ncode that we may be\nheading toward a world of instant software. You know, apps basically spun up\non demand, used a few\ntimes, and then discarded when they're no longer needed. The pluses here would be\nthat, you know, if\nyou've got bespoke code, attackers don't already know what vulnerabilities it has.\nThe downsides\nhere are that the vibe coded bespoke code might be so full of holes, the attackers\ndon't need to\nknow what vulnerabilities it already has. So there's a little bit of a who knows?\nRight. Kimmie, I\nwant to ask you about this first because, you know, look, you were talking about our\nlast nightmare\nOpenClaw, and you gestured towards this possibly being another nightmare. So\nagain, as a security\ndetection engineer, what are you thinking about this idea of ephemeral software and\nwhat it might\nmean for cybersecurity? Ephemeral just means that there's going to be a whole lot\nmore of it.\nThey're not going to get rid of it. It's not going to spin back down. There's not\ngoing to be a\ndeletion of the thing after they're done with it, that somebody is going to have\nthem vibe-code a\nthing, they're going to say, oh, I've got this cool tool and that they're going to\nshare it with all\ntheir friends, and then it's going to just continue to exist in whatever state that\nit came\nin with. Whether it's full of holes or not. I'm sorry if that's a defeatist\nattitude, but that is\nwhere I came from. That's the immediate thought was like, oh no, this is even\nworse. I think that\nthat's a really good point, though, because like, you're right, this assumes\nthat, oh, we'll spin it\nup and then we'll spin it down. How how much stuff do we already not spin down.\nRight. Like, like how\noften are, like credentials and accounts just left sitting after people leave. And\nit's like, if we're\nnot getting rid of that, who's getting rid of the vibe coded ephemeral software,\nright. I just don't.\nSee it personally. I get that, I get that, and I'm seeing head shakes from Dave and\nClaire, or nods\nrather, suggesting you folks agree. I think all of us are a little skeptical of\nthe idea that\nthe software is going to go away. Claire, I want to bring you in here. You know,\nwhen you think about\nthis ephemeral software that we possibly are dealing with. How does it change like\nthe human\nsecurity hygiene practices side of things? Right. We were just talking about like,\npeople don't even\nproperly dispose of accounts. What other practices do you think this is going to\nchallenge us with\nwhen it comes to teaching good security hygiene? I think there's going to be like\na serious\ngraveyard of of just like dead vibe-coded apps that someone was like, oh, this is\ncool. I'm going\nto try it and see what happens. I think the issue, too is going to be some people\nwill continue to\nuse that in its original form and never, use it again. And then maybe that's a\nvulnerable\nversion, versus a newer version. I think it's also just kind of like, what data are\nwe putting\nin those applications? And what is like then there's compliance risk there too. If\npeople are\nusing kind of like, I guess shadow uh,\ninstant software, but I think it's\nyeah, I think it's just going to be there's going to be a lot of\nvulnerabilities. There's going to\nbe a lot of just data living out there. Yeah. Claire, I'm glad you bring up the\nidea of, like,\nshadow ephemeral IT because it's like, oh, boy, could you ask for, like, a worse\ncombination? You\nknow what I mean? And I didn't, honestly, when I first read this, I didn't even\nthink about that\nangle. But you're right. This piece\ncontinues an\nidea we've seen crop up a lot recently, especially around like Mythos and\nGPT-5.4-Cyber,\nwhich is that as we develop these more and more powerful models and AIs and they get\nbetter at\ncoding, maybe we can start inserting them earlier in the process to make like\nshifting left an\nactual reality. Like we've talked about this for a long time, but a lot of people\nare saying, hey, look,\nif the AI is really good at coding, you stick it in there. Maybe it catches more\nvulnerabilities\nthan we did before, and now we have just less vulnerable code overall. Dave, I\nwanted to ask your\nthoughts here. Do you think that that is a realistic view of how we can slot AI into\nthe\ncoding process and maybe use it to make up for some of its own shortcomings,\nbasically, right. What\nare your thoughts there? Well, I mean, I think that's why we were all talking about\nMythos, right?\nRight. Like, wait, hold on. I can find stuff and then fix it. Like, that's the\nthat's the that's. The\nwhole. Man. Yeah. The trouble is that on the other side of this, we don't call bugs\nbugs. We call them\nvulnerabilities. And when you write code that uses them, we call them exploits. You\nknow, just a thing.\nRight. So we're back to the good and the bad. Right. So it can't hurt. It can only\nhelp. Sorry. Talk\nabout getting cut. Jeez. Is that what you were going? I'm not sure what I'm trying\nto say at\nthis point. it will help if we write better code, obviously. Right. That has to\nbe the thing. And\nI think that's the altruistic version of what we. What? You know, all of them,\nright? Like Anthropic\nand OpenAI. Right. You know, Gemini. Pick a model. Doesn't matter. Right. Those\nthose things, you\nknow, are are not trying to be bad tools. They're not they're not. There are some\nother ones that\nare out there are definitely trying to be bad tools. Right. But the ones that have\nall the money\nand the things that are going to come first, at least so far, right, you know,\nare to help. I think\nthe other part of this is we need we need the defenses, not just. Yeah, write better\ncode. Right.\nAnd completely agree with the premise of the article. That and what you guys have\nbeen chatting\nabout, like, yeah, it's going to happen. Of course it's going to happen. And yes,\nhygiene is going to\nbe ah, come on. We don't do it now. Right. So so completely agree with everything you\nguys have\nsaid. So so isn't the real answer. We need\nalways on ambient predictive\nprotective defenses. We can't respond with humans in the loop anymore, right? So we\nneed to lean in\nlike this goes right back to the first comment. Like would you use a pen tester\nAI? Right. Yeah, yeah, I'd\nalso use one to stare at my identity. I'd also use one right all the way down the\nstack. So like that's\nhow you get to like this ambient always on\nfully autonomous defender. Right. So like,\nwell wait a minute. I don't know what this thing is, but I have the ability to pause\nit, quarantine,\nand do whatever it may be before it hits users data. You know, other systems, it\ndoesn't spread\nbecause that capability is built into my, my, my whole, you know, security ontology\nas a, as a as an\nenterprise. That's hard. Right? I know we're working on it. It's it's a it's a\ndifficult thing. Right?\nBecause you've got the business challenges and they're wanting to go do different\nthings. Right.\nSo cool. You've got their technology ecosystem, which is not just security\nthings. Right. And you\nneed to bring all of that stuff together. Oh, not to mention they have partners that\nthird parties\nthey got all kinds of. Right. Clients have not that we don't. Right. But like clients\nhave all kinds of\nchallenges and like I need to be open, but I need to be secure. The only way we're\ngoing to solve\nthis is with with defensive AI that's running ambiently that, that that has a\nmindset shift\nof I'm not here to react to it. I'm here to predict where it could potentially\nhappen. Prevent\nit from from ever becoming a problem. Right. Just completely reduce all of that\nthrough\ncompensating controls, through code fixes. Like we were just talking about whatever\nthat might be.\nRight. Always on, always rolling. Right. And then what we get to do. And the\nchallenge is, is like,\nwe're going to have to keep bringing in the domain experience. And that could be\nfrom the\nbusiness side. It could be from threat intel. It could be. Right. Like that's\nwhere humans, I think\nare going to kind of go to this. I know you didn't ask that question, but someone\nis thinking about\nlike, did he just say there's no jobs for security? No. Absolutely not. Right. It's\njust we shouldn't be\nstaring at screens. We shouldn't be trying to like, well, is this a good change that\nI should approve?\nNo. We can we can build that in. Right. Like there's confidence. There's things\nthat we can do. We\nneed to operate at machine scale now. I really like that. And I like that you also\ngesture towards, you\nknow, the kind of supply chain angle here, because part of what complicates things\nabout this\nimagined world of like, you know, ephemeral software is that there's how we\nmanage\nvulnerability detection for like spun up software someone made in-house versus like\nproprietary\nsoftware. We don't have the access to the source code, but it's still in the supply\nchain. It's\nstill part of it. Like those are different things. And, you know, it's going to take\na different\napproach. And I like how you kind of summed it up as like this always on\nautonomous basically\necosystem that is looking at all this stuff and it's approaching these things.\nIt's picking up on\n00:22:53,869 ecosystem that is looking at all this stuff and it's approaching these\nthings. It's picking up on\nthings. And then you bring that human in the loop for those decisions. Like, what\ndo we do about vibe\ncoding software versus this, this, you know, proprietary software like that is I\nlike that.\nIt's a really holistic picture of things. I have to wrap us up pretty soon. But to\nto wrap up the\nsegment. Kimmie, I just want to ask you, you know, Dave has really kind of set the\nstage for like,\nwhat he imagines we need to do to secure ephemeral software. But any thoughts you\nwanted to\nadd there in terms of like, look, we're headed towards this future, here are the\nthings you need\nto start thinking about now. Any takes there. That's a great question, but I\nreally wanted to\nrespond to the earlier question, which. Go. Throw my question away. Respond to it.\nWhere in the\nprocess of security should we introduce the AI LLMs? Right. And I wanted to just\npoint out how\nironic it is that we, we in the same conversation, we talked about how\nvibecoding is potentially\nfull of holes and full of vulnerabilities,\nbut we want AI to fix itself.\nSo that's again, this is where this Mythos thing comes in. That's great. But at the\nsame time, like,\nhow come we can't just tell the vibecode to make it with secure code, right? Like,\nwhy\ndoesn't it just automatically make it secure? Why are there holes in vibecoded,\nyou know, AI-\ncreated code. I that part kind of blows my mind. Like, can't you just tell it as part\nof its\nguidelines? You know all the best practices for security. And when you write\nyour code, it should\nhave no holes. I'm like, no. Let me just\ndo that. I mean. I think\nthat this gets to like Dave's point again about how like, you can't take the people\nout, right?\nBecause like at the end of the day, the people are telling the the you're\nprompting things, right?\nYou're prompting the AI to write it. And especially we're talking about this future\nwhere\nlike, people are spinning up their own apps on the fly. You're talking about a\nbunch of people with\nno security background prompting a thing to to to code it. Right? And it's like if\nour expert coders\nwho know this stuff can't produce code with zero flaws, of course, the vibecoded\nstuff by a guy who's\nnot an expert coder is also going to have flaws. And it's almost like, I keep\nthinking of this idea\nof like defense in depth. And I feel like it really applies to AI especially,\nbecause it's like\nyou need an AI to watch your AI, to watch\nyour AI, to watch your AI.\nAnd it's like, you know, I think that's just security, right? Like that is that\nthose layers are\nhow it works. And now the difference is just there's an AI in some of those loops\ninstead of\nlike, you know, just an IPS or something like that, you know. But, we got to move\non to our final\nstory for today, folks. I really like that discussion though. This is ransomware\ngrowing\nthree times faster than security spending.\nThis comes from breach intelligence platform CipherCue, who reports a\npotentially troubling\ndiscrepancy between attackers and defenders here. According to an analysis\nof ransomware leak sites,\nCipherCue found that the number of claimed ransomware incidents increased by 30%\nbetween\n2024 and 2025. They then compare this to Gartner's July 2025 spending forecast,\nwhich found that\nworldwide information security spending only increased 10% in that same time\nperiod. Now, CipherCue\nnotes that this isn't like a perfect comparison, but I like how they\ncontextualize it. Right? Which\nis, quote, \"Directional comparisons like this are how budget conversations start.\nIf the observable\nthreat is growing at 30% and the budget is growing at 10%, the gap compounds every\nyear it\npersists.\" I think it's an interesting idea. Claire, I want to start with you.\nWhen you look at\nthis, do you find this concerning? Are you like, you know, there's there's a point to\nbe made here or\nare you like, I don't know man, like, what's your take? What's your response\nhere? My initial thought when\nreading this was like this is a confusing comparison of of ransomware. Yeah, sure.\nRansomware\nclaims are increasing okay. But spend is\nincreasing only a little bit. I think it\ndoesn't take into the, into account, like everything that organizations are doing\nfor\nsecurity, or past elements that organizations have taken into account for\nsecurity, like\npast trainings and things. I think also, just because something is increasing in\nthe wild\ndoesn't necessarily mean an extra spend needs to be taken. I think security in\ngeneral, excuse me, is\none of those things that, you know, organizations don't really want to have to\nspend money on, like\nthey they know they should. They don't always want to. Unfortunately, we all know\nthat here as as\nsecurity professionals. But, you know, I think it's one of those things that\norganizations don't want\nto, like, dump a ton of money into. But I don't think saying that just because\nransomware claims\nhave increased, you know, 30%, that that spending should also increase 30% or\nsomething. I think it\nwould be far more valuable to see, like the efficacy of, of that spending. Like\nhow\nefficient is that spending in those programs? That's a lot more difficult to\ntrack than than\nspend itself. But, you know, I think just because you spend more doesn't mean that\nyou have a\nbetter security posture in general. It comes down to your overall organization,\nsecurity culture and\nand and everything as well. You can spend so much money on a tool or services and,\nand not do\nanything with that tool or those findings from different services or assessments. I\nmean, we we\nsee that a lot. I think we all see that a\nlot. So, you know, spend. Spend does\nnot like you can spend $1,000 on a dress and it could still look really bad on you\nif you style\nit poorly. Like it's it's so true though. You can spend a lot of money on something.\nI really like\nthis point that you're making, and I think it's a really important one, which is that\nlike it's it's,\nyou know, just because something is increasing in the wild doesn't mean the\nresponse is you spend\nmore money on the thing, right? It's like how you spend the money and what it's\ndoing is way more\nimportant than the sheer numbers. And I really like how you contextualize that,\nespecially in, as\nwe've been talking this whole episode about AI and how it's going to change\nthings. And I think\nthere's a real temptation for organizations to be like, buy the AI\nthing, and then we're done. And\nit's like, that's not that's not how it works. You know, there's a whole Dave has\nbeen laying it out\nfor us steadily. There's a lot of work that goes into it. It's not set it and\nforget it, you know\nwhat I mean? So I really like how you're contextualizing that. Kimmie, I also saw\nyou shaking\nyour head. You're like, I don't really love this study. I want to see what what\nare your thoughts\non these numbers? What does it make you think of? Claire has a great point right\nthere. The two\nthings are not really, you know, compared to each other. This is a very difficult\nthing to say that\none has anything or has has any direct comparison to the other. Right. Yes, sure.\nCompanies don't\nreally want to spend money on security. Got that? We. That's sort of been a a\nbaseline across the\nboard, right? It's it's a spend on top of things and they don't see really a huge\nreturn on\ninvestment, unfortunately. Ransomware. Not everyone's been hit by ransomware, so they\ndon't\nnecessarily feel the bottom line effect. Right. Not to say that they won't be,\nbecause as we, you know,\nhave seen through history, it's not a matter of if. It's a matter of when.\nRight. But\nbut this is why I say this is kind of a\nbogus study. So, like, I'm like,\nit is a little disappointing to know that the that that, you know, overall, security\nspending\nhas only gone up 10%. You know, whereas we know that ransomware attacks has gone up\n30%, right?\nThe attacks and whatnot, but but I don't think that those two things are really\nrelatable. Not in\nthe way that they tried to make them. Right. Like, no. It's interesting. Like\nit's an interesting\nthing to see side by side for sure. And the way they're tracking the ransomware\nclaim information,\nthat's super interesting because not everybody is like, I was attacked and I\npaid a ransom. Most\npeople aren't. So yeah. No, I think that you both point out some really important\nflaws here in how\nthis is presented while also like highlighting what we can take away from\nit. And so to kind of\nround us out for today, Dave, I'm going to pose the final question to you here, which\nis we spent this\nsegment really talking about, you know, security spend and how, you know, how we\nspend things is\nmore important than sheer numbers. Any thoughts in terms of looking at this\nransomware landscape or\nseeing things, you know, claims increase. We're seeing the number of ransomware\ngroups increase\nas well. That was also in this report. Any thoughts on like where we should be\nputting our spend to\ndeal with ransomware threats or any other takeaways from this Dave? Threats are\ngetting. There\nare more of them, right? I don't know if counting it matters anymore, but there's\nmore of them than\nthey're right. It's never going to be in line anymore. So then you go like, all\nright. Well, where\ndo I go first? Well, you got to go to the things that the AI is kind of like, ready\nto do. and,\nand even if you're still using it in assistant mode, which we've kind of\ncrossed that as a\ngenerational thing. Like, we can get to some autonomous stuff, right? Like. Right.\nAnd some of the\nthings that we're doing with clients. Right. Autonomous threat investigations.\nRight. So no\none's staring at a console waiting for the thing to go. Right? We have AI. It's\ncalled ATOM. More, more,\nmore to find out later. But, like what ATOM does. And I don't mean to humanize\nthe AI, but. And it's\nA-T-O-M, so it does sound like a person's name. Well, you know what it does. It's\nit's tier one.\nTier two. Kind of getting ready for tier three in a classic SoC. Well, that's the\nbiggest spend\ninside of threat ops. It's like, we'd love to spend it on pen testing. We'd love to\nspend it on\nresponse and run books, but we don't. We have to watch all of these things and\ninvestigate all\nthese things. Okay, AI, I got you. Come here. Right. So, like, that's a place\nwhere I would. I would go, so I\nwould look. I would look at where AI is either doing it ideally, like in this case\nwith ATOM, but\nthen also like where can you augment in a really meaningful way. Be an assistant.\nRight. Risk\nscoring. I might not reduce my spend there, but my quality has gone through the\nroof because I'm not\nmaking changes in my my cloud environments or my identity policies without like,\nreally\nunderstanding what I've just done. Right. And so, I mean, to me it's it's don't\ndon't overcomplicate\nit. You do not need to go to pick a favorite planet, right. Like we're not\ndoing that. We just\nneed to get off the ground. Right. We can work on flying before we go to space.\nOkay. So, um. Terrible\nanalogy. Um. I'm trying. I'm just trying to top Claire's dress because that was\nreally good. That\nwas a good one. That was a good one. Yeah, because. Because I'm not gonna look good\nin any dress. It's\nnot going to matter. Um, so it totally resonated with me. Claire. Thank you. But\nbut hopefully at\nthat point is like, like, I think there's a tendency to say like, oh my gosh, AI can\nsolve all\nof our problems. Settle. Hold on. Yeah, perhaps. But let's pick some things that\nyou know and\nunderstand and that you can apply either in heavy assistant mode, but ideally more\nautonomously.\nRight. Let it do its thing. Um, and then then work on how do I control that thing,\nhow do I control\nthe outputs, change my business practices and processes to support that, and then I\ncan pick the\nnext thing, right. So to me and what I spend I spent all week with clients. Um,\nthanks. Frontier AI\nmodels. Um, you don't need to name them, right? But, but the advice in the\nconversations go with like,\nlet's start somewhere that we know and we're a little bit more comfortable,\nright? And then we\nwork on adjacencies. And I'll give you one quick example. Right. So we'll start with\nthreat. Right. If\nI can bring autonomy into my threat investigations, the next thing I might\nwant to do\nis say, you know, we've never really watched, nd this actually shows up in, I\nthink, two of the\narticles we talked about already, identity. We don't really monitor threats\nin identity. We kind\nof like misuse and some other sorts of things. Right. And we've always wanted to.\nRight. So ITDR is a\nthing and we've announced some services in and around that space. So that's a nice\nadjacency. And\nnow I'm bridging into my identity program. My identity program probably is if it's\nlike most\nthere's lots of duct tape, chewing gum, paper clips. Right. Lots of stuff. Right.\nEven in the\nnewly transformed there's. Because it's complicated. You talked about the\necosystem, third\nparty vendors, partners themselves, subsidiaries like it's. Identity systems\nare really complicated\nto get just right. Well, maybe we can have some AI help us there. I'm not saying give\nit full,\nbut maybe we can help. Right. And so that's just a path to autonomy. Right.\nContinuous\ncontrols, governance can sit on top of all of this stuff, right? Like, how ready am I\nto be audited? Man,\nthat's not the question. How secure are you right now? Right. That's what\ngovernance is supposed to\nbe. Right. So anyway, like, I can, like,\nI, I have to cut myself off here because.\nRight. Like, I'm, I love this stuff. So we should just give you like a whole episode\nwhere you just\nget to just riff. You know, I think we should. Unfortunately, that that does it\nfor this episode.\nIt's all the time we have for today. I want to thank our panelists, Kimmie and\nDave and Claire.\nThank you to the viewers and the listeners. Thank you to our producers.\nSubscribe to Security\nIntelligence wherever podcasts are found, so that you never miss an episode. Stay\nsafe out there. And\nin Dave's words, don't overcomplicate\nthings.",
  "transcript_chars": 39139,
  "ingested_at": "2026-05-21T19:10:42.992056+00:00",
  "source": "retry-no-transcript",
  "yt_meta": {
    "view_count": 2937,
    "like_count": 79,
    "channel_id": "UCKWaEZ-_VweaEx1j62do_vQ"
  }
}