The transition from manual Digital Risk Protection (DRP) to automated workflows is transforming how organizations handle online impersonation securely and efficiently. In this episode, Ashish sits down with Alex Dhillon, CEO of Outtake.ai, to discuss how the industry is solving the problem of high-volume digital spoofing. Alex explains how Gartner’s new DTAP (Digital Trust and Authenticity Platform) category merges impersonation prevention, narrative intelligence, and authenticity to create a more comprehensive defense strategy. He shares insights from his time as a Forward Deployed Engineer at Palantir and outlines how modern organizations use reconnaissance agents to accurately verify profiles, websites, and social media accounts without relying on manual labor. The conversation highlights practical solutions for making fraudulent campaigns too expensive for attackers to maintain, while ensuring legitimate content remains accessible and safe from accidental takedowns.
Questions asked:
00:00 Introduction to Digital Risk Protection (DRP)
01:50 Alex Dhillon’s Background as a Forward Deployed Engineer at Palantir
04:30 Evaluating Early Large Language Models for Security Solutions
07:00 The Shift from Legacy Manual DRP to Modern Automated DRP
13:30 Understanding Gartner's DTAP (Digital Trust and Authenticity Platform)
18:30 The Economics of Digital Trust: Making Falsehoods Expensive
20:30 Using Reconnaissance Agents to Verify Online Identities
23:30 Streamlining Takedown Workflows Within the Security Team
26:30 Why Defense Companies and Hedge Funds Adopt DRP
30:30 Measuring DRP Success: Recall, Precision, and Time-to-Takedown
35:30 Evaluating AI Platforms Through Graph Linkages and Transparent Classification
Alex Dhillon: [00:00:00] I can make a thousand fake websites, you know, in 10 minutes. Like, they're, they didn't even apply, right? They're just- Yeah ... pretending to work at your company Nation states love to impersonate defense companies because it's very strategic. Literally, like 50 to $100,000 being spent for like a, like a two-week emergency on a massive legal bill.
Ashish Rajan: Almost made the human problem into a software problem. Greater than
Alex Dhillon: 70 to 80% of the, the ways that people actually get inside most institutions is just tricking humans. I will make it very expensive for you. I will find everything you make, and I will keep taking it down. You might spin it back up, but every time you do, you will spend more money.
Alex Dhillon: There is no world, there's just no world where the manual approach succeeds anymore.
Ashish Rajan: If you have ever been impersonated on the internet, perhaps you're executive or you have been reached out by fake information on social media, a lot of this may or may not be familiar, but there's a field called DRP or digital risk protection, which is very common in defense organizations, regulated industries, and Fortune 500, Global 5000 companies, which are very much on the consumer side, but a lot [00:01:00] more.
Ashish Rajan: I had a great conversation with Alex Dillon. He is the CEO of Outtake.ai, and we spoke about DRP, DTAP, which the Gartner has recently announced as another variation or expansion of DRP, I should say. We also spoke about what's a good way to measure a DRP program, and what's the difference between a legacy and a modern DRP program.
Ashish Rajan: All that and a lot more in this particular episode of the podcast. As always, if you have been watching or listening an episode of the podcast or maybe sharing with your friends and colleagues as well, I would really appreciate if you take a quick second to hit the follow subscribe button, whichever podcast platform you li- you listen or watch us on.
Ashish Rajan: We are on YouTube, LinkedIn, Spotify, Apple, and anywhere else you consume your podcast from. I hope you enjoy this episode with Alex, and I'll talk to you soon. Peace. Hello, and welcome to another, another episode of the podcast. I've got Alex with me. Hey, man. Thanks for coming on the show.
Alex Dhillon: Hey. Thanks for having me.
Ashish Rajan: I'm looking forward to this conversation, but maybe to kick things off, if you could share a bit about yourself, your professional background for the audience to have some idea.
Alex Dhillon: Yeah. Yeah, yeah. So, man, [00:02:00] I-- before doing Outtake, I spent five years working at, at Palantir, which, I feel like has become a, a fairly well-known company.
Alex Dhillon: But it's fun to rewind the clock. Back when I joined in 2018 I feel like Palantir was fairly under the radar. And, and, and frankly, people kind of viewed it as this like secret shadowy company, like CIA backing or God knows what they were doing. Um, and even crazier, um, the role that I signed up for, and you're gonna laugh probably, but at the time no one knew what that role meant.
Alex Dhillon: It was called forward deployed engineer, right?
Ashish Rajan: Oh, really? Oh, wow, okay. Yeah, yeah. Wow. 2018.
Alex Dhillon: And, and Palantir famously invented the role. And, and the reason they invented the role is because Palantir, I think, was unique among Silicon Valley companies in that they were trying very hard to work with, uh, I would say traditional sectors.
Alex Dhillon: They were like, "Hey, we wanna, we wanna go bring the power of software to to banking, to shipping, to manufacturing." I mean, all these things now we take for granted in 2026, where all those industries are radically being digitally transformed first by cloud and now by [00:03:00] AI. But but again, like Palantir's early insight was like, that needs to happen.
Alex Dhillon: And the only way to do that is to actually take the best possible engineers you can find who understand software really well, but then embed them very, very deeply. And so, That-- I feel like that was, like, an incredible apprenticeship for me, frankly, where to, to learn uh, the depth of these various industries.
Alex Dhillon: I did that for about three years at Palantir, and then I rotated into the experimental product team. So this basically, uh, the best way to think, think about this is, is a team of about, you know, 10 to 15 engineers. They work in very small groups of three to four, and they really just, uh, wherever the C-suite kind of points them.
Alex Dhillon: So the CTO, the CEO would basically say, "Hey, like, we wanna take a big bet on manufacturing, for example. We're gonna get access to three of the largest manufacturing companies in the United States. Let's go figure out what their hardest problems are, what their repeatable solution might be, um, and let's build it."
Alex Dhillon: Um, and, and, and so that was the job of the, the experimental team. And that was, as you can imagine, incredible, like, frankly like a startup training ground in some ways, [00:04:00] right? Yeah. Yeah. Because you were constantly like, we're building from scratch. Uh, we're scoping everything from scratch. You're navigating these, like, large organizations, and you're constantly asking yourself the question of, like, "What is the hardest problem for this institution?
Alex Dhillon: How can I go solve it? I need to cut through politics, through distinct systems through sort of legacy ways of doing things. I need to do this in a way that is also exciting and useful to the organization. I don't need to be..." Like the wrong thing to do, for example, would be to come in and uh, be really arrogant and assume you actually know how it should work.
Alex Dhillon: Anyway, all of that ended up being incredible training experience. Most importantly, maybe was by virtue of being on this team, and this sort of touches on how I ended up deciding to build Outtake. By virtue of being on this team, you can imagine when large language models first emerged it was, uh, you know, w- again, rewinding the clock, now it's 2022, so, uh, ChatGPT has not been released.
Alex Dhillon: It's like early in 2022. Um, and but, but because of course, Palantir's a very forward-thinking company, uh, we start to hear about, we [00:05:00] start to hear about large language models. And so my team starts to say, "Hey, where can we plug this in? Like, where is this-- You know, we have this like magic genie in a bottle.
Alex Dhillon: Where can I use it?" And The, the, the models at the time, you, you probably remember, weren't like-- they were not brilliant, right? They were, th- like, you kind of had to trick them into being useful. That, like, prompt engineering was I-I, like, kind of a real skill 'cause you were like- Yeah ... how do I write a prompt to actually do-- get something nice out of this?
Alex Dhillon: And we very quickly realized that there were gonna be a few categories of obvious places that LLMs were gonna be useful. It was going to be amazing for customer support. It was gonna be great for content generation. And it was going to potentially, I, I, I think at the time, frankly, this is one of the ones where I was like, "Oh," like, that moved way faster than I expected.
Alex Dhillon: It was gonna be p- maybe useful for coding, though I remember we were kind of like, "Oh, it'll be useful for, like, boilerplate front-end code, but maybe, like, not great for anything else." And then the model capabilities, like, went super, super fast there. And then of course security. Just because security involves, like, sort of [00:06:00] large scale analysis sometimes of like, many different information types.
Alex Dhillon: Maybe for, for one aspect of security, the part that Outtake became obsessed with, or certainly I became obsessed with, was, you know, impersonation, scams, and fraud. It was, like, very clear that the content generation capabilities of AI were going to be weaponized. And so then-- a-a-and, and sometimes I feel like people over-index on, like, just deepfakes.
Alex Dhillon: Like, yes, deepfakes are cool and they're shiny, but like, l-let's be real, the average person is just, like, falling for a fake website or like, a fake social media profile. And really the AI accelerant isn't just like, you know, a Zoom deepfake, though that's interesting, but rather the fact that I can make 1,000 d- uh, fake websites, in 10 minutes, and then email them out- Right
Alex Dhillon: with really thoughtful go-to-market outbound, um, and then get people to click on them. Like, that's the really crazy part in my opinion. Um- Yeah, and
Ashish Rajan: do you find that-
Alex Dhillon: So anyway, I'll pause there.
Ashish Rajan: No, no, no. I, I think I, I think you touched on some-- I think you touched on something interesting there, 'cause DRP, obviously, as the category is called out by [00:07:00] a lot of people, I think it's a good way to kind of call that out, because today DRP doesn't mean the same as it traditionally meant.
Ashish Rajan: Kind of what you were doing before to what you said with the traditional Ford-deployed engineer walking into a manufacturing firm and saying- Right ... "Hey, 20 workflows. I think only two of them make sense to be modernized because they're repeatable patterns." What's the difference that you find in the, the pre-AI DRP and the post-AI DRP?
Ashish Rajan: The-- or so we're not really post yet. Okay, so let's just say in AI, I hope we are not post yet, but maybe after this recording. Yeah. Uh, what is the current version of DRP?
Alex Dhillon: Look, I think historical DRP, let me define that, 'cause I, I think it's so interesting as to like how it's, to your point, dramatically shifted.
Alex Dhillon: Like, what, what is this-- this category's existed. The problem has certainly existed. Fake websites have existed since probably the, the internet, right? So, like 2000- Yeah ... the early 2000s if, at a minimum, if not the mid-'90s. The problem is the, the volume and, and quality, right? Like that-- And that, by the way, that's like a common theme across cyber right now, right?
Alex Dhillon: It's [00:08:00] that historically you would have higher volume attacks and they'd be low quality, or you would have very, uh, low volume and very high quality. Like that was an intrinsic trade-off because it required human effort to create an attack. And the big unlock across all of cyber, not only our space, is that you can now conduct attacks of high volume and high What that means for DRP is maybe 10 years ago, you as a, as an institution dealt with, you know, maybe three to four fake websites, uh, a week, maybe the same amount, uh, across social media profiles.
Alex Dhillon: Um, and, and by the way, the number of digital surface areas you had might have been constrained to like roughly your website. Uh, and, and like maybe you didn't think of too far ahead on like what other surfaces you might have as a brand. And you come to 2026, one, you have more surfaces.
Alex Dhillon: All your employees are on social media, they are on LinkedIn, so now they can also be spoofed on LinkedIn. So all your employees now certainly have expanded your surface area. You as a brand [00:09:00] actually not only interface on your website, but you might have digital apps, so you're in the app store. You certainly have digital advertising, so now you're in the ad libraries.
Alex Dhillon: And perhaps you have agents, uh, that represent some of your work. Um, and so now-- So like the, the, your, your digital surface area is also meaningfully-- public surface area is meaningfully expanded. Okay. On top of that, all those surface areas can now be spoofed, right? And so in the past, you m- this was this really interesting problem that sat between cyber and legal.
Alex Dhillon: Mm-hmm ... you would-- Cyber was sometimes expected to detect, and then legal was expected to respond, right? So like that, that's how we think about with cyber workflows, right? It's detection and response. Um- Yeah. Um, and, and this problem was particularly strange because the response side was actually you trying to say, "Hey, other institution," Facebook, Cloudflare, somewhere external is hosting something malicious, and I want to influence them or c- ask them to, to, to take this down.
Alex Dhillon: And, you know, I, I... [00:10:00] Traditionally, the way you get someone, get a, , a third-party organization to listen i-if, if they're, if they aren't listening is, is the courts, it's the law, and that's why lawyers get involved. It's not like- Yeah ... a security question. And so anyway, all to say, historically DRP was like this relatively low volume thing, and then when it did come up in a serious way, it was very expensive because you were working across two different dreams, cyber and legal and it was a very manual workflow.
Alex Dhillon: Yeah. And so then what happened is the sort of companies emerged in the space about a decade ago and said, "Okay, maybe we can do a little bit better than, than what's going on. What if we just hire a bunch of people and we're just gonna have them manually search for all the sort of impersonations, and then we're gonna have them manually again report all the impersonations.
Alex Dhillon: And hopefully this, this like, uh, leads to hope-- like hopefully this leads to like better coverage or, and whatnot." And what ended up happening was W- In general, it didn't, right? Like, in general, what happened is it gave some level of peace of [00:11:00] mind, like I have a solution, but the solution was often ineffective.
Ashish Rajan: Yeah.
Alex Dhillon: Um, because if you're depending on manual search, we both know cyber is a super adversarial game, and so whatever, like, standardized keyword searches that the overseas contract labor you've trained to go search on soon as the bad actor realizes how to evade that it's very unlikely that your manual approach is gonna keep up.
Alex Dhillon: And then you fast-forward to today, which was your original question, like what is modern DRP then? Yeah. Modern DRP says, "Okay, because the volume quality, uh, quality of these attacks has gone up, there is no world, there's just no world where the manual approach succeeds anymore." And by the way, um, the fact that this exists across multiple teams in an org is unnecessary friction, and you're basically shooting yourselves in a foot, in the foot.
Alex Dhillon: This should be consolidated into one tool that owns the workflow from detection to response end to end, right? That is how all great cyber tooling works, and that should be true for DRP as well. And so, so, so that's, that's, [00:12:00] that's really how I think about modern DRP. It's like saying, "Okay, it cannot be manual.
Alex Dhillon: It must be agentic," um, because the, the bad actors are certainly, they are using agents to spin up hundreds of fake sites, fake socials, fake customer support, et cetera. And the only way you manage that scale is, is responding with a machine response. And then two the-- you need to own everything all the way to the end, including the takedown.
Alex Dhillon: And to do a great takedown, by the way you don't just send a takedown report. You need to actually say, "Hey, I found a p-particular let's say, website." You need to find the campaign behind it, right? So most attacks are part of broader infrastructure, so you, you... A good DRP tool is able to research that.
Ashish Rajan: No, I think you kind of said something really interesting. You almost made the human problem into a software problem in a way.
Alex Dhillon: Yeah, that's exactly right. Um- '
Ashish Rajan: Cause what you, what you, what you said, I think I remember this like, I think one of the incidents that I, I don't know about fortunate, but I definitely re-witnessed it where a person on LinkedIn was given a, a, on a link, um, fellow employee.
Ashish Rajan: They click on the link, something happens, and next thing [00:13:00] you know, it's like out there on the internet for, uh... Their information was out on the internet and go so on and so on. The, the DRP as a, as in digital risk protection, has also been pushed into the whole DTAP category. I don't know if you heard of that from Gartner.
Ashish Rajan: Yeah. Yeah. And I don't know if you agree with it or what's the stand with DTAP and... 'Cause it's obviously people are at the moment trying to figure out what does their security program need to look like in this AI world?
Ashish Rajan: Obviously people who have been doing DRP for a long time, they probably understand that, "Hey, we do need to have this reputation at stake, brand at stake." What is the difference? Because a lot of them may look at a Gartner and go, "I think I need a DTAP. I don't need a D-DRB." First of all, what is DTAP?
Ashish Rajan: Sounds like a reggae name, but hey, could be something else .
Alex Dhillon: It does, it... Yeah, it does sound like a great reggae performer. No, I, I think DTAP is actually-- it's really clever insight from Gartner, 'cause I think they've realized that there's... And there's actually like three three [00:14:00] historical legacy categories that are converging- Okay
Alex Dhillon: um, and being consolidated into DTAP. So DTAP stands for Digital Trust and Authenticity Platform. And the three categories that are converging, one is uh, it- it's like impersonation prevention, which is basically one-to-one with most of DRP. Yeah. Uh, because historically, DRP has roughly meant impersonation prevention for brands and executives.
Ashish Rajan: Yep.
Alex Dhillon: Okay, so that's category one. Category two is what they call narrative intelligence. And this is saying, hey, it's one thing to look out on the internet and understand what's fake. That's important. But actually the way that you understand what's fake and what you can trust, uh, you kind of need to actually cast a wider net and say, you know, let's say I'm protecting Acme Bank.
Alex Dhillon: I wanna know everything going on around Acme Bank. I wanna know when people are, are chattering about it in positive or negative ways. Certainly, if people are plotting against it, because that narrative intelligence is gonna help me proactively find [00:15:00] potentially the impersonations that are being built.
Alex Dhillon: And so narrative intelligence ends up being a really, uh, useful part of, of the broader platform. And then the final part is authenticity. And that's saying, "Hey, okay, it's great that you can find fake things and remove them. It's great that you can bring generic intelligence across all content related to this organization.
Alex Dhillon: Um, but maybe we should lean into, like, cryptographic w- ways to, to verify identities, uh, with external parties before we interact with them." And, and maybe the closest-- I think, by the-- I wanna be clear, I think that's the part that is, like, least figured out across the industry right now. Right. It's like what is authentic, um, and how do you verify authenticity in these third-party interactions i-i- is, is the least-- uh, is the part that's least figured out.
Alex Dhillon: One version of it, a small subset of this problem that I see discussed a lot in cyber though, is actually kind of the know your candidate problem, which you see with, like, uh, all the discussions around, like, DPRK and, like, fake [00:16:00] employees joining your company. Like- Mm-hmm ... from my perspective, as someone that just constantly thinks about digital trust, that's actually an authenticity problem, right?
Alex Dhillon: Like, how can I verify that this candidate I'm talking to is, like, who they claim to be, right? Um- Yeah.
Ashish Rajan: Yeah.
Alex Dhillon: And so, so all to say, I, I think these, like, three areas are going to be converging in pretty interesting ways, uh, because they, they touch on this, like, broader problem of, like, digital trust. Uh, which is, if you're-- which I realize is, a very broad term, but really it's just saying, "Hey, if I'm interacting with something on the internet, you know, it's a website, social media, ads, a, a person agent, a software package, this is something outside my organization, it's online.
Alex Dhillon: Should I trust it? Like, will it-- Is it trying to help me or hurt me?" Yeah. Um, that's the broader digital trust pro- uh, problem. And then, and then coming back to your, to, to your point on DTAP I think platforms that consolidate those three categories, you know, DRP, impersonation prevention, narrative intelligence, and authenticity into Gartner's view of [00:17:00] DTAP, I think that's, like, going to be the solution to this digital trust issue.
Ashish Rajan: I appreciate you sharing that also because I feel like the, the DTAP analogy, and I think I heard you use the word, how, how do you authenticate the identity in a way as well? That's, it's an interesting play there 'cause- Right ... um, you know, because you've made the human part, like I go back to the LinkedIn scenario before It, it required a human to judge on the fact that, hey, yes, this is Alex.
Ashish Rajan: Yes, this is Ashish. Right. This is not... Or no, this is not Ashish, this is not Alex.
Alex Dhillon: Right.
Ashish Rajan: How... I don't know how much of you can share it. I'm totally fine if you wanna, wanna skip this as well. I'm curious as to how does the cog wheel work, 'cause as a CISO, as a leader, I'm just curious as to what would this be different to what my other DRB people are saying.
Ashish Rajan: Because traditionally, at least the way I saw it, and I could be old school, I normally look at something on the internet and go, "Yep, that's not Ashish 'cause Ashish told me it's not Ashish." That and- Right ... it's like the Spider-Man moment of like pointing at each other kind of imagine that meme. Yeah. It's like [00:18:00] how does that work in a software context and, and how-- what are you guys doing that is making you guys, um, uh, be able to do this as a, at a software level?
Alex Dhillon: Yeah. '
Ashish Rajan: Cause I imagine the-- going back to what you said about the detection response, which I'd like to expand on, but maybe this is a good place to start expanding on that as well.
Alex Dhillon: Yeah. So coming from the perspective of like, uh, m-maybe to put it very simply, it's like How, how do we get software to get, get a version of the vibe or gut sense check that we, you and I as humans have when we're interacting with things?
Alex Dhillon: And, and, and then, and then how do we encode that into a machine and how does that scale? Is that, is that a fair way
Alex Dhillon: to put it? Yeah, yeah. That's
Ashish Rajan: pretty much it. Yeah, yeah.
Alex Dhillon: Yeah. You know, I've thought a lot about how to define trust. So maybe allow me to get slightly philosophical for just like 30 seconds. Sure. 'Cause trust is this, like, very ambiguous thing and like, you know, people could, I don't know, pontificate about it forever.
Alex Dhillon: And, and so I was like, how can I, like, how can I measure this? Like, what, what does it mean to trust something? And, and, and what does that mean for what Outtake builds? And so [00:19:00] trust if, if-- Let me take an economic perspective. Trust is, is, is two things. It's one, you wanna make falsehood very expensive to maintain, very difficult.
Alex Dhillon: Um, concrete example. If you impersonate an Outtake customer I will make it very expensive for you. I will find everything you make, and I will keep taking it down. You might spin it back up, but every time you do, you will spend more money, right? Yeah. And I will keep burning it down. And if you're economically rational, you will say, "I should go attack someone else because this guy is protected by Outtake."
Ashish Rajan: Yeah.
Alex Dhillon: Right? Okay. So I've made falsehood very expensive to maintain. The, the other half of it though, And by the way, Legacy DRP just thinks about this, right? Like, just kinda thinks about this falsehood side. Oh,
Ashish Rajan: interesting.
Alex Dhillon: Okay. Um, the other half of it that I think is, is equally important is how do you make truth easier to access, right?
Alex Dhillon: Maybe cheaper to access. For example, i-in, in, in your-- as you were talk- we were talking about the candidates, how do you make it really easy to know? Like, [00:20:00] it shouldn't actually take a ton of effort to just say, "Hey, that's actually Ashish." Yeah.
Ashish Rajan: Yeah.
Alex Dhillon: And then it's low friction to keep moving forward in a business transaction, social interaction, And I think that side of the equation, making truth easily accessible is, is relatively uh, there's, there's a lack of focus on it actually across the industry. Like, there there aren't a lot of great solutions is the short answer. Right. And I think what you asked is, well, how does Outtake think about it today?
Alex Dhillon: One of-- I think one of the most powerful things we've done 'cause there's, there there's a lot of ways to approach, you know, what is the trusted parts of the internet. But one of the most interestings, interesting things we did was we, we launched a product actually alongside Anthropic and this is public, y- you'll be able to find it if you Google.
Alex Dhillon: It was called the Reconnaissance Agent. It was one of the first long running models, uh, or sorry, long-running agents that we w- that Anthropic actually decided to, to shout out about. Because what it does is it says, "Hey, I-- given a specific part of the internet," uh, maybe it's Ashish's, uh, [00:21:00] LinkedIn social profile.
Alex Dhillon: It's going to say, "Okay, great. How do I assess whether this is a high trust profile?" We'll, we'll jump back to your intuition, which is, well, how would a human do it? A human would say, "Okay, roughly, like, does this profile have some history? Has it been around for a long time? Is it connected to people that I trust?
Alex Dhillon: Is the, like, last three months of content high quality?" If these things are roughly true, then my confidence that this is, like, truly Ashish is, like, way higher, right?
Ashish Rajan: Yep.
Alex Dhillon: Yep. Um, and conversely, if this was made yesterday and it's hosted in, I don't know, uh, a country that the US does not have friendly relations with and it seems to change languages every, like, two months 'cause it's, I don't know, targeting different pl- people to scam, confidence is on the extreme opposite.
Alex Dhillon: Now, of course, all the hard problems in the world aren't ever that extreme. They're always somewhere in the middle in a gray zone, so
Ashish Rajan: Yeah, yeah, yeah. That's a good point. Yeah.
Alex Dhillon: all to say, we encoded a lot of that intuition that you were talking about into a long-running agent which does the research to say, "Okay, what are the signals that I as a [00:22:00] human would use?
Alex Dhillon: And let me... You know, I'm infinitely patient in doing research, so I'm gonna grab all the research as fast as possible to pull it together and, and come to a decision." That, I think, is the state of the art today. Now, if you and I hallucinate into the future, I wanna be clear that Outtake is not touching anything like this today but I can imagine a world where, you know, the i-i- instead of depending on just research, uh, you move closer to things like cryptographic protocols where you say, "Okay, no, like, actually you have to, like, show me via token, like, y- you signed with your private key XYZ and now I trust that it's you."
Alex Dhillon: I- In like, I'm sure you and I, like on the nerdy side of the world are like, "Wow, that would be amazing." I think getting like, um, getting widespread adoption of like new protocols is obviously a very complex technical task. Right. So, so that's why it's, it's gonna be slow on that side.
Ashish Rajan: No, I mean, but that's a great answer also because I, I'm-- I imagine a lot of people who are making that decision with DRP today are-- they obviously struggle with the whole, whether it's a legal problem, a marketing problem, or whether [00:23:00] it's a technical cybersecurity problem.
Ashish Rajan: To what you said, there's, there is a split there. Yes. And one of the reasons for me to ask that question was that as well, where a lot of takedowns usually had to be that I find a contact in LinkedIn. I try and talk to marketing and go, "Hey, is there someone in marketing who has connections in LinkedIn so I can talk to them about bring this pa- bringing this down?"
Ashish Rajan: Um- Oh, yeah ... it's like it's-- a-and but that's was one of the reasons I asked is because a-- let's just say a security operations person comes across this from a threat intel feed or whatever what's n- what would normally happen and what happens in this particular scenario now that you guys have figured out a way to make this into a software?
Alex Dhillon: Yeah.
Ashish Rajan: I'm curious of how do, how do-- how does it work in an Outtake customer versus a non-Outtake customer, so at least, uh, we get both sides view?
Alex Dhillon: Yeah. I think I I think what's really f- uh, interesting about our space is it's so visible that, like, when it is a problem sometimes parts of the org that [00:24:00] you would rather not notice the problem are very aware.
Alex Dhillon: For example if a CEO is being impersonated, odds are it's the CEO coming to the security org being like, "Guys, what are we doing?" Right? Yeah. Which is never a comfortable, never a comfortable conversation. Which I can say as a CEO who sometimes has to be like, "Guys, what are we doing?"
Ashish Rajan: Yeah.
Alex Dhillon: And so what normally happens I think in a healthy DRP program and I would say with lots of bias, Outtake creates healthy DRP programs, of course.
Alex Dhillon: Uh, in a healthy DRP program, you, the security team, are always the first folks to hear about the problem. In an h- unhealthy program it is very reactive and you're kind of waiting for someone to tell you that there's a problem, and worst case, it's leadership. Leadership has noticed that, the-- like, they went to the App Store and they looked for their own app, and they saw that they were competing with four, four spoofs.
Alex Dhillon: Or they, they Googled some- they Googled thems- themselves, and the first SEO result [00:25:00] was a, a fake version of them. And you're right that irritation and wrath is probably gonna land on some combination of marketing and brand because they, you know, they're like, "Hey, what are you doing about how we look pr- publicly?"
Alex Dhillon: And then security because, "Hey, this is ultimately a DRP or brand protection problem, and shouldn't you, like, know how to fix this for us?" And so in those unhealthy situations, these things are, like, very spiky emergencies, um, and people are looking for relief as fast as possible. And, um, i- in a, in a strong organization, a technically strong organization that does move into the security team, and the security team is able to, like, reason through, "Okay, like, this is on Cloudflare."
Alex Dhillon: As you kind of said, "Do we have any connections at Cloudflare? Like, can we get this taken down?" I think the w- places where I see it go most wrong is in unhealthy DRP programs in non-technical organizations. Sometimes it never even crosses into security and it remains legal. And then what happens [00:26:00] is, your inside counsel is calling outside counsel to work on, like, copyright and trademark problems, and this is, like, slowly ballooning into, like, literally, like, you know, 50 to $100,000 being spent for, like, a, like, a two-week emergency on a massive legal bill when you could have actually implemented a program uh instead.
Alex Dhillon: And, and, and, and, and, and actually saved yourself the, the recurrence many times over. Yeah that, that's sort of what I've noticed so far at least. I,
Ashish Rajan: I think it's a good point also because it highlights the point that DRP is not for every organization, right?
Alex Dhillon: Right.
Ashish Rajan: Obviously we don't want like a-- Actually, uh, this is probably a question for you.
Ashish Rajan: What kind of organizations do you see working with Outtake, and what kind of organizations typically have a DRP problem? 'Cause a lot of people in the audience may have ne- not even heard about the term DRP 'cause-
Alex Dhillon: Right ...
Ashish Rajan: they heard about AI, cloud, SOC, all these other terms. But I feel like DRP is that interesting niche as [00:27:00] well, where y- only a certain scale of organization actually deals with that, that kind of problem.
Ashish Rajan: So I'm curious as to, just for the audience to get some context, what kind of organizations usually go for a DRP program?
Alex Dhillon: Yeah. Yeah, it's a great question, mostly because my original intuition as a founder was wrong. I thought in-- when I founded in 2023, that this was gonna be really about like the Fortune 500, and even within Fortune 500, this would really be about consumer companies.
Alex Dhillon: Because consumer companies are very consumer facing, have a very loud brand, it's gonna be like websites and socials for them. And like that has mostly been true, but we've had crazy traction in industries that I did not expect. Oh. ... like last quarter, we-- some of our strongest growth was across defense companies.
Alex Dhillon: Um, and it turns out that Nation-states love to impersonate defense companies because it's very strategic, right? Like if you wanna pretend to be a senior executive at a defense [00:28:00] tech company, um, y- you might do this because you're trying to pretend to be that person online and then talk to real employees and then extract information, right?
Alex Dhillon: That's a very strategic thing to do. Um- Yeah. ... i- it's basically espionage. And it turns out that, Yeah it, it turns out that's actually a very prevalent problem, right? Um, and so now you need to proactively find fake employees for-- that, that are trying-- not only trying to join your company, but just pretending to be them online, right?
Alex Dhillon: Like, they're-- they didn't even apply, right? They're just- Yeah ... pretending they work at your company on LinkedIn. Well, then now, now you need to go solve that problem. And so, so that's been super interesting. Uh, the-- another industry that I hadn't expected was financial services. Like, yes, financial services take cyber very seriously.
Alex Dhillon: Yeah. But you know, we work with a number of hedge funds at this point, and hedge funds are certainly not consumer facing or certain- or maybe if-- unless the consumer's a billionaire. Yeah, yeah,
Ashish Rajan: yeah.
Alex Dhillon: And, and so, but it turns out hedge funds are in a very regulated industry. And so when people [00:29:00] misrepresent them or seem to give financial advice, even if it's not them doing it, it leads to lawsuits against them, and that's a massive headache.
Alex Dhillon: Uh, so there's like a reputational and legal risk that they need to go solve. And so-- but the dis- the detection side of it is clearly a cyber problem. And so financial services ended up being a sort of a massive massive tailwind as well. And so I, I think coming back to your top level question, like what are the kinds of companies that that makes-- that need DRP programs?
Alex Dhillon: I think it's a combination of a few things. It's like if you tick any of these boxes, you should probably consider it. One is, yes, my first intuition, like consumer facing, almost definitely. But two, if you're in a regulated industry where your public statements are analyzed and then maybe used against you this of course includes-- this includes basically all of finance.
Alex Dhillon: Or if you're in an indus- industry that just gets disproportionate focus from attackers trying to get inside i.e. defense. Yeah. Um, that last part happens a lot [00:30:00] because you know, in cyber, we all know greater than 70% to 80% of the, the ways that people actually get inside, uh, most institutions is just tricking humans, right?
Alex Dhillon: And so, finding all the places that might trick humans, like your fake site, socials, whatever- Yeah ... is a, is a cost-effective way to solve the problem. So anyway, those are, those are sort of the big three that I come to.
Ashish Rajan: Those, those are good examples, but I'm also curious from a measuring success over DRP program as well.
Ashish Rajan: A lot of people have a program, perhaps they have a legacy DRP program and thinking of a modern DRP program.
Alex Dhillon: Yeah.
Ashish Rajan: What do you see as some of the measuring RO-- um, what measurements they can use or metrics they can use to-
Alex Dhillon: Yeah ...
Ashish Rajan: show the ROI or show the progress of maturity for DRP programs as well?
Alex Dhillon: Yeah. So I'll tell you what the s- like traditional metrics are and then maybe the ways that I think sometimes they fall short. Sure. Um, and maybe how modern programs should, should level up. So the obvious is... maybe even before [00:31:00] measurement, let me talk about like how someone approaches this, right?
Alex Dhillon: They're like, basically, I want to find all the things that mention me that are fake and then I want to take them down. Okay. Yeah. So the first problem is can I find the things, and the second problem is can I take them down?
Ashish Rajan: Mm-hmm.
Alex Dhillon: Um, and, um, you know, in, in, in machine learning the, the idea of can I find all the relevant things is you measure by recall.
Alex Dhillon: Um, whether you find the correct set of things is precision. Um, and then whether you take it down is a time measurement. It's like time to take down. Nice. Um, and so a, a legacy program that has taken their work seriously would be trying to measure these three things. Okay. But no measurement's perfect, and it turns out there's like issues with, with each one.
Alex Dhillon: So for example, recall when you're trying to do recall on the internet, right? It's really hard to know what you don't know, right? Like by definition, if I never found the thing, I will never know that I never found it. And so I don't-- like there-- it's actually very-- [00:32:00] it's almost intellectually impossible to measure true recall when you're doing it against the whole internet.
Alex Dhillon: And so inevitably what happens for, for most programs is they like make, take an attempt but it's a very flawed statistic. Okay. Then the next part is precision, which is okay, of all the things I found how many of these should definitely be flagged and escalated and, and, responded to?
Alex Dhillon: And by the way, this is exactly where a lot of legacy DRP programs get into a lot of hot water because they, they-- like anytime you make a mistake at this stage, you're effectively taking down something real, right? Yeah. Like your false positives are actually really painful. Um, they're potentially a PR crisis because you took down a fan account.
Alex Dhillon: It's potentially a legal issue because someone's very upset. Um, and so the, the accuracy of what you do here really, really matters. And in fact, one, one of the ways that we've, you know, as a company beat out competitors frequently, even modern competitors in the last [00:33:00] two, two, three quarters, is precisely this.
Alex Dhillon: It's like Outtakes sort of radical adherence to, uh, being very transparent about how our agents reason about the classifications, right? So we stay far away from, you know, black box classifiers. Uh, and we say, "Here's like-- here's the specific signals we looked at. Here's how we weighted them. Um, by the way, we weighted them in this way because of prior things your, your team chose to escalate.
Alex Dhillon: So this is similar to things you've chosen to escalate before. And that's why we came to this conclusion, and that's why it's being taken down." Like that, just the simple like act of being transparent about how you come to s- a classification, I think has won us a lot of customer love, and I think, I think that's important.
Alex Dhillon: Um Um, and then, and then, and then finally time to take down is the, like, final metric that, that people really focus on. Uh, and this one, ah, it's like, it's really important, but then it gets gamed, right? Like, I see it gamed so much that it really frustrates me, 'cause I, as a founder, especially as an engineer, like, I try to be-- I, [00:34:00] I skew towards being, like, radically honest, where I'm like, "Here's what's working, here's what's not working."
Alex Dhillon: Generally because I think my best customers and design partnerships have emerged from being really open about that, 'cause then your product gets way better. Yeah. But I think in the industry, of course, there's a lot of, like, go-to-market pressure, and there's lots of people who will, like, sort of hand wave and summarize away things.
Alex Dhillon: And so I'll give you a concrete example. What I see happen all the time, where people will say, "Oh, my time to take down is, like, some abs-absurdly small number," like, you know, six hours or something. And what that's obscuring is where, right? Like, okay, my time to take down for, let's say exam- for example on, on the Meta platform where we have very deep integrations might be six hours.
Alex Dhillon: My time to take down a Russian website is certainly not six hours, right? Yeah. Um, and, and if anything, maybe one guidance to CISOs, I, I think this is always a great sort of, like, question is is just ask-- In our space, you should a- maybe point blank [00:35:00] ask, like, time to take down across a few different platforms.
Alex Dhillon: And, like, anyone that's honest will tell you, like, "Hey, a website hosted on adversarial infrastructure, it looks more like this versus, like, platforms that are based in the US looks like that." Like a great sniff test is just asking about Telegram. There'll be plenty of people who will, you know, blindly be like, "Yes, I can get anything taken down on Telegram."
Alex Dhillon: And, like, to me, that's, like, a massive red flag. That person is just lying to your face. Um, and so anyway time to take down you need to be very specific in, in, in where you're measuring it as, as a- Sure ... roadmap. Last thing I, I realized... Sorry, I can talk about metrics forever.
Ashish Rajan: No, no, that's fine.
Alex Dhillon: Last sort of comment on on, on, on metrics. Everything I described is, like, what anyone should've been doing for DRP already. I think what changes in a big way for modern DRP programs is, um, this is kind of nuanced. For every alert your vendor finds, you should kind of see if they can tell you how many links that alert has.
Alex Dhillon: So, like, [00:36:00] um, a given website, how many things is it connected to? Like, is this website connected to, again, social media ads WhatsApp group, whatever. The more links, legitimate links of course, that they find the, the more... This is a very straightforward way to measure how intelligent the platform is, right?
Alex Dhillon: Like is it able to jump between impersonations and between platforms and create the linkages and really map out the graph? And, and the reality is doing that with just humans is basically impossible. So the fact that they are able to do that is evidence, it's proof of work that this is actually some level of good AI has been implemented here.
Alex Dhillon: And so that, you know, we do that very i-in a lot of depth. We show like the graph. We show like, "Hey, here's the thing, but here's all the other things it's connected to." And we do this of course, mostly because we, we-- it makes us better at our job. But I, I think it's actually a very nuanced thing that one can measure in our, in our space to say, "Okay, like this is actually a real tool."
Ashish Rajan: Awesome. I mean, [00:37:00] that was a great answer as well. Um, but that's what we had most the time for, man. But where can people find you and connect with you to know more about the DRP programs that they might be running or trying to uplift them and, uh, more about Outtake as well?
Alex Dhillon: Yeah. I, um, like many cyber founders, am painfully loud on LinkedIn, so-
Alex Dhillon: probably the best place to find me. In fact, I've had CISOs just DM me during an emergency, and, and we'll, we'll hop in there and, and, like, no questions asked. What-- 'cause look, I think one of my favorite things about cyber is it's, it's very community driven. Like- Yeah ... these-- we're all on the same side.
Alex Dhillon: We're fighting roughly all the same bad actors. One of my favorite stories is, like, OpenAI, which is our customer, referred us to Anthropic, which is our customer, because they were dealing with the same problem, right? And those two companies are clearly competitors across 99% of their functions, but in security they're partners.
Ashish Rajan: Fab.
Alex Dhillon: And, and I think it's so amazing that, uh, that, uh, myself and Outtake get to be part of that. And, and yeah, where, where I find myself engaging with that community is, is, is mostly [00:38:00] LinkedIn. Um, of course, if you wanna just, uh, book a demo generally, Outtake.ai, uh, we have a book a demo button as well.
Ashish Rajan: Awesome. I'll, uh, put a link to your, um, LinkedIn as well onto the, the true link for your LinkedIn considering we-- this is the DRP episode. Yeah. I'll make sure the, the... I'll check the link before, uh, it go-goes out by the team as well. Uh, but dude, thanks so much for coming on the show and sharing everything that you guys are working on.
Ashish Rajan: As far as, like, to your point about the metrics and everything else, I feel there's a lot more to unravel there. Yeah. Uh, but I look forward to having a follow-up conversation with you as well. But thanks so much for your time, man.
Alex Dhillon: Yeah, I would love to. Th-thank you so much, Ashish. Thanks for taking the time.
Ashish Rajan: Thanks everyone tuning in as well. Thank you for listening or watching this episode of "Cloud Security Podcast." This was brought to you by techriot.io. If you are enjoying episodes on cloud security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple, Spotify.
Ashish Rajan: In case you are interested in learning about AI security as well, do check out our sister podcast called "AI Security Podcast," which [00:39:00] is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security. Finally, if you are after newsletter, it just gives you top news and insight from all the experts we talk to at "Cloud Security Podcast."
Ashish Rajan: You can check that out on cloudsecuritynewsletter.com. I'll see you next episode.
Peace.

.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)


.png)


.png)



