Endpoint Security is the Future of AI Prevention

View Show Notes and Transcript

Are you over-indexing on prompt injection while ignoring the unregulated AI packages installing themselves on your endpoints? In this episode, Ashish sits down with Emily Heath, COO of Glow and former CISO at United Airlines to discuss why the endpoint is experiencing a massive resurgence. While traditional EDR solutions were built over 15 years ago for detection and response, modern AI context finally makes true prevention possible. Emily explains why relying on a single "unicorn" AI security product is a myth and how CISOs must segment their strategy across Code, SaaS, and the Endpoint to be effective.

Questions asked:
‍00:00 Introduction: The Endpoint's Moment
‍02:00 Emily Heath's Background: From CISO to VC to Glow COO
‍03:00 Why Prompt Injection is Just a DLP Problem
‍04:30 The Hidden Danger of Unregulated AI Plugins
‍06:30 Why EDRs Are Blind to Modern AI Configurations
‍08:00 Moving from Detection & Response to True Prevention
‍11:00 Discovering 60,000 Unique Pieces of Software
‍14:30 Shrinking the Attack Surface Against Frontier Models
‍20:30 Solving the CMDB and Device Reconciliation Nightmare
‍25:00 The Importance of 100% Explainable AI Decisions
‍35:30 The 3 Layers of AI Security: Code, SaaS, and Endpoint
‍39:00 Agentless Security vs. Lightweight Collectors
‍42:30 The Evolving Role of the CISO and IT Collaboration
‍53:30 The "You Laugh, You Lose" Cybersecurity Joke Challenge

Emily Heath: [00:00:00] They found over 60,000 unique pieces of software. You put these frontier models to work on all of those vulnerabilities. You don't stand a chance.

Ashish Rajan: I already have an EDR. Yeah. I already have DLP. Okay. I've already spent my money on browser security- Yeah ... 'cause that was supposed to be the one kill chain for all of this.

Emily Heath: Your EDR cannot see whether it's configured properly. They can't see the packages that have been installed. They can't see the plugins. The time to vulnerability exposure, it used to be weeks. We're talking hours, minutes- Yeah, yeah ... now. For the first time, we live in this world where we've got this incredible technology, and we can actually really think about solving a prevention problem.

Emily Heath: We've never been able to do that before. You're never gonna get to zero. You're never gonna get to zero. It's just impossible. This is the moment for the endpoint.

Ashish Rajan: Yeah.

Emily Heath: It is the endpoint's moment. It's not been its moment for 15 years or more.

Ashish Rajan: Yeah,

Emily Heath: yeah, yeah. Now is the time to do it.

Ashish Rajan: If you're looking at AI security as a space and an ecosystem today and want a approach which gives you visibility across all facets of it, or whether it's to understand as an operator, how do I start approaching this?

Ashish Rajan: What does that mean for my team? [00:01:00] What should be my first priority be? Then this conversation with Emily Heath is the right one to start with. She has been an operator and a CISO for years with experience as a CISO in United Airlines and many other companies, then a VC. Now she works for a company called Glow In this conversation, we spoke about what, as a CISO, you should be thinking about as the right approach to bring this forward as a ecosystem. For things that used to take four FTEs in your organization to get information, how can you better utilize AI for capabilities and get an understanding of how do you manage that effectively so you can enable the business to be more productive?

Ashish Rajan: What is the right way when Bob from accounting or Susie from legal starts doing vibe coding? What does that mean for your organization, and how should you approach it? What should be the first 30, 60, 90 days as a CISO in an organization where you're trying to build a AI security program? All that and a lot more in this episode of the podcast.

Ashish Rajan: If you have been listening or watching an episode of the podcast for some time and are here for a second or third time, I would really appreciate if you could hit the follow or subscribe button, whichever podcast platform you listen or watch us on. [00:02:00] We are on YouTube, LinkedIn, Apple, Spotify, and wherever you consume your podcast from.

Ashish Rajan: I hope you enjoy this episode. I'll talk to you soon. Hello, welcome to the show. Today I have Emily. Thanks for coming on the show.

Emily Heath: Such a pleasure. Thanks for having me.

Ashish Rajan: Uh, maybe just to set the scene, could you share a bit about yourself, your professional background as well?

Emily Heath: Yeah. So I used to be a CISO.

Emily Heath: I'm a recovering CISO. Uh, I was a CISO at United Airlines, DocuSign, a couple of other places. Left my operating life about four or five years ago with the full intention of disappearing into board life, but apparently me and retirement are not really made for each other. So I ended up going to venture capital for a few years, and then most recently left venture capital, the easy-peasy life- Oh

Emily Heath: to join a startup called Glow, and I'm the chief operating officer.

Ashish Rajan: Awesome. And, uh, actually, 'cause now you guys ha- you've seen both sides of it. You've seen the operator side, you've also seen the venture side, and now you're on the product side.

Emily Heath: Yeah.

Ashish Rajan: I'm curious as to, in the AI security ecosystem, what are you finding people are, especially CISOs, over-indexing on, and probably underx- [00:03:00] under-indexing on some?

Emily Heath: Yeah. With AI especially- Yeah ... I mean, we're all learning this, right? Mm. I mean, like, this is such a new world. Yeah. But there's a couple of things that I think, for me, I, I can't help but put my practitioner hat on. So I think of things like, you think about the prompt. Everybody's worried about what people are putting into the prompts.

Emily Heath: Yeah. I think there's a little over-indexing on the prompt. That's like a DLP problem to me. It's something that's not necessarily new, it's just a new application of how you're doing that. I feel like the dangers are much more around all of the AI tools that people are using. Like, I mean, if you ask Claude to do something for you, it's got one job- Mm

Emily Heath: to give you what you asked for.

Ashish Rajan: Yeah.

Emily Heath: And do anything for it. What it's, what it's actually doing in the background is w- for me, way, way more important and way more risky- Yeah ... than, you know, the, the thought of somebody perhaps putting something that they shouldn't do in a prompt. So, eh, it's not that it's not important.

Emily Heath: Yeah. It's all important. But I don't know, just my personal opinion.

Ashish Rajan: Do you find that the... It's an interesting one, right? Because to [00:04:00] what you said, the entire industry started the conversation about AI security with prompt injection as that- Yeah ... thing that can be unsolved, because we still haven't solved it fully.

Ashish Rajan: Yeah. And it's been, like, a few years of doing this. Uh, what, what's the right place to start the AI security conversation then?

Emily Heath: Yeah. So obviously I'm a little biased, but I think it's the endpoint, and there's a reason why I really feel strongly about it, and that's because you look at these AI apps that people are using, whether it be Claude or whether it's Cursor or ChatGPT or whatever it is.

Emily Heath: We've spent years trying to get everything off the endpoint- ... and now all of a sudden everything's coming back to the endpoint. So, when you... Again, I'll use the same example. When you ask Claude to do something for you, it's got one job, and that's to deliver it. Yeah. But what's happening in the background is it's deploying all kinds of packages and plugins that- Mm.

Emily Heath: Claude doesn't care if it's malicious. Yeah. It goes to the internet and grabs whatever seems like the most, uh, suitable and economic tool to give you what you asked for. Yeah. But it's... And it's unregulated. This is a completely unregulated environment. Mm. [00:05:00] So it's been installed on the endpoints without anybody even seeing it.

Emily Heath: So- Yeah ... the prompt is something you can see, and, you know, it's like a s- it's a SaaS problem. But when you think about these packages that are being im- and plugins and these kinds of things that are being installed on your machine, you, you just can't even see them. It's absolutely astounding that this can happen.

Emily Heath: Astounding.

Ashish Rajan: It's, it's an interesting proposition, right? 'Cause to your point, the, A, the, I think the change is way more dramatic than people thought initially- Yeah ... and a lot of people went down the path of, uh, j- and to your point, I understand the endpoint analogy, but I also think from practitioners who are watching and listening to this, they might think of this from a perspective, "I already have an EDR."

Emily Heath: Yeah. "

Ashish Rajan: I already have DLP." Yeah. "I've already spent my money on browser security-" Yeah ... 'cause that was supposed to be the one kill chain for all of this.

Emily Heath: That's right. And-

Ashish Rajan: So

Emily Heath: they're spending a lot of money- Yeah, yeah. ... on all of that stuff.

Ashish Rajan: So, yeah, like I think now you're almost at this, in a bit of a pickle, at least the, some, some of them are 'cause you almost feel like [00:06:00] why the confidence with endpoint in terms of is it- The fact that the browser is no longer a relevant use case, or is that because it's not the full picture?

Ashish Rajan: What's making you... 'Cause obviously to what you said- Yeah ... you've seen different, different roles. Yeah. You made an active call to come into this, especially in the endpoint security space. That's right. So clearly you did your research. Yeah. I'm just curious to double down on, on that research from, um, why not the browser security- Yeah

Ashish Rajan: or any of the other angles- Yeah ... where do you see it as long term?

Emily Heath: And it's not that browser's not important, it's just that literally, like I said, we've spent all these years trying to get everything into the cloud.

Ashish Rajan: Yeah.

Emily Heath: And now everything is coming back to the place where people actually do their work.

Emily Heath: Yeah. So it, what's being installed, you install Claude Code on your endpoint. It's not necessarily being run from a browser anymore. It won't operate in the same way if you run it from a browser.

Ashish Rajan: Yeah.

Emily Heath: So it's actually being installed on your endpoint in a different way. And I think from an EDR perspective, EDR was, designed 15 or more years ago, and at the time, that was where the attacks were coming [00:07:00] from.

Emily Heath: EDR is built to do something very different. Uh, it's still needed, but it's very much detection and response focused. It's not prevention focused. And I think now for the first time we live in this world where we've got this incredible technology And we can actually really think about solving a prevention problem.

Emily Heath: We've never been able to do that before.

Ashish Rajan: 'Cause I'm curious. Prevention is something every time I've mentioned this word, at least pre-AI, people just roll eyes- Yeah ... and like, "Oh, that's never gonna happen." And this is the reason why for, I feel for decades we over-indexed on detection, the SOC team, the SIEM, and everything else we built around- Mm-hmm

Ashish Rajan: this ecosystem to detect something from going wrong because I- That's right ... we, we kind of, we wanna be the response people rather than- That's right ... the prevention people. What's changed with AI that- Yeah ... we're feeling confident with, with prevention? I'm curious.

Emily Heath: So if you think about it, the old way was, "Oh my God, it's either allow or deny."

Ashish Rajan: Yes.

Emily Heath: There were the two options- ... and that's like a lose-lose situation. If- With

Ashish Rajan: regex on top, I guess.

Emily Heath: Yeah. If you allow- Mm-hmm ... everything, then you got a chaos.

Ashish Rajan: Yeah.

Emily Heath: If you deny everything, you got very [00:08:00] unhappy employees who can't innovate and do the, the work that they need to do. Yeah. And so it was difficult.

Emily Heath: It's hard, and it's hard for a reason because just having that kind of binary decision of allow or deny, it's not practical. It's not how people actually do their work. Mm-hmm. So now you think about it in terms of, okay, well, we can now correlate together devices, people, every piece of software that they're using.

Emily Heath: We now can apply AI to that and give incredible context that we've never been able to do before. The backend of our system, we've got over 100 agents doing work for you- Mm ... that's doing all the investigation and doing all of this context gathering and deep research and analysis. Humans couldn't do that before, so how were they going to make a decision whether to allow or deny something?

Emily Heath: Which is why that was normally just global policies with a nightmare of exceptions. Mm. But now it can be done in real time. So now you actually have much more capability, and let's say, okay, Ashish wants to use this particular product. Well, let's just Slack him and ask him why he needs to use it. And AI [00:09:00] can help you do that so that you're not just a brick wall.

Emily Heath: And it's just the level of context that you can get now from a real runtime situation is very different than it used to be. So I'm really hopeful that prevention will be the new model, and the reason I say that is because, detection response, it's the afterthought. We've all... I've lived it so many times through the years.

Emily Heath: I kn- I know how hard it is to try and keep up. But the tools that we've got now should hopefully help us think a little bit differently.

Ashish Rajan: This is, to your point, the reason why a lot of CISOs hate the 5:00 PM Friday deployments. 'Cause-

Emily Heath: It's just like, "Thanks very much. There's my weekend."

Ashish Rajan: Yeah, that's right.

Ashish Rajan: Literally. And I still remember, I, I mean, it, I'm sure it's happened to everyone. You get a call on Saturday morning for whatever. You're, you're in the middle of an activity which you had planned weeks ago. That's right. But it's like then you get a call like, "Oh, by the way, need to come back to the office."

Ashish Rajan: Yeah. Uh, no it's... i'm glad you mentioned this because I almost feel, Just from the prevention piece, 'cause to, to your point, we have a lot more data points. So is the focus with endpoint security now and with the prevention mindset is more on the [00:10:00] behavior? 'Cause a lot of people at least in my mind, the reason we did that is because we thought, "Oh, I can't make Ashish stop from opening, I don't know, Meta AI or whatever," right?

Ashish Rajan: Which is not an approved AI. So which is an, quote-unquote, "intent"-

Emily Heath: Yeah ...

Ashish Rajan: that, hey, I should not do it, bad Ashish- Yeah ... but somehow I can do it because my EDR thinks it's a, oh, just a browser open application. That's

Emily Heath: right. Yeah.

Ashish Rajan: I wanna I'm gonna wait till something wrong happens before I do anything.

Emily Heath: Yeah.

Emily Heath: Just, it's not just behavior anymore. Right. Okay. So I think behavior is more about the context. Mm-hmm. So for years we've tried to do kinda insider threat, behavioral monitoring. It's never really worked. Mm. And it's, you know, we, we've done as much as we possibly could without kind of being Big Brother and without kind of stopping people from doing the things they need to do.

Ashish Rajan: Yeah.

Emily Heath: Really, if you think about kind of the foundations of any security program, you've got people, devices, and every single piece of software they're using. Okay, so now if we understand what that is, I'll give you an example. We're working with one customer who plugged in Glow, and [00:11:00] they found over 60,000 unique pieces-

Emily Heath: of software. 60,000. 60-- Over 60,000. Now, some of that was AI packages, AI tools, all of these IDE plugins and browser extension and all those things. A lot of it was the old stuff that they're using. So you can't separate the, this, this new world of AI from the old world that we've been trying to protect for all these years.

Emily Heath: You can't really separate those things. Mm. You have to think of it holistically because that's how people work. People are not now all of a sudden abandoning the old stuff- ... and using to, using just the new stuff. We've got two completely different attack surfaces.

Ashish Rajan: Yeah.

Emily Heath: One which we understand fairly well because we've spent decades trying to understand it, and one that's completely brand new that we're real- really still trying to wrap our heads around a little bit.

Emily Heath: So okay, you got 60,000 pieces of software. What the heck are you gonna do with those? There's no w- there's no way an army of analysts can try and figure out what all that stuff is. So when you think about how to do that from a prevention perspective-

...

Emily Heath: Let's take that, you take that 60,000 pieces of software, now [00:12:00] put Mythos on top of that.

Emily Heath: You think about how much the exposure is. The prevention mindset is, let's control that attack surface down. So let's maybe get that to the 5,000 approved pieces of software, or the 2,000 or the 10,000 or whatever it is. Don't let that run in the environment in the first place so that technically speaking, your detection response should go down-

Ashish Rajan: Yeah

Emily Heath: because the noise that the, the SOC teams are dealing with shouldn't actually be as high if you can really control it from a prevention perspective. So it's the same with AI as it is with every other tool, every installed app, every browser extension, every IDE plugin you know, you get the idea. Every SaaS.

Emily Heath: Mm. If you understand it all and you understand who's using it, and then you do the research on it, it gives you much more visibility to be able to control it-

Ashish Rajan: Yeah ...

Emily Heath: and have AI kinda help you do that.

Ashish Rajan: I think, um, I, I'm wanna double click on that reduce attack s- surface because- A lot of the industry at the moment, especially with Mythos being in the picture, uh, at least in Europe, people seem to have gone down the path of [00:13:00] enterprise, what's it called?

Ashish Rajan: Uh, Mythos readiness assessment. Mm-hmm. Is that, is that actual thing people are signing up for? It's crazy, isn't it? That we're

Emily Heath: talking about this.

Ashish Rajan: Yeah. That's crazy. And you're like, what... Uh, you almost think like, "Wait, what are you scanning for?" The unan- Yeah ... un- so it's almost like I want you to scan for zero days in my machine.

Ashish Rajan: If we could find zero days, I don't know why would you scan for it, but hey. Yeah. I mean, keeping that, taking that conversation aside, do you find that with the introduction of Mythos and frontier models now giving cybersecurity capabilities Are you seeing enterprise behavior change in terms of... 'Cause th- and I'll probably certify about why I'm going down this path, is because one of the reasons why prevention never worked was also because culturally we go- Yeah

Ashish Rajan: "Oh, we should do security awareness training. We should te- teach Ashish what's the right way to use them." That's right. "If he or she completes the training, at least we can just tell that to the board or whoever that, 'Hey, by the way, the entire organization has done security awareness training, so we are confident, fairly confident they should at least be aware when they do something wrong.'"

Emily Heath: Yeah.

Ashish Rajan: And [00:14:00] does that not exist ch- as a challenge in this ecosystem that you're moving towards, and does that not become the Big Brother thing that we were talking about earlier?

Emily Heath: Yeah, I mean, of course it exists, and you still have to do training and all of those things, but it's just not realistic in my opinion.

Emily Heath: Mm. And I, I've... This is nothing new from my kind of frame of reference for security. I've always wanted employees to do their job.

Ashish Rajan: Yeah.

Emily Heath: It's not their job to think about security. It's my job to think about security. Yeah. And yes, you have to make people aware, of course, but at the end of the day, these people are busy.

Emily Heath: Product people have a product to ship, finance people have finance to do, and legal people have legal stuff to do. They've got their expertise. Yeah. And so we don't wanna get in the way of that. But I think what we've come to now with things like Mythos is, and again, it's the exposure not just of the new stuff.

Emily Heath: You have people installing all these new agents and, and MCP servers and all of those things, but you... I'll use the example again of the 60,000 pieces of software. Many of those, of course, will have vulnerabilities, and you put these frontier models to work- ... on all of those vulnerabilities. You don't stand a chance-

Ashish Rajan: Yeah

Emily Heath: if you [00:15:00] don't reduce that attack surface. So again, it's the prevention and reduction of the attack surface is what, in my opinion, is gonna help save you because you don't want hundreds of thousands of vulnerabilities that frontier models can go after. You're never gonna get to zero. You're never gonna get to zero.

Emily Heath: It's just impossible- Mm ... to have no vulnerabilities in your organization. But at least if you understand by reducing the attack surface and then knowing what the residual is, companies have to operate with risk. Having zero risk is not realistic. But you just have to have your eyes wide open and know that you're accepting that risk and, that you're fully aware of it.

Ashish Rajan: Do, do you find... And, uh, I'm glad, so glad you mentioned this as well, 'cause I, every time you mention the fact that, oh, zero risk is not a possibility, but somehow people have that as their, uh, rainbow- Yeah ... for lack of a better word, that's what you wanna get.

Emily Heath: It's always the, the gold standard, right?

Ashish Rajan: Yeah,

Emily Heath: yeah, yeah. That's what... That's the nirvana that we all want. That's

Ashish Rajan: right. Wi- without the budget as well.

Emily Heath: Yeah, of course. That little thing.

Ashish Rajan: Yeah, yeah. It's like you don't have the budget, but you, we, we want zero exposure. [00:16:00] To, uh, to kinda double down on this a bit more, 'cause a lot of people obviously have your, um, and 'cause endpoint security specifically got ignored for a while- Yeah

Ashish Rajan: where, A, because it was never part of the core. Let's just say enter- enterprise security is what usually p- people look at that. Yeah. Like, that's, they're the ones who are deploying it, managing it, all that. And- Now somehow because all these endpoints are important because of the AI agent and- Mm-hmm ... I think I'll just use the example of Bob from finance also happens to have-

Emily Heath: That's right

Ashish Rajan: an AI agent, uh, whether it's in his, his, in his SaaS application or he just saw a tutorial online for it. This is how you process hundreds of Excel files in one go. Mm-hmm. Just copy paste this partial script and it'll all work. It's the thinking of how endpoint has usually behaved in an organization has, in my mind, evolved.

Emily Heath: Yeah.

Ashish Rajan: Are you seeing the same kind of response in your, uh, in the set of customers you talk to? What are some of the level of maturity you're finding in terms of the ones who are Probably closer to understanding this bit more- Yeah ... and what do they [00:17:00] prioritize versus the ones who are not started and what should they prioritize?

Ashish Rajan: Yeah.

Emily Heath: It's across the board.

Ashish Rajan: Yeah.

Emily Heath: And, you know, they... and it doesn't really matter by industry. You know, some healthcare companies are actually very advanced- Mm-hmm ... and some tech companies are very not advanced. Mm. You know, it really depends on the, the organization. What is a common theme with everybody is everybody's fully leaning into AI.

Emily Heath: And so that's a given. Yeah,

Ashish Rajan: yeah.

Emily Heath: The fact that Bob from finances, you know, using AI to fast-track his Excel spreadsheets, we want Bob to do that. Yeah. Everybody does. Every organization does. And no- not... it's a common theme. I haven't met anybody who is saying, "We are not allowing AI."

Emily Heath: Yeah, yeah. Nobody. There's lots of CISOs who have, you know, AI governance programs and a lot of that historically up until this point, which is, legacy is only what, two years or- Yeah ... something like that. It's been a committee, and the committee, you know, reviews what AI is being used in the organization.

Emily Heath: Yeah. But the problem is they don't s- they don't know. What, what is probably the most staggering thing we see is just [00:18:00] kind of the jaw-dropping of how much is actually being run, and this is, again, it's because of Bob in finance connecting to MCP servers when it's asking Claude to do something, and it's connecting through MCP servers.

Emily Heath: It's Jimmy from sales is asking, "Look at this spreadsheet, connect it with Gong, connect it with Salesforce- Yeah ... and, you know, give me a report every day." Yeah. And Susie's doing the same thing in legal. You don't wanna stop that- Yeah ... but the amount of software that is being installed on endpoints when that happens is, I think, the jaw-dropping moment.

Emily Heath: Yeah. There's the... It's just... it's not well understood yet. And so most people think of the AI tools themselves, but they're not necessarily thinking about are those tools configured properly because your EDR's not gonna tell you that. Your EDR cannot see whether it's configured properly. They can't see the packages that have been installed.

Emily Heath: They can't see the plugins. They can see that Claude exists, but they can't see anything beyond that, and this is where the big gap is. So you still need EDR. Yeah. The detection and response, you still need that. [00:19:00]

Ashish Rajan: Yeah, yeah.

Emily Heath: But we live in a different world, and so yes, there's all the benefits of reducing attack surface and saving people oodles of time, but the very real risk that really does exist with a lot of these AI tools and what's happening in the background, I think, is the most misunderstood.

Ashish Rajan: And too, I, I think I'm glad you mentioned this 'cause for me- The fact that we, yes, we want people to start using AI. Yes, we want them to use I guess improve their productivity to- Yeah ... what, what bosses want us to say. Uh, the understanding over there, and I'm glad you mentioned this EDR capability as well, and we were talk- when we were ca- we were catching up on the phone, we spoke about this as well.

Ashish Rajan: Traditionally, if you wanted to secure anything, at least endpoint-related, I had to have a Salesforce admin- Yeah ... uh, then there's another admin for something else. Y- traditionally, these have been disconnected.

Emily Heath: Yeah.

Ashish Rajan: Uh, never the one piece that- That's right ... looks me or makes me look at everything, and this includes the EDR to which you said, which tells me I have [00:20:00] Claude, I have OpenClaw, I have all these things, but it doesn't know what it's doing until it does something wrong, which ha- it has an indicator for.

Ashish Rajan: That's

Emily Heath: right.

Ashish Rajan: Uh, what, what's, what, what are you finding as the, the, the conversation evolve to where what is possible with AI today- Yeah ... now that we know already, and maybe to your point, we weren't, we were aware of this, we just hired people to do this- Yep ... instead of trying to, "Hey, maybe we can do this better."

Ashish Rajan: Yeah. So how can people do this better?

Emily Heath: Yeah. So I think it comes to, to me, down to the kind of the three layers. The first one is the foundations will always be the most important. Mm. Every single CISO job I've ever had- Yeah ... first project is a visibility project. Yeah. And I think, CISOs will be laughing and smiling when they hear that, like, "Yeah, me too."

Emily Heath: Yeah, yeah. Everybody's got a visibility project.

Ashish Rajan: Yeah.

Emily Heath: So the same thing still exists. I don't know anyone who trusts their CMDB.

Emily Heath: This is still an, again, an old problem. Yeah, yeah. Nobody trusts a CMDB. Why? Because it's hard.

Ashish Rajan: Yeah.

Emily Heath: Device reconciliation, you take your EDR and your MDM and your IDP and, try and reconcile these things together.

Ashish Rajan: Yeah.

Emily Heath: There is no common schema in [00:21:00] the industry. Therefore, what your EDR calls this particular attribute and what MDM calls the attribute are all different.

Ashish Rajan: Mm-hmm.

Emily Heath: So it's been fundamentally just difficult. Yeah. AI can definitely help with that. So number one, asset inventory, no problem.

Ashish Rajan: Yeah.

Emily Heath: Now you start to think about layering in people, and you start to layer in software.

Emily Heath: I used to pay three or four people full time to try and pull all of this data together in one place-

Ashish Rajan: Mm-hmm ...

Emily Heath: so that I could understand who was using what, what we were paying for, where the risks were, are the security controls properly deployed? When Susie left three months ago, does Susie still have access to this stuff?

Emily Heath: Like this is basic hygiene, so that fundamentally doesn't change. No. Now you've just got an add-on to that in AI. Yeah. You need to do the exact same thing to understand your own AI landscape. That's table stakes for us. The middle section then is, okay, so how can we make people a little more efficient- Mm

Emily Heath: and make sure that we're actually using AI to do some of the work for us? Mm. So this is where you can have them do the deep research and analysis, uh, we put those agents to work. We do [00:22:00] the device reconciliation for you. Other products out there make you do that manually. We've actually got agents that do that for you.

Emily Heath: Same with the software research and analysis. Deep research on vendors- Mm ... go to are they from Russia, China, North Korea? Were they breached in the last 12 months? What are the Reddit forums saying? What about the intelligence? You now have the capability to do that in real time. Mm. It's not just a one and done.

Ashish Rajan: Yeah.

Emily Heath: And then the final layer, which to me is the most important layer, is the action.

Ashish Rajan: Mm.

Emily Heath: So now you've got this an- amazing foundation. You've got the context piece in the middle, which saves people tons of time, and it allows it to be in real time, which reduces risk. Now you can have them take the action.

Ashish Rajan: Mm.

Emily Heath: Now, of course, everything's human in the loop to start with. What's fascinating to me and what we're seeing is I thought it would be a crawl, walk, run. What I'm finding is, and what we're seeing, it's a crawl, run. Oh,

Ashish Rajan: gee.

Emily Heath: Okay. It's the, the, it's, it's- There's no walking ... there's no walk in the middle. Yeah.

Emily Heath: You either trust, uh, AI to do something or you don't, and so they test it- Yeah ... with, with human in the loop. And, AI agents in, [00:23:00] and certainly in our system, and I'm sure in other people's, can do investigation for you. We do... And create an action plan. Let's say there's six steps in an action plan.

Emily Heath: Well, five of them can be done by AI.

Ashish Rajan: Yeah.

Emily Heath: Saves me a ton of time. Maybe all you want is the analyst to review the final piece to see, do you want me to take that action or not? And so the way to think about it is the foundations doesn't go away.

Ashish Rajan: Mm-hmm.

Emily Heath: It's, it's always the core pillar of everything we do.

Emily Heath: It's the old saying, "You can't protect what you don't see." Yeah. And it's the truth, the whole truth, and nothing but the truth- Yeah ... and that's never gonna change.

Ashish Rajan: Yeah.

Emily Heath: So now we've just extended that. Now let's put AI to work for us- Yeah ... in terms of context and action. And I think that way it's not just a prevention capability, but it's also a remediation capability.

Emily Heath: You've now got both sides of this-

Ashish Rajan: Yeah ...

Emily Heath: where you can leverage AI to do both.

Ashish Rajan: Oh, remediation is also an interesting one. But I'm just curious- People find it or people struggle to put confidence on AI for... And to your point, there are definitely two camps. One is the- Yeah ... uh, the crawl [00:24:00] camp, which is- Yeah

Ashish Rajan: basically saying, "I don't think I believe this," and would approach it with skepticism. Then the other running one, which is basically, "I don't really care what it says. I'm just gonna agree with it and move on. I'll make the risk choice later on." Yeah. In the previous camp, I definitely find a lot of people struggle with putting their trust on AI.

Ashish Rajan: Yeah. Like especially, uh, AI for security. Oh, sorry, the other way I said. Well, yeah- Yeah ... AI for security, where it's all how do I trust the result that's being shared with me? Because I guess it also because, you know, when you're looking at detection, you know you have created an alert, anything outside of it is potentially a zero day- Mm-hmm

Ashish Rajan: or I just haven't found it yet. Yeah. Whereas in prevention, it's more like I'm trying to predict that Ashish is gonna click that link and or ask the agent to go to this tool which I... is not in my list. Yeah. It's almost like the, the opposite of allow or deny that- Yeah ... where we started this conversation.

Ashish Rajan: How do you find people are able to build, uh, that trust with the use of AI- Yeah ... in security decisions being made?

Emily Heath: Yeah. It's a really, really important [00:25:00] question, and to me, everything that is, uh, an end result of an AI agent must be 100% explainable.

Ashish Rajan: Mm.

Emily Heath: So I know certainly in our product, we have every single decision, and everything you see is fully explainable.

Emily Heath: So it will tell you exactly how that decision was reached. It needs to be governed. Mm-hmm. So not only do you have full explainability, but you also can have AI agents that are governing other AI agents. Okay. So explainability, if you're using any product that is showing you an end result of AI and it's not capable of giving you the explainability, that would be a red flag for me.

Emily Heath: You need to know how it reached that decision. That should not be a black box.

Emily Heath: That should be 100% explainable to

Ashish Rajan: you. And I think I love what you said there because so it still, um, it kind of says it, but I'll probably state it out loud, and feel free to correct me, that I'm still not using AI as my final decision-maker.

Ashish Rajan: I'm still using the information provided to make the right call- Yeah ... as an individual.

Emily Heath: Yeah.

Ashish Rajan: It's not that the AI is making... I can take the action at that point in [00:26:00] time. "Oh, yeah, I like this action. Please go ahead." Yeah. Or, "Don't go ahead."

Emily Heath: Yeah. There's some simple ones, right? So let's just say somebody's trying to install a malicious browser extension.

Emily Heath: Yeah. That's an easy one. Once you've done human in the loop a couple of times, you're like, "Yeah, I trust that now." Let's just not let ever let that happen. Yeah. That can happen autonomously. No problem.

Ashish Rajan: Yeah.

Emily Heath: Now let's say that you find, I don't know, 2,700 missing EDRs.

Ashish Rajan: Mm.

Emily Heath: Okay, I probably wouldn't want AI to just go install it.

Emily Heath: There might be a good reason why- Yeah ... there, there's no security on those particular workstations or servers or whatever they are. So but the investigation can be done- Yeah ... by AI agents. Even when we're in security operations when there's an issue and when there's a an incident, oftentimes- When it's a device name, it'll say there's an issue on, uh, device number 01587XYZ.

Ashish Rajan: Yeah.

Emily Heath: And the first problem is, what the heck is that? Yeah. What the heck is that thing? Yeah. And who owns it? What, what-- How, how worried do I need to be?

Ashish Rajan: Yeah.

Emily Heath: And this is where, you know, with natural [00:27:00] language- ... you can ask product like ours and just put it in. It'll tell you everything about it because you've already got the context.

Emily Heath: So the amount of time that it saves just in security operations work as well as, trying to make sure that people can actually use the tools that they wanna use. Mm-hmm. So it's, um, there are so many very practical- Yeah ... use cases, but you can have AI do the work. You don't necessarily always have to have it make the actual remediation action until you're comfortable with it.

Emily Heath: So let's say, for example, that there were 2,700 missing EDRs. So what do you do about that? Okay. So AI can do the investigation, come up with an action plan for you, take you right to the very last step. Yeah. Take you to the last mile.

Emily Heath: Analyst comes in, reviews this and goes, "Okay." They can review this and decide what action to take.

Ashish Rajan: Yeah.

Emily Heath: Maybe the AI agents suggest, "Okay, we can create a ticket for you. Would you like us to do that in Jira, or do you want us to d-send it directly to ServiceNow?"

"

Emily Heath: Do you need us to Slack the engineer who owns these environments to ask them what they are?" There are so many actions that can now be taken.

Emily Heath: It's not just allow and [00:28:00] deny anymore.

Ashish Rajan: Mm.

Emily Heath: Uh, and these remediation types of, uh, situations, you can really have a lot of the work done for you before you make the final call.

Ashish Rajan: I love the, uh-- 'cause, uh, auto-remediation was also another one that 'cause you've been in the cloud space as well, it was-- it came for a hot second-

Emily Heath: Yeah

Ashish Rajan: and people instantly like, "Oh, actually this is a bad idea. Let's move on. Ignore

Emily Heath: it." Yeah. You're like, "I don't know whether I want a patch to be deployed on those servers

Ashish Rajan: or- Yeah ... in that environment." Let's, let's move on. Let's move on. Yeah, yeah. Ignore it. Nothing happened over here. Let's move on. Let's move to the next topic.

Ashish Rajan: Yeah. And then suddenly CNAPP was a thing after that.

Emily Heath: Yeah. But- But the things still exist, right? Yeah. The vulnerabilities still exist, so let's have AI do the work for you- Yeah ... and then leave me with the decision-making capability. It's, it's- It's much more efficient.

Ashish Rajan: I'm, I'm sure it's obviously people like you and I, but I'm just curious also for people who have not-- 'cause in a lot of conversations that I've had with people in the Fortune 500s and Global 1000 as well, some of them have gone down the path of saying absolutely no to AI until there's regulation.

Ashish Rajan: And then obviously there's some who have gone full, I mean, just go as deep as you can, spend all the tokens, don't really care if it's millions per month or not because this, our [00:29:00] life depends on it. I'm curious, is there a simple framework you have found for- I guess getting used to-- Especially for people who are on the, on the extreme where they have not adopted AI what do you find as a good mental model to go for where should be a human in the loop versus where should be an autonomous AI?

Ashish Rajan: Yeah. 'Cause everyone's, I'm sure, being said that, "Hey, AI is gonna solve all your security problems."

Emily Heath: Yeah, of course.

Ashish Rajan: Let's, let's start with the list with- It's the

Emily Heath: new holy grail

Ashish Rajan: for everybody. Yeah. That's right. Let's start with all the problems you have- Yeah ... and I'll show, I'll show you how AI can solve that.

Ashish Rajan: Yeah. And that makes people even more like, "I don't know, man." It's like- That's a bit

Emily Heath: cynical,

Ashish Rajan: right? Yeah, yeah, yeah. Yeah, of course. Which is just fair, and I think cybersecurity is known to be cynical to everything- Yeah ... in gen-in general, so- Naturally so. Yeah, so we are extra cynical to the whole thing. Yeah.

Ashish Rajan: But I'm curious as to, for people who are probably on that extreme what's a easy framework that they can use to dip their toes into that-

Emily Heath: Yeah ...

Ashish Rajan: oh, AI autonomous versus human loop. Like where do you- Yeah ... find the balance?

Emily Heath: First of all, if, if people are saying we're not using AI, I would highly caution the fact that they probably are.

Emily Heath: And [00:30:00] employees have ways to go around things and have done for many years, as we know. They'll be using personal accounts, which is even worse- Yeah ... because usually that, that means that your data's being used to train models and all those scary things.

Ashish Rajan: Yeah.

Emily Heath: Which comes down to the first thing. It's...

Emily Heath: i'm a broken record here. Mm. It's visibility. You need to understand what you have.

Ashish Rajan: Yeah.

Emily Heath: And so starting there will help you make better decisions. If you can figure out what you have, now you can apply policy. So now you can really think about, what do I really want to be the decision here? Mm. And if something is malicious or I don't want people to use Claude, I only want people to use Cursor-

Emily Heath: Set the policy. Set the policy so that can happen, and then you are then dealing with the drift-

Ashish Rajan: Yeah ...

Emily Heath: from, from this. Right? And you can either use-- you can choose to enforce that in real time, or you can do it passively and allow people to do it and then take care of it later. Mm. Most people want the human in the loop at first to see what is happening.

Ashish Rajan: Yeah.

Emily Heath: If it's something that is you know, usually malicious of in nature of some sort, I think the tendency for people is [00:31:00] to allow the AI agents to make the decision to flag this, isolate it, don't do anything with it yet because if it's malicious, it's just gonna get worse. Mm. But I think, you know, human in the loop is naturally the first thing that people should go to- Mm

Emily Heath: and that's healthy.

Ashish Rajan: Yeah.

Emily Heath: And whether you do the crawl, run, or you do the crawl, walk, run- Yeah ... there is a, a trust that we all have here. We're, we're all trying to figure out what is the best way to leverage this amazing capability- Yeah ... and leverage it so that we can really allow our employees to innovate 'cause that's what we want in business.

Emily Heath: We want innovation. We want people to go do their jobs- Yeah ... effectively. But you can't stop and get them in the way. I don't think not allowing people to use AI is the answer, personally- Mm ... and I don't believe that that's reality. Yeah. I think people are using AI, just whether or not it's sanctioned AI is different.

Emily Heath: Yeah. So whether it's sanctioned, whether you come from either camp, you still need to understand what you have-

Ashish Rajan: Yeah ...

Emily Heath: then apply policy to it, [00:32:00] and then think about, "Do I want this now, the action, to be autonomous or human in the loop?" And I would bias everybody to be human in the loop first. Get the trust and the explainability-

Ashish Rajan: Yeah

Emily Heath: so that you can really have deep understanding and, and trust in the action. Once it becomes repeatable, then there's a little bit more trust to be able to turn that on as human in the loop, and that will save you tons of time.

Ashish Rajan: Yeah. And I guess your point, the, the coupled version of explainability and visibility kind of- Yeah helps you at least- at least the data would be in front of you- Yeah ... to make the call for- Yeah ... do you trust this or not?

Emily Heath: It's classic security.

Ashish Rajan: Yeah.

Emily Heath: It's just this is a whole new world of software-

Ashish Rajan: Yeah ...

Emily Heath: which is why our position on this is we're gonna solve... We're gonna enable you to use AI safely on the new side- Yeah

Emily Heath: but we're also gonna take care of the old stuff for you as well, because having 60,000 pieces of software with Mythos on the loose is really not a healthy situation.

Ashish Rajan: Yeah.

Emily Heath: This attack surface now, I mean, you think about the time to vulner- from vulnerability exposure, it used to be weeks.

Ashish Rajan: Yeah.

Emily Heath: We're talking hours, [00:33:00] minutes- Yeah, yeah

Emily Heath: now. 30, 60, 90-day SLAs are not gonna be acceptable- Yeah ... in anybody's world soon. So you can't just put a ring fence around AI-

Ashish Rajan: Mm ...

Emily Heath: and think that's just the new problem.

Ashish Rajan: Yeah.

Emily Heath: It's not just the new problem. There's the other side of the house that's not going away. Nobody's getting rid of servers.

Emily Heath: Nobody's getting w- rid of PCs and Macs. Yeah. You still have to solve those problems. So we're trying to look at this more holistically. We don't wanna be a point solution. We really believe wholeheartedly that AI doesn't just exist here, it actually exists over here as well.

Ashish Rajan: Interesting. And 'cause I'm also thinking more from a perspective of people who have spent a lot of time on the SaaSes of the world, the EDRs of the world, the MDMs of the world.

Ashish Rajan: 'Cause, um, people already have, to, to what you said, a quote, unquote... And I'm sure people were like, "I have a lot of visibility, Emily."

Emily Heath: Yeah.

Ashish Rajan: Like, a lot- Yeah ... of visibility, right?

Emily Heath: Believe me, I've, I've said it a million times too. Believe me, I, I

Ashish Rajan: get it. Yeah, yeah. It's like, I'm sure when you hear pitches from other- Yeah

Ashish Rajan: kinda like, "Oh, I think I've seen enough visibility. I, I don't think I need any more visibility on this." [00:34:00] Yeah. But where do you find is the... I won't use the word skeps- skepticism for this, but I definitely find that people are try- finding it harder to justify for wha- when do I pull out my EDR?

Ashish Rajan: And maybe to your point, you don't have to pull out the EDR, you're just stealing the information, but more like- What's the signal in this noise of all the AI security visibility that I'm trying to get and the remediation that I want to do? If I were to take a step back and look at first principle-

Ashish Rajan: How would you approach this back when you were on as an operator? Yeah. 'Cause reality of every operator right now is that they are being told browser is the best option- Yeah ... endpoint is the right option. My- Yeah, it's so confusing, right? Yeah, my EDR does this as well. And I think I was talking to someone on the other day, they said, "Well, my appsec has AI."

Ashish Rajan: I'm like, "Your app- appsec has AI?" Like, "Oh yeah, my, my SCA tool has AI." Like, oh, you're like, okay. K- So people are being obviously approached from multiple sides on the AI security problem. So to putting back your operator hat-

Emily Heath: Mm-hmm ...

Ashish Rajan: [00:35:00] how- what's been your approach? 'Cause you obviously won the cloud revolution- Yeah

Ashish Rajan: as well when that happened.

Emily Heath: Yeah.

Ashish Rajan: Which somehow seems like eight decades ago, but- This is fine. So apparently we have another one. How do you approach this now?

Emily Heath: Yeah. So it's, the biggest thing is there's not one size fits all here. AI is everywhere. So AI exists in code.

Ashish Rajan: Yeah.

Emily Heath: That's a s- a completely set of solutions, a different set of solutions that will deal with making sure that your code that is being generated by AI, that is being deployed by AI into your production environments, that's, uh, that's the first group.

Emily Heath: To me, there's three. That's the first one. The second one is the SaaS. When you think about the prompts and, and these kinds of things and the agents, the what's the word I'm looking for? Like the sidecars that, that sit- Yeah ... with all like, browser, um- Extensions ... usage. Yeah. Not the extensions, but the, uh, Salesforce has an agent.

Emily Heath: Every- Oh, right, right. Yeah, yeah ... everybody has their own agent, right? So- Yeah, yeah. Like

Ashish Rajan: almost like an

Emily Heath: embedded agent, yeah ... it's a, it's a, it's a SaaS problem. Yeah. Like that's a SaaS problem to me. And then there's the endpoint- Yeah ... approach where everybody's putting everything on [00:36:00] the endpoint. There is not one single solution that will do all of those things.

Emily Heath: So people are trying to find the unicorn that does all of those things. There is no such thing right now. Mm. Whether there will be in a few years, probably.

Ashish Rajan: Yeah.

Emily Heath: But right now, there, there really isn't one solution that does everything. So the first, uh, piece of advice I'd think about was, would be for me, "Okay, where's, where's my biggest risk?"

Emily Heath: Obviously, I believe the biggest risk is what sits on the endpoint 'cause that's where people do their work. Yeah. That's where the work is getting done.

Ashish Rajan: Yeah.

Emily Heath: The SaaS problem's existed for a long time. And yes, we've trusted that people won't export things from Salesforce and send them different places, and now we're trying to trust that they won't put stupid stuff inside of a prompt.

Emily Heath: Mm. That's a DLP problem-

Emily Heath: yeah ... to me. Yeah. And if you have a good DLP solution, I would advise looking for your DLP solution to see if they solve this. Yeah. For the code side, that's an AppSec thing. That's a, an entirely different skill set.

Ashish Rajan: Yeah.

Emily Heath: So if you're a tech company, you're really worried about, code being put into production that's been written by agents, that's been deployed by agents, [00:37:00] that's a whole different type of product.

Emily Heath: So I know a lot of people are looking for that all-in-one.

Ashish Rajan: Mm-hmm.

Emily Heath: I don't believe that exists. I haven't seen any company- Yeah ... that does all of those things. I think what we find is a Venn diagram. Mm. Right? Some of them fit a couple of them. Some fit a couple. Like, we fit a couple. They fit a couple. But you really, as a CISO, if I put my CISO hat on- Yeah

Emily Heath: I'm thinking about, "Where is my exposure? What am I the most concerned about? And let me try and solve that p- that problem first." But yes, it comes down to visibility, control-

Ashish Rajan: Mm ...

Emily Heath: monitoring, and enforcement. Mm-hmm. That's really what it comes down to. It's security principle 101. Yeah. It's, none of that's any different than it used to be.

Ashish Rajan: Yeah. And I think I'd probably I think, A, well said 'cause I definitely believe that is true, that I don't think people can have one solution for each one of them. It's a very unique problem, very unique set- It's

Emily Heath: huge.

Ashish Rajan: Yeah, yeah. It's just,

Emily Heath: it's, it's, we're talking about all of security- Yeah, yeah, yeah ... all of technology.

Ashish Rajan: The entire

Emily Heath: category. Right. So we're talking about all of technology. There's not one, one solution that does all of those things. Yeah. So you really gotta think about where, you know... And if there, if somebody says, "We do it all"- ... I don't [00:38:00] think that that's really right. So it's being very clear on which parts of AI you're the most concerned about.

Ashish Rajan: Yeah. I'm sure the platform provider's like, "We do all of it, Emily." Like with an asterisk on top. Of course. Yeah. Uh, I think the, uh, one more question I had was endpoint security's also interesting because a few years ago in 2024, I think, there was, like, a blue screen of death that occurred globally.

Ashish Rajan: And a lot of people, uh, and this has at least come up in the conversations that I've had- A lot of people believed in endpoint before, but now a bit skeptical 'cause they almost feel like, "Oh, if I add a new variable in this ecosystem-"

Emily Heath: Oh, yeah, the agent fear. Yeah.

Ashish Rajan: Yeah. And now it's like, what does that mean for...

Ashish Rajan: How do I explain this? That, oh, by the way- Yeah ... it's the AI agent that re- may put everyone on blue screen of death, and- Yeah ... there's so many businesses that were disrupted by it.

Emily Heath: Yeah.

Ashish Rajan: Uh, what's been your thought on A, approaching it, balancing it, or mitigating that risk? Or how do you s- Yeah

Ashish Rajan: approach that problem?

Emily Heath: First of all, I mean, I understand completely nobody wants to put more agents on machines. Yeah. It's historically been very [00:39:00] problematic Uh, we're completely agentless.

Ashish Rajan: Mm-hmm.

Emily Heath: So there are ways now to use the technology where you don't need to deploy an agent. Right. And in the instance that we talked about with the blue screens that caused a lot of problems that was a kernel issue.

Emily Heath: Yeah. Right? So agents that have that much control- Mm-hmm ... on endpoints, uh, is a very dangerous place, and I think even they've changed- Oh, yeah ... now.

Ashish Rajan: Yeah. Okay.

Emily Heath: But first of all, do you n- really need an agent?

Emily Heath: I know for us you don't need an a- we have an agent if you want to do enforcement that's not through your MDM or something else, so but it's more of a small use case of enforcement, not to give you all the rest of the capabilities.

Emily Heath: Yeah, yeah. So, so I think that there are m- and, and we're not the only ones. There, there are- Mm-hmm ... many solutions now that don't need agents.

Emily Heath: If they do need agents, you still have to have the same level of concern as you've always had with agents. Yeah. Uh, yes, they're a little more lightweight now.

Emily Heath: They're most definitely more contemporary than- Mm ... they used to be. I mean, a lot of these agents were so clunky and, you know, designed years ago. Yeah. And then you put an agent on top of agent on top of agent- Yep ... and, you know, all your CPUs- And they, they didn't like each other as [00:40:00] well ... have been sucked or down and performance issues everywhere.

Emily Heath: Yeah. That was always the biggest concern. That's right. So they're a lot more lightweight than they used to be- Yeah ... now. But in our case, like I said we don't need an agent for that. We have a collector that's run differently, but you don't need to necessarily always install agents. If you do I would still have the same concerns as with any other agent- Yeah

Emily Heath: and I would do my due diligence and testing on that because at the end of the day, the impact on the business is what matters the most. That's

Ashish Rajan: right. Yeah.

Emily Heath: You know, it's at the end of the day, you have to know what matters most to your business. You know, you gotta know where it is and how- Yeah ... you're protecting it, and know how to be resilient enough that you can stand with your hand on your heart and know I know what I'm gonna do when something goes wrong, 'cause one day it will.

Ashish Rajan: Mm.

Emily Heath: So same, same set of problems, but hopefully we can do- Yeah ... things a little better now.

Ashish Rajan: Yeah. Well, I think hopefully, 'cause I think, uh, when you were saying this, reminded me that there used to be agents that used to hate the other agent.

Ashish Rajan: Yeah. And it- Totally

Emily Heath: interfere

Ashish Rajan: with each other. Yeah, yeah.

Ashish Rajan: Battle of the agents. And you're like, I think... I can't remember the names of companies, but I re- pretty sure I can't remember if it was the antivirus hating EDR or EDR hating antivirus. Yeah. It's a, it's a rogue [00:41:00] agent- That's right ... on your laptop, and you're like, it's a false positive, but hey. That's

Emily Heath: right.

Ashish Rajan: That, that is generally a concern.

Emily Heath: It really is, and I think what you'll see in the not so distant future is more of a consolidation approach of agents. I... There is the technology, and now we shouldn't be living with old agents that still do the same clunky things- Yeah ... and applying more agents on top of them.

Emily Heath: That's just, that's not the future for anybody.

Ashish Rajan: Yeah. Do you find that the security teams, the way they're... Obviously, because you've been an operator before- The way they operate today in a lot of ways is considered traditional. Like we have an AppSec team, we have a CloudSec team, security awareness list goes on.

Ashish Rajan: Um, but to what you said earlier, to get information from multiple sources- Mm-hmm ... we had to have multiple people- That's right ... go across the board. Someone gets information from the cloud security people, someone gets information from the AppSec people- That's right ... and then you get the one, one holistic view of- Yeah

Ashish Rajan: "Oh, this is what my platform actually is look like." Yeah. "This is how much work I have to do-" It's hard. "... to get the..." Yeah. And now- And when

Emily Heath: you do find out, now it's stale. You know? It's like- Yeah, yeah, yeah. Now I have to go back and do it all

Ashish Rajan: again. That's right, yeah. By the time you [00:42:00] got the information, it's already six months later and you're like, "Oh, well I could...

Ashish Rajan: I'll just start again the project then." Yeah. Yeah. How do you... do you foresee the current model existing as we go more deeper into AI? And if it should change, what, how should it change? Yeah.

Emily Heath: I think it's blending more. I mean, we're even seeing the role of the CISO change a lot. We're seeing, you know, CIOs become...

Emily Heath: CIOs and CISOs blending together. We're seeing a lot of CISOs take on infrastructure responsibilities. Yeah, yeah. It's a, it's definitely a, a trend in the industry, and that's because the lines are getting very blurred. Mm-hmm. I mean, I'll give you an example. As you know, I had the privilege of being on the board of directors for Wiz.

Emily Heath: Yeah. So I can't unsee that phenomenon. Yeah. But Wiz were kind of the bridge between security and DevOps.

Ashish Rajan: Mm-hmm. Yeah, yeah.

Emily Heath: We see ourselves as the bridge between security and IT.

Ashish Rajan: Oh,

Emily Heath: right. Because IT also care deeply about endpoints. Yeah, yeah. They care about software. They have a slightly different lens than security- Yeah

Emily Heath: but the worlds are blending together. So we're seeing that the practitioners themselves are taking on roles that are a little bit broader- Mm-hmm ... [00:43:00] because now having the scope of knowing the, what the left and right hands are doing is a lot easier if it's un- under one roof and there's not kind of the historic kind of battle of, you know, uh, territory and, you know, dynamics in an IT team when security needs something from IT or they need- Mm

Emily Heath: it from infrastructure. It's historically, years ago, was very difficult- Yeah, yeah ... to navigate that, and it's all about- Yeah ... political capital.

Ashish Rajan: Oh

Emily Heath: my God, yeah. It's all about, like, you- Un-

Ashish Rajan: unfortunately they never got the- They never got the line show the budget so they hit nothing

Emily Heath: more. Yeah. No, but it's, you want something doing, like you find ways to- Yeah

Emily Heath: to build relationships with people. Yeah,

Ashish Rajan: yeah.

Emily Heath: But, you know, the... So I think the world in which the CISOs live, the security teams live, has definitely changed, and I think that the solutions that are being presented are a reflection of that- ... because you do need to have that bridge. It's not just a one-size-fit-all.

Emily Heath: You also have to play within the ecosystem.

Ashish Rajan: Mm-hmm.

Emily Heath: You can't keep everything here and then not feed it back to the CMDB- Mm ... or not feed it back over here. You have to think about things in terms of the practitioner. I certainly do. Yeah, yeah. And that, that's a big reason [00:44:00] why I wanted to join the startup world, because I know I bring very much a practical operator lens to it.

Emily Heath: Yeah. But I really care about this industry a lot.

Ashish Rajan: Mm-hmm.

Emily Heath: And I know that CISOs don't have more money, they don't have more resources. Yeah, yeah. And they have 10 times more challenges than they did when I was starting my career.

Ashish Rajan: Yeah,

Emily Heath: yeah. It's, this is a hard job. Yeah. It's a difficult job. It's a very high-level executive job, and a lot of people misunderstand or maybe don't give the credit to just how difficult this job is.

Emily Heath: Mm, mm-hmm. So where we can leverage the technology to not only help reduce risk and those kinds of things, but also build bridges between teams, help them have the same source of truth so that we're not... You know, the first thing that you take, you do when you take something to an engineer, an engineer will say, "Well, where'd you get that data from?"

Ashish Rajan: Oh,

Emily Heath: yeah. "Now, where'd you get it?" It's, y- there's a battle- Mm ... of a source of truth.

Ashish Rajan: Yeah, yeah.

Emily Heath: Right? So they won't trust you until it's their data. Yeah. So let's use their data. Mm. Let's make sure that it's the s- the same source of truth. The amount of friction that takes out of true day-to-day operations is [00:45:00] enormous.

Emily Heath: So having the data in one place is without doubt not just for the security teams, this is for the broader organization. And hey, you know, this is something that a company like Wiz did exceptionally well.

Ashish Rajan: Yeah.

Emily Heath: Security teams would buy the product and then they'd get out the way And let other people use it, let developers use it, let cloud people use it.

Emily Heath: Yeah,

Ashish Rajan: yeah,

Emily Heath: yeah. It's a very similar situation for us. Right. Security pe- people buy the product, and they get out the way and let IT use it, too. This is- Oh, right ... you know, there's you can't separate the worlds. Yeah. And this is to me what the difference is between good CISOs and great CISOs.

Ashish Rajan: Yeah, okay.

Emily Heath: Great CISOs really build relationships and really understand their business exceptionally well. So it's not a territory, this is not about just security. It's about enabling business-

Ashish Rajan: Yeah ...

Emily Heath: and you can't do that in a silo.

Ashish Rajan: No. And I guess, you're pr- you're almost being cross-functional in that way- You have

Emily Heath: to be

Emily Heath: in that sense. You have to be.

Ashish Rajan: Yeah.

Emily Heath: And whether or not it's true ownership or ownership through influence- Mm ... really doesn't matter. You- you've got one goal, and that the goal [00:46:00] is not to be everybody's friend. Your goal is to keep your company safe. Yeah. And, and it's a high-stakes job, and like I said, it's, uh, very underestimated sometimes at just, not just the pressure and, you know, I'm not just saying that CISOs, uh, have this very difficult job, but it's genuinely a very hard job.

Emily Heath: Yeah. There's so many moving pieces. Very few jobs are you responsible for something that you have no control over.

Ashish Rajan: Yeah. You don't even know

Emily Heath: what it does. You, you, you're not the one that says you can use that or not. Yeah, yeah, yeah. So it's, uh, you know, it's, uh, it's a, it really is a very influential job.

Emily Heath: Yeah. But, um, you know, it's getting harder, but I think the tools that, the solutions that are being designed, especially with AI, should make a huge, enormous difference in the day-to-day.

Ashish Rajan: Do- do you feel there'll be almost merging of different teams to, to... I mean, obviously, there's the IT team, and then there's the AppSec team.

Ashish Rajan: There's also a merger in the sense that the applications that are being produced, uh, let's just say the AppSec world, which is the coding agent- Mm-hmm ... world that you recommended earlier. There, there is that, uh, running on laptops or endpoints, and then there is also the, [00:47:00] uh, the endpoint itself where I'm using a browser- Mm-hmm

Ashish Rajan: which is, w- I'm just a non-technical software... No, I'm not a software engineer. I'm just Bob from accounting, let's say. I just happen to be in a browser. They're both in that overlap category of coding agents, and there's like- Yeah ... so do you find that more and more CISOs would start combining those roles as well?

Emily Heath: Yeah. I mean, it's, it's, I- I view it as to where the fingers hit the device- Yeah ... where the, where the work gets done.

Ashish Rajan: Yeah.

Emily Heath: And if that's the case, I mean, we can see all your browser extensions. Mm.

Ashish Rajan: You

Emily Heath: know, we have a browser extension- Yeah ... so we can monitor all that activity. Yeah. It's, there is a massive consolidation opportunity here for CISOs, and I don't just mean in terms of money, although money is always short.

Emily Heath: Of course. Uh, but in terms of skillsets, in terms of capabilities- Yeah ... point solutions are just not the way of the future. It's not... Everybody's looking to consolidate, but there's a balance here between platform play versus point solution. Where's the middle ground?

Ashish Rajan: Mm.

Emily Heath: There's somewhere.

Emily Heath: You're always gonna have a suite-

Ashish Rajan: Yeah ...

Emily Heath: of products, and we all know how many products security people have. They're paying a lot of money for that [00:48:00] stuff.

Ashish Rajan: Yep.

Emily Heath: And you don't want it to be shelfware. Yeah, yeah. You want that stuff to be really used. I used to say to my teams, "If you're not using it at least 80%, you don't need it."

Emily Heath: Yeah,

Ashish Rajan: yeah.

Emily Heath: Because we wanna get bang for the buck out of what we're using. Let's make sure- We become experts in what we do.

Ashish Rajan: Yeah.

Emily Heath: But, uh, I do believe that there is an opportunity to consolidate capabilities, for sure.

Ashish Rajan: I think also to your point, finding frictionless ways to introduce security to teams as well, to what you said about- Yeah the browserless-- sorry, the, um, agentless model as well. Yeah. But I'm curious about the agentless. The reason why always people thought that you have to have an agent is so that you get to see everything- Yeah ... the network, the- Mm-hmm ... browser, everything. I'm just curious as to how does this work in an agentless world?

Ashish Rajan: You- Yeah.

Emily Heath: So I mean, it, in an a- it- when it comes to an endpoint, of course you do integrations. Yeah. So simple one-click integrations, you can light everything up like a Christmas tree- Yeah ... you know, within less than an hour. But then you can have collectors that you can run. So instead of just installing an agent, you can run a collector, and you can run it as many times a day as you want.

Emily Heath: Yeah. You can run it once a day, once a week, whenever you want to, and it's fully within the [00:49:00] control of the security team. It's not necessarily something you have to deploy onto each, uh, device in order to do that. Right. So a combination of a kinda proprietary collector plus integrations, and you don't need many.

Emily Heath: You think EDR, IDP, MDM.

Ashish Rajan: Yeah.

Emily Heath: Uh, if you wanna see the network stuff, sure. CASB, you know, your Zscalers of the world, the Netskopes or whomever.

Ashish Rajan: Right.

Emily Heath: You know, they're just APIs. Right. Right. It's, it's, that's just giving you visibility. But where you get- Yeah ... the, the enforcement and control, some of that can be done through a collector, some of it can be done by maybe you want the MDM to take the action.

Ashish Rajan: Okay. Yeah.

Emily Heath: So the control plane tells the MDM to take the action. Yeah. Sometimes you might wanna create a ticket. Yeah. You know, do that. We do have an agent, as I said.

Ashish Rajan: Yeah,

Emily Heath: yeah, yeah. Uh, it's actually surprising how many people are deploying the agent because they want the enforcement themselves without having to ask IT.

Ashish Rajan: Oh, right. Okay. Yeah. Yeah. Okay, then- So

Emily Heath: but it, but it's a small set of use cases. It's really enforcement. It's the enforcement layer that really does need an agent- Yeah ... uh, or, you know, some capability [00:50:00] if you want it truly in runtime.

Ashish Rajan: Mm.

Emily Heath: Otherwise, there's always gonna be a slight delay-

Ashish Rajan: Yeah,

Emily Heath: yeah ... by calling one of the other tool sets that you have to do that.

Ashish Rajan: It's like, so going back to, and this is my f- final question as well, 'cause I wonder where is the line to be drawn for endpoint security as a solution ecosystem? Is it based-- people should make that call based on how frictionless? 'Cause I t- I, I guess to your point- Everyone may have the same kind of visibility, same kind of integration, but where it may be the, the true source of it is only found after the POC.

Ashish Rajan: Of now I'm starting to implement it, now I'm trying to figure out, "Oh, how do I apply this or how do I implement this and kind of spread this across my organization to have the most coverage possible?" Yeah. What- how should CISOs kind of approach that particular problem for endpoint? 'Cause I imagine multiple organizations have different ways of doing it.

Ashish Rajan: To your point, go- maybe it goes back to the relationship as well, maybe leverage some of that. What do you find is a better way to tackle AI specifically because it's such a wide problem? Yeah. It's not just like... And [00:51:00] you mentioned three use cases right there- Yeah ... each one of them being its own- Its own

Emily Heath: product set.

Ashish Rajan: Yeah, yeah.

Emily Heath: Yeah.

Ashish Rajan: So how do you, what do you, what's your recommendation on, for that?

Emily Heath: Yeah, I mean, again, I, I know I'm a little biased here but truly there's a reason why I left my easy-peasy VC- VC life to, to, to go- Every time you say that, all of me- ... to go into the fast lane and do, and build a startup. I,

Ashish Rajan: I feel like every time you say that the easy-peasy VC, VC's like, "Did she just say that?"

Emily Heath: I'm saying it. No. You know my VC friends, they'll be like, "Oh my God, what's she saying?" Yeah. But no, it's a, it's a very different type of world, right? Yeah. The, the, the running into the fast lane- Yeah ... and, uh, building a startup is not for the faint-hearted. Yeah. And if I was gonna do this, I could do this in something that I cared deeply about- Of course

Emily Heath: that I really believe is gonna be industry-defining.

Ashish Rajan: Mm-hmm.

Emily Heath: This is the moment for the endpoint.

Ashish Rajan: Yeah.

Emily Heath: It is the endpoint's moment. It's not been its moment for 15 years or more. Yeah, yeah,

Ashish Rajan: yeah.

Emily Heath: Now is the time to do that. And as you can see, just even the last couple of months, there's lots of new companies that are- Mm

Emily Heath: that are coming into this space. And th- and that's market validation. Yeah, yeah. That's, that's because we've now got the technology to actually do something about it. Where I care the most is where the risk is the most.

Ashish Rajan: Yeah.

Emily Heath: I want to [00:52:00] protect my organization from as much risk as possible. If I can do that by safely allowing people to use AI and adopt AI, because they're going to anyway.

Emily Heath: Yeah,

Ashish Rajan: yeah.

Emily Heath: So let me allow them to do that safely- Yeah ... and be the safety net for them, because I want them to go innovate. That's what I want my, my business to do.

Ashish Rajan: Yeah.

Emily Heath: But at the same time, let me apply the same principles to also solving the problems that already exist on this monstrosity of an environment that we've been trying to protect for years.

Emily Heath: Mm. So again for me I think it's beyond just AI- Mm ... when you start to talk about the endpoint. There's a new and the old world. Yeah. AI's getting a lot of attention, and even we pivoted much heavier into it because that's where people were drawing us to. Mm. But really the thought of having the same capabilities across every single piece of software that your company is using I believe it's really powerful, and that's, it's the moment for the endpoint.

Emily Heath: Yeah. It's right now.

Ashish Rajan: I, I'm with, 100% with you. Also because if you notice the kind of AI hacks that are coming across, even the Hugging Face one- Yeah ... the agent [00:53:00] coming out of the sandbox- All the use cases point majority times, so even if you look at the MCP world, skills world, all of that just point you to something is happening at the endpoint that you need visibility- Yeah

Ashish Rajan: and control over. Yeah. So.

Emily Heath: It's just a, one of the fundamental pillars. And like I said, EDR has been, the trooper for the last 15 or more years- Yeah ... that's been trying to help keep us completely secure, and that's just from a detection-

Ashish Rajan: Yeah ...

Emily Heath: perspective. Not prevention. Because prevention's been just really hard.

Ashish Rajan: Yeah.

Emily Heath: But now we have the capability to be able to do that. Mm-hmm. And, um, I see it as game changing. I really do.

Ashish Rajan: No. Awesome. No, thank you for sharing that. We're also doing this thing called, uh, you laugh, you lose. The rules are simple. If you laugh, you lose.

Ashish Rajan: And, um, fi- you have five seconds to react or not, all right? 'Cause this is an endpoint joke. I was thinking, trying to think of, hey, what's the real-life comparison for endpoint and like, oh, I think I... 'Cause I was in an Uber ride when I was trying to-

Ashish Rajan: think of this. So I like- I should have done the same. Yeah. And like endpoint security would absolutely be the Uber[00:54:00]

Ashish Rajan: driver who locks the doors and says, "So where are we really going?"

Emily Heath: Yes. Okay. You know, you got me.

Ashish Rajan: Yeah, yeah. You see what I mean? It's like, I'm like, oh, actually, yeah, I wonder if

Emily Heath: Uber driver- Okay, you're clever, so I'm gonna have to think of a really good one.

Ashish Rajan: Uh, well, I, I, I'm glad you kind of agreed to this.

Ashish Rajan: But that's all I had for the episode. Where can people learn more about Glow and the work you guys are doing, and where can they connect with you as well?

Emily Heath: Yeah. So glow.io- Mm-hmm ... is the website. Feel free to reach out to me on LinkedIn. I am not only a huge advocate of what we're doing here, but I'm also, I care deeply about this community a lot.

Emily Heath: Yeah. And I spend a lot of time talking to CISOs who are either looking for opportunities, you know, about being on boards and that kind of thing later in life, uh, or whether people are up-and-comers and want to be in the CISO world. Uh, I genuinely mean it. I never ask for anything in return other than pay it forward and do something nice for somebody else.

Emily Heath: Uh, it's my way of giving back to this community, which I really, really believe wholeheartedly in. And, uh, I'm just thrilled to be a part of it from a different [00:55:00] angle. So glow.io, and, uh, for those of you, of course, I know this will come out after Black Hat, but you'll see us at the House of Glow.

Ashish Rajan: Awesome. All right.

Ashish Rajan: The House of Glow. And I will, uh, put the LinkedIn link as well as the website in there. Thank you so much- Yeah ... for coming on the show.

Emily Heath: Thank you for having me.

Ashish Rajan: Uh, thank you. It's amazing. Thanks everyone for tuning in. Thank you for listening or watching this episode of Cloud Security Podcast. This was brought to you by techriot.io.

Ashish Rajan: If you are enjoying episodes on cloud security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple, Spotify. In case you are interested in learning about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security.

Ashish Rajan: Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at Cloud Security Podcast. You can check that out on cloudsecuritynewsletter.com. I'll see you in the next episode.

Peace.

‍

No items found.
More Videos