Why are legacy DLP and EDR solutions failing to protect enterprises from AI-driven data exfiltration? Because when an AI agent holds corporate data in its memory, traditional network scans and malware signatures are completely blind to the context and intent of the action. In this episode, Ashish sits down with Nati Hazut, CEO and Founder of Bold Security, to discuss the massive resurgence of endpoint security in the AI era. Nati explains why relying solely on cloud-based Data Security Posture Management (DSPM) forces CISOs to accept dangerous trade-offs like only scanning 5% of their data and why running lightweight AI models locally on the endpoint is the key to true real-time prevention. We also explore the threat of shadow MCPs, the limitations of certificate pinning, and how to achieve "zero policy" data visibility.
Questions asked:
00:00 Introduction to Endpoint Security and AI
02:00 Nati Hazut’s Background (SAM, Polyrise, Varonis, Bold)
03:20 Why Endpoint Security is a Priority Again in the AI Era
05:00 Why Legacy DLP Fails to Understand AI Agent Intentions
07:20 The Blind Spots of EDR and Network-Based Security
09:30 Cloud AI vs. Local Endpoint AI: Overcoming Data Sampling Trade-offs
13:30 Catching Large File Exfiltration with Local Scans
15:10 Shadow AI and the Danger of Rogue MCP Connections
18:00 Controlling AI Adoption and Sanctioning Specific MCPs
21:30 The "Zero Policy" Approach to Data Visibility
23:40 Integrating Endpoint Alerts with MCPs for Incident Response
28:50 Certificate Pinning: Why Network Traffic Visibility is Shrinking
30:30 The "You Laugh, You Lose" Cybersecurity Joke Challenge
Nati Hazut: [00:00:00] If you want to steal files, go big. Because if you go big, it's just they won't even try to scan it, so they just let it pass. You'll find it with all the vendors, I promise you.
Ashish Rajan: Like, why is my DLP not enough?
Nati Hazut: This attack surface is just increasing, and as an industry, we're not ready. We're still using those old tools that's been around for twenty, thirty years.
Nati Hazut: With AI, you're sharing data with an agent. It's in the memory of this agent, and there's a potential of this agent to take this data outside. If you go to the CISOs, they'll tell you that a day after a POV, they're starting with the trade-offs, and trade-offs are data sampling. Scan five percent of your data.
Nati Hazut: Scan it once a month. An AI agent decided my machine should listen on a TCP port for whatever incoming connection. Internal MCPs that are the holy grail of the company, the repository, their knowledge base, connected sometimes, most cases by mistake, with either personal MCPs or public MCPs.
Ashish Rajan: [00:01:00] We didn't have a prevention method before, but now we're saying actually prevention is possible today.
Ashish Rajan: If you have used a DSPM and built a data classification engine, you probably realize the fact that doing data classification at a cloud level or even on the device has its own challenges. I had a great conversation with Nati Hazut from Bold Security. We spoke about the challenges that comes with the gaps that are exposed by DSPM, how it's not real-time enough.
Ashish Rajan: We spoke about DLP as an ecosystem, how that may not be the right approach to solve, or at least get visibility across all the AI usage you may have across your organization. We also spoke about what does it look like to use AI as a capability to have full visibility across your AI ecosystem, whether it's on your CLI browser and any other approach that your organization may be taking to utilize AI for maximizing productivity.
Ashish Rajan: All that and a lot more in this conversation with Nati. And if you have been watching, listening an episode of the podcast for a while and are here for a second or third time, [00:02:00] I would really appreciate if you drop the follow, subscribe button, whichever platform you listen to us on, whether it's on YouTube, LinkedIn, Spotify, Apple.
Ashish Rajan: We are everywhere you consume your podcast from. I hope you enjoy this episode, and I'll talk to you soon. Hello and welcome to the episode. Today, I've got Nati with me. Hey man, thanks for coming on the show.
Nati Hazut: Hi, thank you for having me.
Ashish Rajan: I'm excited for this. Maybe to kick it off, could you share a bit about yourself, your professional background?
Nati Hazut: Of course. So, um, I'm Nati, CEO and founder of a company called Bold. Uh, Bold is actually my third startup. So, uh, the first one was in the agent security space, but agent in, you know, the old terms of securing routers of service providers. Oh. Uh, company called SAM. I sold it to Qualcomm, and then I founded a, a DSPM company in its early days called Polyrise.
Nati Hazut: I sold it to Varonis in 2020-
Ashish Rajan: Wow ...
Nati Hazut: uh, and led the cloud initiative there for three years. And then I left. I thought, "I'm gonna take one year off." It ended up in three months, uh, of, uh, vacation, and then I started Bold. [00:03:00]
Ashish Rajan: Oh, wow. Oh and I think it's interesting, third startup, you've doubled down on the endpoint challenge, which is in itself interesting because most of the industry kind of ignored endpoint as a solved space.
Ashish Rajan: Then AI kind of changed it a bit, and it seems to have become a priority again for a lot of people. I'm curious, obviously, you could have gone anywhere. You could have picked any direction. What was it about the endpoint securities ecosystem that caught your attention, and what was not being addressed that specifically you got drawn to?
Nati Hazut: Yeah. I, I agree. For years, it was the backyard of the enterprise, right? It was nice to ignore it. Uh, but yeah, AI, uh, brought it to the front. I think that for the past, say, two decades, we're heavily invested as an industry in the cloud and in the SaaS. But I remember this moment when I was talking with a customer after a big DSPM project, and they're asking a very basic question that makes you wonder.
Nati Hazut: They're like, "So right now, when we're done with this project, if someone's gonna take [00:04:00] data out of this, you know, production system and, I don't know, zip it and send it over whatever SaaS, would you be able to help me?" And that moment I realized that, we did good with the posture, but we cannot actually protect the users.
Nati Hazut: And suddenly with AI, you realize that, you know, this attack surface is just increasing. And as an industry, we're not ready. We're still using those old tools that are, that's been around for 20, 30 years, and they, by the way, still struggling with the old challenges. So I thought this is, you know, a once in a decade opportunity because nobody wants to actually replace agents on the endpoint.
Nati Hazut: Yeah. It's very tedious. It's very hard. So you need a very good explanation of a why now, and I think this why now is here.
Ashish Rajan: And maybe just to set some context as well, because AI security, a lot of people look at that to, to what you said, DSPM is like, "Oh, I've got data security covered, DSPM, posture [00:05:00] management."
Ashish Rajan: Why is there a gap in the way AI interacts with an endpoint that is not... Like why is my DLP not enough?
Nati Hazut: Yeah, that's a great point. So when you think about DLP it is very focused historically on compliance, and it's very focused on the data in a very narrow way. And because it's so siloed, when we think about the new challenges of AI, we're talking about actions, we're talking about intention, we're talking about how the data is being transformed locally on the endpoint and the different egress channels that the AI will use to take this data outside of the enterprise.
Nati Hazut: Now it's getting much more complex with the introduction of MCPs, with CLI actions that are happening and there's also one another thing that we see, which is the intention of prompts and the memory of the AI. So in the past, we thought about data flowing from [00:06:00] one place to another- Yeah ... and whether you block it or allowing it.
Nati Hazut: With AI, you're sharing data with, uh, with an agent. It's in the memory of this agent, and there's a potential of this agent to take this data outside. So it's getting more complex in how this data is actually also being exfiltrated.
Ashish Rajan: So why was there so much attention given to the browser? 'Cause obviously to what you said is CLI, there is...
Ashish Rajan: we haven't even gone into the MCP and AI agent conversation yet. Why was... Uh, 'cause, I don't know, the reason where I'm coming from this is a lot of people that I speak to over-invested in browser security being that first layer that they go for AI security. And sounds like there's a lot more ways people can interact with AI.
Ashish Rajan: It's... And it's just not me, but it's also third party, the SaaS providers as well. What does the endpoint give as an advantage that I can't have with a browser or some kind of a, uh, some other tooling that I may have? And also [00:07:00] just in that same vein, I have EDR, why do I need another one? And just the reason I say this is because many people already have an EDR.
Ashish Rajan: Many people-- To what, where we started the conversation, endpoint was the back end. The reason it became the back end is like, "Oh, we have an agent," looks after everything, or they go, people go through VPN.
Nati Hazut: Mm-hmm.
Ashish Rajan: What is it different this time with AI specifically that makes it like those things are just half the picture, for that lack of a word?
Nati Hazut: Sure. So the first thing about the browser, secured browsers. I think secured browsers are still relevant in the market and they're being used for multiple purposes, right? We see them going beyond security to, um, to productivity, to SASE. There's many aspects of the secured browsers. But I think what was kind of like surprising for us as an industry, and it's, it goes the same with what I said about how we were heavily invested in the cloud-
Nati Hazut: The endpoint is no longer just your gateway to the enterprise assets. There's some local workflows running on the endpoint, right? We [00:08:00] see this demand for local AI, and we see this demand for agents running on the endpoint. And as said, it goes far beyond the managed browsers to the unmanaged browsers, AI browsers, CLI, desktop apps that we're seeing that are being used.
Nati Hazut: So basically, it's just one front out of many. And to your point about EDR, I think that EDR, um, is really focused on malware-
Ashish Rajan: Mm ...
Nati Hazut: right? That's w- how it was built. Yeah. So in missing the context of the data, the intention, the users, and- When we look at kind of like the, those solutions today, and when we talk about, let's say, ransomware, right?
Nati Hazut: The impact of a ransomware of, on various organization is just the same. We can all agree, right? It's wrong.
Ashish Rajan: Yeah.
Nati Hazut: But an action of a user of an AI agent on different organizations is very different. It depends on the business [00:09:00] context, it depends on the types of the data and the regulation, and these tools are just not built for this purpose, right?
Nati Hazut: They're not built to understand this business context that we need so bad now with AI, and in general, in the data security space.
Ashish Rajan: Oh, uh, and I'm glad you mentioned the local agent as well, because at least the way I understood the models for how you make your AI usage secure is either you can send requests to an MCP server, which is on the internet, it's hosted in the cloud, or you can have it locally.
Ashish Rajan: And basically the, the balance you're trying to find is the latency in the request. Does it make a difference, uh, whether it's in the cloud or in, on, on the device itself? Like, what's the advantage of having it on the device versus, hey, the cl- I mean, I can just send it to an MCP server, 'cause I'm sure a lot of people are thinking that in their mind as well.
Ashish Rajan: Sure.
Nati Hazut: So again, coming from the DSPM space, we saw the struggle of securing the large enterprises- Mm ... at scale and protecting their data. If you go to the CISOs, [00:10:00] they'll tell you that a day after a POV, they're starting with the trade-offs, and trade-offs are data sampling, scan 5% of your data, scan it once a month, right?
Nati Hazut: Mm. It goes far beyond the near real-time promise. And when we talk about protecting data on the endpoint, and we know the amount of interactions, we know the amount of data that we have on these endpoints, trying to do all the heavy lifting in the cloud got multiple disadvantages. The first one is the ability to do prevention based on AI.
Nati Hazut: I think we can all use cloud, we can all use prompts, and we can all get amazing analytics. Mm. But they're all after the fact. And the challenge for us if we wanna make AI-grade decisions in real time-
Ashish Rajan: Mm-hmm ...
Nati Hazut: this is why we made these huge efforts to minimize those AI models to run locally on the endpoint.
Nati Hazut: And by the way, it goes beyond the piece of prevention. Think [00:11:00] about privacy, right? We get it all, especially with the European customers, right? Mm. There's some personal data on the machine of the users. You don't wanna send it to the cloud. Maybe it's personal data. So making the decision locally help you with this.
Nati Hazut: Yeah. Another thing is third-party risk. There's startups, they try to help large enterprises to secure their data, but there is large enterprises, they don't wanna share this data outside of the enterprise.
Ashish Rajan: Yeah.
Nati Hazut: And the last piece that is very interesting, I meet with customers, and they tell me that one of their use cases is they don't want even their internal AI tools to access production data or passwords or keys to their internal tools.
Nati Hazut: But they are using a vendor that use AI- ... to understand this is, you know- Yeah, yeah, yeah ... this is credentials. You see where it's going, right? Yeah, yeah, yeah. So like, you know it's being processed by another AI model- Yeah ... but you're not the owner.
Ashish Rajan: But not my AI,
Nati Hazut: yeah. So we're getting to this paradox that is very interesting.
Nati Hazut: So by being on the endpoint, it really allows you to have those, you know, [00:12:00] benefits of AI without the drawbacks.
Ashish Rajan: The same way you see trade-offs over there, how do you see them manage the, self-hosted endpoint security as a way to use against AI?
Nati Hazut: First of all, I think it's, uh... Obviously, every vendor will say, "Our agent is lightweight," and we're proving it through POVs. In fact, we're today consuming 20% of the resources of the legacy DLP solutions out there. With shared backbone of AI model, you can actually achieve more from your agent while reducing the resources, uh, uh, on the endpoint, and this you know, our customers can test it through a POV with their digital experience tools.
Nati Hazut: And once they get this trust in the system, then they can effortlessly, uh, scale the system. Hmm. As opposed to POVs today that I think that's kind of like a, a sort of a trap. POVs today looks amazing, right? Because the LLMs, right? Mm. So it's not about getting those amazing analytics. It's about how I'm gonna scale it with 50,000 [00:13:00] endpoints, with 100,000 endpoints, right?
Nati Hazut: And even if you're gonna store the AI engine on my premise, what about my tokens and my quotas and the cost of it as well?
Ashish Rajan: Yeah. And do you find that... I, uh, I appreciate the analogy also, because to your point, then you're deploying an individual o- I guess, LLM model on each endpoint as a way.
Ashish Rajan: So do you get to- the conversation of near real time is a lot more achievable than sending it to cloud in the first place.
Nati Hazut: Of course. Of course. And, uh, you know, when you go to the traditional tools and the one that rely on cloud-based classification, there's always a hidden configuration about size of files.
Ashish Rajan: Oh.
Nati Hazut: Right? Like, if you wanna steal files, go big, because if you go big, it's just they won't even try to scan it, so they just let it pass, right?
Ashish Rajan: Oh, I
Nati Hazut: see. You'll find it with all the vendors, I promise you. And the nice part is you got a first mover advantage when you're on the endpoint, because once we see a file being downloaded, no matter how big it is, we're starting to [00:14:00] scan it.
Nati Hazut: And we have data sampling mode that can go through the file and identify some interesting pieces and classify it in advance, so you're also supporting the larger files as well.
Ashish Rajan: So maybe just to add another layer, a lot of-- I mean, obviously, the Hugging Face thing that happened recently has opened up another can, can of worms with the AI agent action versus a user action.
Ashish Rajan: How does-- What's your thinking on attributing the action to a user versus an agent? How does one even distinguish that, and what's the right way to approach it?
Nati Hazut: Yeah, that's, that's a great point, and I think we all, as an industry, we're still learning, right? There's lots of things that are happening right now with this.
Nati Hazut: But, uh, I think first of all, Bold, in terms of, uh, where we see the space, where we kind of like securing it because it's, uh... We're not securing everything, right? Mm. We're securing the, um, the AI adoption by users- Mm-hmm ... uh, and what's happening on the endpoint. [00:15:00] The way we see today with our system, so if we see an AI agent taking a risky action, let's say that an AI agent decided my machine should listen on a TCP port for whatever incoming connection, right?
Nati Hazut: So we're gonna see that the user by the end of the day logged into the system- Yeah ... and on behalf of this user, this action- Mm-hmm ... were executed. Now, there's the question: Was it intentional or not, right? Because when we talk about insider threat, when you identify these type of actions, you're trying to understand the intention, and you're actually enhancing the monitoring on this machine.
Nati Hazut: With AI, I think it's a bit different because the tools are still relatively new. It's about letting the users know that there's this exposure- Hmm ... that they're not aware of. Uh, one of the popular example that we see is the connection of internal MCPs that are kind of like the, the holy grail of the, of the company, the repository, their knowledge base. Connected sometimes, most cases by mistake, with either personal MCPs or public [00:16:00] MCPs. And this is a good example. I don't think there's, in most cases, there's any intentional harm that the user is trying to do here. But it's just like a really bad practice that you should think as an organization how you're blocking it.
Nati Hazut: And when you think about a risk, actually, it's not just about data exfiltration, there's also data corruption, because it can go both ways, right? And this external or personal MCP-
Ashish Rajan: Hmm ...
Nati Hazut: can actually access this data and modify it in some cases. '
Ashish Rajan: Cause I, I'm also cur- the reason I ask that is I'm curious in terms of who do you see do it better, and who do you see it do like, oh, there's a lot more room to improve there?
Nati Hazut: That's a big question. Um- I think there's two types of organizations that we see. We see the heavy regulated one- Mm ... and we see the tech companies.
Ashish Rajan: Yeah.
Nati Hazut: The heavy regulated ones are fairly safe in terms that they have those rough blocks, right? We call them, like, the kitchen knives. It's very, it's very easy to block.
Ashish Rajan: Yeah.
Nati Hazut: But they're suffering from these areas. There's parts [00:17:00] of their organization that have those exceptions, right? They have more, let's say, um, investment, uh, guys or M&A guys that need to communicate with external- Oh, yeah ... um, you know, vendors, et cetera, customers. And for them, those kitchen knives are not good enough to do the surgery, what we call, right?
Nati Hazut: Mm. If they wanna try to adopt some AI tools, the control there is, is limited. The second piece is the tech companies. With the tech companies, for them, I think it's the hardest because they have to be, uh, AI first, but they don't have the controls in place.
Nati Hazut: So in terms of maturity, I think some still think that it's kind of like, you know, blocking some web URLs to block those AI tools.
Nati Hazut: Mm. But I think they're starting to understand it's not enough. The best and great example
Ashish Rajan: is MCPs. Okay.
Nati Hazut: You know, we talk about it and, and one customer, like, uh, last week told me "We're not there yet. We're not, we're not using MCP." So like, [00:18:00] okay, you don't have it managed MCP, but if you're saying that some of your users are already experimenting, you know, some- Yeah, yeah
Nati Hazut: AI agents, you're probably... You know, you're maybe there, but you don't know it, right? Yeah. What I can share that might be helpful for this, for the audience a good practice that I saw for the adoption of the MCP piece is to basically create a list of sanctioned MCPs that you can use.
Ashish Rajan: Yeah.
Nati Hazut: It could be a very limited list because if you're using, let's say, an MCP gateway, you just wanna make sure all of your users are using this MCP gateway, and from there, you can manage it. Yeah. So basically, if you can control and secure the adoption of MCPs on your endpoint with tool like Bold, right?
Nati Hazut: Yeah. This will help you make sure that once they get to the MCP gateway, you're seeing all the traffic, and you're actually managing it effectively.
Ashish Rajan: It's kind of what we were doing with, in a way, threat intelligence, where there's, like, 20,000 alerts you can get in a day. But if you're able to filter the right [00:19:00] ones in the beginning, then you just focus your energy on the right ones- Right
Ashish Rajan: instead of trying to look at all 20,000 of them.
Nati Hazut: Absolutely.
Ashish Rajan: So when I'm building application as security architect am I th- approaching this problem now that if I have something like Bold, which is a language model that's hosted on my laptop- I don't have to worry about things like your CLI exposing an MCP that I don't approve to what you said- Yeah
Ashish Rajan: about sanction MCP.
Nati Hazut: So I think the kind of like high-level goal for us is that when you're handing off a laptop to an employee, right, you just wanna make sure that they're using it the right way.
Nati Hazut: And I think as an industry, we thought about it in a siloed way. One to secure the data, one the actions of the users, one for the applications one for AI now.
Ashish Rajan: Yeah. Uh,
Nati Hazut: but that's, that's a big problem because even if you manage to stitch the, you know, the broader picture by kind of like [00:20:00] correlating some logs, when you come to prevention, when you come to coaching the users, it's impossible. And I think that a good way to think about Bold is just, uh, a tool that breaks these silos and help you understand how users and AI are using the endpoint and identifying when things go wrong, and actually provide controls around it, right?
Nati Hazut: So I think like EDR is one thing, and the way that users and AI are using the endpoint, that's another thing, and this is where we kind of like providing a, a single solution. So when we think about multiple agents on the endpoints, what we're saying is start with your gap, right? If you have a gap with AI, right, Bold could definitely help you solve it.
Nati Hazut: But then when you think about alternatives for your DLP or for your UBA on the endpoint, we can provide you this value as well. Because with AI, you can level up expectations around what a single agent can do. And I think we saw similar thing in places where we saw more [00:21:00] innovation, right? Like with CSPM turning into CNAPP.
Ashish Rajan: Yeah, yeah.
Nati Hazut: So I think it's time to do the same thing with the endpoint.
Ashish Rajan: Oh, interesting. And al- also, I think I was reading maybe one of the blogs about it's zero policies, zero policies to write.
Ashish Rajan: A- it's interesting because obviously a lot of our audience is in a regulated space. The reason why people end up having like a SIEM or like some kind of, sorry, like a a control system is to have the policies to show to an auditor, "Hey, look at these policies that I have created."
Ashish Rajan: But in a user behavior world where we're looking at prevention how do you see your customers kind of manage that conversation about zero policies?
Nati Hazut: That's a great point. So- What we mean when we say zero policy means that if you wanna get the value from the system, if you wanna be able to identify those risky things that are happening on the endpoints, you don't need to set any policy.
Nati Hazut: But we do allow the customers to create those policies. We do allow them to create fully granular [00:22:00] configurable policies. We as, uh, entrepreneurs, we need to be cautious with the pace of innovation and to make it with, sorry, with good correlation with how the market is able to adopt it.
Ashish Rajan: Mm-hmm.
Nati Hazut: Because, it all started with, with the prompts, you know?
Nati Hazut: Systems that everything goes with prompt. Just write me the policy, just say whatever you want. This is a great layer that you wanna provide, but as you said, it doesn't replace the auditing that, y- you know, that you need policies for these purposes. So we allow both.
Ashish Rajan: Yeah.
Nati Hazut: But the idea is that once you set up the system, when we think about traditional systems, they were asking too many questions.
Nati Hazut: What data you care about, uh, how finance are using data, where they're taking this data from, uh, what is the policy, what is the threshold? Answer is, we don't know. Think about the most advanced security architect. They don't know. They're not aware of [00:23:00] any, uh, for each one of the business units, how they're using data.
Nati Hazut: So the idea with Bold was to provide with zero policy, out-of-the-box visibility to what data is stored on these machines, how this data is flowing, how different business units are leveraging data and where they're taking it outside. And also create out-of-the-box alerts for the risky events with zero policies and zero configuration.
Ashish Rajan: Oh,
Nati Hazut: right. But you can always add your own for the audit purpose and-
Ashish Rajan: Of course ...
Nati Hazut: et cetera.
Ashish Rajan: All right. Okay, so your point, so the, it's just understanding a system a bit more better than instead of just bolting policies onto it.
Nati Hazut: Exactly.
Ashish Rajan: I, I got another question in terms of the incident response side of things.
Ashish Rajan: Usually, the reason why these EDRs and all those existed is because we had designed an adjacent team right next to it, so anything, any alert that comes out of it goes to a SOC team. And how do you see that ecosystem change with more AI security and endpoint security coming in? Um, how do you see endpoint security play a role there in whether are we updating our incident response [00:24:00] plans?
Ashish Rajan: 'Cause to your point, it goes back to the attribution piece. Can I-- Am I attributing a user, agent? How do I separate them? What... How do you see that kind of space evolve as endpoint security becomes more mainstream?
Nati Hazut: I think that, uh, uh, one of the things that really stood out when we talked with customers, the more advanced one, but I definitely see it becoming more and more common, is that they're consuming from the system a distilled version of the notification that, uh, that the system can provide, but here's the interesting piece.
Nati Hazut: The advanced customers, they're no longer consuming those alerts directly into their SIEM. Maybe they'll do it for auditing- Mm ... but how they're actually monitoring and doing the triage and, and the respond is through actually connecting our system with MCP along with other systems. And the way they act is they say, if each one of these systems, could be the EDR, could be Bolt, could be any other system, you get a [00:25:00] critical alert from the system, then it will open an investigation, an incident, and will start do the investigation through the different systems and get a very holistic view of what happened here.
Nati Hazut: Uh, so I think this is already changing, and when you see the results, it's, it's kind of like mind-blowing, you know, the, uh, the efficiency and accuracy of those, uh, yeah, of those reports.
Ashish Rajan: So is the definition of how we do inventory of AI ecosystem in our organization evolving as well? And with endpoint security, does that, is that, does that become the new inventory of the ecosystem?
Nati Hazut: So here again, I think it's too early to say-
Ashish Rajan: Mm ...
Nati Hazut: because there's some questions that we as an industry, I don't think we have the final answer for it. For example Eventually, do we see those agents running in the cloud, uh, and users remotely accessing to them? Are they gonna run it partially locally, and for sensitive data they'll do it in the cloud?
Nati Hazut: So I think right now we're [00:26:00] just using those, uh, um, legacy inventory system as an aggregative layer that we can query. Mm. Uh, but it's, it's interesting to see how it's gonna evolve.
Ashish Rajan: Do you f- so maybe for people who are the uninitiated, I guess, 'cause a lot of people at th- at this point in time have an enterprise browser, espe- es- especially in the large organization, regulated space, have an enterprise browser, EDR.
Ashish Rajan: I'm sure they have a lot more other tools as well for the SASE and everything else in there as well. What do you see as with endpoint security as that, uh, starting point? Which one of these is probably something they can switch off if they want to, or, and maybe slowly get away with if they wanted to?
Ashish Rajan: Like, how far do you feel endpoint security is today in terms of prevention that maybe people can consider turning off some of the things that we use for detection? 'Cause we didn't have a prevention method before, but now we're saying actually prevention is possible today. So what do you see as things that ad- uh, endpoint [00:27:00] security gives you as an advantage and maybe perhaps overlaps with other parts of your organization or other parts of security ecosystem?
Nati Hazut: So one thing that, uh, you mentioned earlier is the DSPM. Yeah. I think Bold is a great extension for those DSPMs, right? Even consuming their own labels and providing enforcement on the last mile of the enterprise, which is a huge blind spot as we started this conversation. For the EDR right now again, I, I don't see us playing in this space, and to be honest, I don't feel we have enough urgency in the market to replace those EDRs.
Nati Hazut: I know a lot of companies are, like, trying to revolutionize the EDR. I think it makes sense- ...
Nati Hazut: but I think it's a bit early to market. Mm. We don't see enough- Mm ... of these attacks. I feel like if you have today, uh, you know, an EDR, you feel sort of safe.
Ashish Rajan: Yeah.
Nati Hazut: It's also interesting to see how it's gonna evolve in the next, uh, uh, decade or so, right?
Nati Hazut: After, you know, after what happened with Microsoft and their kernel, they kind of like trying to go on the way of Apple and say kind of like, you [00:28:00] know, "Let's take everyone out of our kernel." Uh, so it's interesting where the EDR will play, uh- Mm ... in the future.
Ashish Rajan: Yeah.
Nati Hazut: But I think definitely the the data layer, the intention layer, the prevention layer, mostly about usage.
Nati Hazut: Mm. Less about a malware piece, but more about the usage, right? So instead of getting one system to identify which applications are being used, and then another system that will identify the accounts that are logged in, and then one for the data and one for the usage- You could have it all with a single platform, and I think it's, it definitely makes sense to expect the market to provide these type of solutions.
Ashish Rajan: Do you find that anyone who's building an AI security program today, what do you see as a good place to start? Is endpoint security the right place to start in the beginning of an AI security program?
Nati Hazut: I think it all goes bas- back to the basics, right? First and foremost, inventory, right? Let's understand what our users are using.
Nati Hazut: That's what I [00:29:00] always recommend, right? Uh, by the way, not j- not just on the endpoint, obviously, I'm biased, but also in the cloud.
Ashish Rajan: Mm.
Nati Hazut: First of all, we need to understand, how's the posture, how it looks like, uh, what tools they're leveraging. Is it on the desktop, on the web? Like, how they're using these tools.
Nati Hazut: That's kind of like the first place I would start. And then the second piece is just helping users or making sure that the users are using the right tools we expect them to use. Because no matter how advanced the tool you'll bring to secure AI in the cloud, to inspect the packets, um, I don't know, whatever your method and what you believe in, if you're not sitting in the right place or your users are just using other channels to take this data outside or to use those AI tools, you're missing the story.
Nati Hazut: And I think a good example of it is people today relying on the network-based solution, they're missing big chunk of the story, and the visibility of the web-based traffic is just getting [00:30:00] narrower more and more. Think about AI tools, desktop apps, or even instant messaging apps today. They're using certificate pinning.
Nati Hazut: If you're not managing the app, you cannot see the traffic because of certificate pinning, and you can't see the actions that the user did before they took this data outside. So you're really missing a lot of the context- Mm ... uh, by being there. So same thing with AI.
Nati Hazut: You wanna have good advanced mechanism to control it, but first you wanna make sure you're actually sitting in the right place, and you're seeing the data you're expecting to see.
Ashish Rajan: We're doing this thing called, uh, you laugh, you lose. Uh- Okay ... it's a, uh, well, I guess the context is I say a joke, and if you laugh, you lose. But if you say a joke, if I laugh, I lose. We've been, uh, giving it best of one, best of three. I can start first, uh, just to give you a heads up if you like.
Nati Hazut: Yeah.
Ashish Rajan: Uh, the goal of the game is s- simple. You have to try not laugh, but it... You can maintain a poker face the entire time if you like, uh, but we'll see. Uh, so are you okay with that?
Nati Hazut: Same for [00:31:00] me.
Ashish Rajan: Yeah. Same for me. I'm like, "Oh my God, I did not realize"- ... why is... Anyway. All right. Here's, here's my joke. Um, and you have five seconds to react, right?
Ashish Rajan: You can choose however you like. My, my joke here is I was giving endpoint security quite a bit of thought in terms of what does it mean in the modern world. And I came across this quote, which made me realize, oh, this is what endpoint security is: Modern endpoint security isn't jealous. It just asks, "Who's ChatGPT, and why have you been spending all day with it?"
Ashish Rajan: Dude, that was good. That was good. You're good. All right. Okay. Okay. Well, let- let's hear yours then.
Nati Hazut: Okay. Um, my question is more in the data classification space.
Ashish Rajan: Mm-hmm.
Nati Hazut: So why do you think regex is so good in Tinder?
Ashish Rajan: Why is it good in Tinder?
Nati Hazut: Because it match with everyone.
Ashish Rajan: Okay, fair. That was a good one.
Ashish Rajan: That was, that was... Okay, I lose that one. No, that was, that was good. [00:32:00] Did, did you come up with that? Was that original? That's a really, really good one, man. Oh, okay. I'm gonna use that someday. I mean, maybe you spend too much time on data security, so that was good. That was good. But you clearly won.
Ashish Rajan: Um, where can people find more about Bold and connect with you guys and know more about the work you guys are doing?
Nati Hazut: Yeah. Of course, uh, on our website. So, you know, if you wanna learn more- Yeah be happy to. Just, you know, reach out, and we'll be happy to provide more information. And,
Ashish Rajan: uh, are you g- are you on LinkedIn as well, so I can put your LinkedIn link as well- Of course ... for people to connect with you?
Nati Hazut: Of course.
Ashish Rajan: Perfect. I'll, uh, I'll put your LinkedIn link for people to connect with you and talk more about endpoint security.
Ashish Rajan: But dude, thank you so much for coming on the show. Thank you. It was a pleasure. I really enjoyed our conversation. I... Now I realize why data security people would love Tinder as a, as a place to be. But thanks
Nati Hazut: so much, man. Wonderful.
Ashish Rajan: Yeah. Thank you so much. Thank you everyone for tuning in as well. Thank you for listening or watching this episode of Cloud Security Podcast.
Ashish Rajan: This was brought to you by TechRiot.io. If you are enjoying episodes on cloud security, you can find more episodes like these on CloudSecurityPodcast.tv, our website, or on social media platforms like YouTube, [00:33:00] LinkedIn, and Apple, Spotify. In case you are interested in learning about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security.
Ashish Rajan: Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at Cloud Security Podcast. You can check that out on CloudSecurityNewsletter.com. I'll see you next episode.
Peace.


.png)


.png)














