Episode 917 ·
How to Build Defense for AI Cyber Attack Waves with Ariful Huq, Co-Founder at Exaforce
AI is flooding the cybersecurity space. So, how do we fight back?
Today, we're talking to Ariful Huq, co-founder at Exaforce. We discuss how to build AI defense systems against AI-powered attack waves, why 98% of security alerts are false positives, and how to turn a team of three analysts into a team of ten using AI agents.
All of this right here, right now, on the Modern CTO Podcast!
To learn more about Exaforce, check out their website here.
About Ariful Huq
Ariful Huq is the cofounder of Exaforce, a platform that helps organizations build enterprise-grade security operations centers using AI agents. Prior to Exaforce, Ariful was at Palo Alto Networks following the acquisition of his previous startup in cloud security. With 17 years of product leadership experience, he specializes in leveraging AI to solve complex cybersecurity challenges.
About Exaforce
At Exaforce, we are on a mission to 10x the productivity and efficacy of security and operations (SOC) teams using our transformative multi-model AI engine. Our Agentic SOC Platform combines AI agents (“Exabots”) with advanced data exploration to deliver real-time insights, proactive detection and response, in-depth investigations, and automated workflows. Backed by Khosla Ventures, Mayfield, Thomvest Ventures, Touring Capital, and others, Exaforce helps SOC teams respond to threats and breaches faster, with higher precision, greater consistency, and at lower total costs—redefining how SOC teams function.
Transcript
(Intro Narrator at 00:00:00) Today, we're talking to R.F. Huq, co-founder at Exaforce, about fighting AI cyber attack waves with AI defense. And you're listening to Joel Beasley, Modern CTO.
(Joel Beasley at 00:00:16) So I was particularly excited about this episode because the intended title for it is "How to Build Defense for AI Attack Waves." What is that? That's like some really good spicy stuff. Did you use Grok for that? Like you just quit hollerin'. So what is it that you guys actually do then? Like, what's the boring version of what you guys do?
(R.F. Huq at 00:00:35) Oh yeah, boring version. We're building a combination of platform and services that can help organizations of all sizes. Think about high growth organizations that are startups that start to care about security, as well as mid enterprises and larger organizations, build enterprise grade SOC. Essentially, think about how can you build the best SOC technology out there for everybody, no matter where you are in your journey, whether you're starting from scratch or you've got existing technology. That's how we think about it, and that's what we're helping our customers with.
(Joel Beasley at 00:01:16) What's their chief complaint? What's like the main reason people are handing you money? You solve what problem?
(R.F. Huq at 00:01:21) Yeah, so it really depends where you are in that journey, and it's kind of why I frame it in that context. So think about a high growth startup, late stage funded, just starting to sell to larger enterprises, B2B play. What we find often, small security organization, they are starting to get a lot of pressure around customers asking them questions around, do you have 24/7 monitoring? Do you have an incident response plan in place? Making sure your data is safe, those kinds of things. And typically in this type of organization, the head of security starts to think about, oh, I have to put an operations platform in place. Typically, think about a SIEM, maybe hire detection engineering, some sort of analyst, they may be looking at the alerts. Putting that all together in earnest can take nine months, if not more. And so for these types of organizations, the head of security is thinking, how can I augment my small team with AI so I can leverage my existing team with a platform that's augmented with AI that can solve all of these problems for me? Build my SOC from scratch in days, not months. So that's for that type of organization. And if we think about mid enterprises, they may have a SOC team already. It's a more complex environment. They've been as a company, they've been around for much longer, so they have these processes in place. But the challenge there becomes, do I keep hiring SOC analysts as my number of alerts keep increasing? Because the threat surface keeps increasing, number of attacks keep increasing. So do I just keep increasing the number of SOC analysts because they're overburdened? Too many alerts coming in, not all of them are being looked at, not all of them are being investigated. And so for those types of organizations, it becomes, how can we make your SOC analysts superhumans? How can we essentially make your team of three a team of 10 or team of 15? So that's how we're thinking about it. A non-linear approach for you to solve your security operations needs as you scale your organization.
(Joel Beasley at 00:03:34) You must be a co-founder. Are you a co-founder?
(R.F. Huq at 00:03:42) I am.
(Joel Beasley at 00:03:42) You understand the problem so clearly and so directly so early in the interview. Like you immediately get, here's how we bring value to which type of customer, and that's the first thing coming out of your mouth. I'm like, this is co-founder quality person. That's what it says. You know, if I didn't have that right, then we would not be in a good position.
(R.F. Huq at 00:04:00) There would be no more.
(Joel Beasley at 00:04:01) Checks. Yeah, if you don't get that right, nothing else can exist.
(R.F. Huq at 00:04:06) That's correct. That's correct.
(Joel Beasley at 00:04:08) So those are your two main areas of customer base. High growth, late stage funded that are trying to build a SOC in days, not months. And mid enterprises who are just hot. Like all the AI threats are coming at them. So the bad guys have increased their productivity a hundredfold. But to respond to that activity increase, they're having to hire real people, real salaries, real money. And so it's almost unfair. It's like there's a weird parallel happening right now in the medical world because my brother and mom are physicians, where all the insurance companies have adopted the AI to constantly send requests to all the doctors, flooding and multiplying their request that they have to respond manual responses to. They haven't caught up yet to get the AI to respond back. So they're now building tools in the medical space to get the AIs to respond back. So maybe that's a little, you guys are experiencing that, but like on an attack threat situation.
(R.F. Huq at 00:05:05) There's a lot of parallels. Like, I mean, actually, now that you bring that up, my wife is actually in the biomedical field, and they're using AI to do early cancer detection. So using, you know, essentially some blood, not just a single drop, a little bit more than that, but they're using a lot of different types of signals, biomarkers that they can use. So yeah, this technology is going to be valuable way beyond what we're doing.
(Joel Beasley at 00:05:33) I can't wait till we increase our capacity to decode DNA quickly. I think there's going to be so many answers eventually when we get to that point. It's like you're kind of not feeling well. One drop of blood, they decode your DNA almost instantly, and they can see exactly what. I think there's way more data in there than we realize.
(R.F. Huq at 00:05:50) Yeah. And I think the key thing is how do you make it cheap enough so everybody can benefit from it? It's not that just the upper echelons of society can benefit from something like that.
(Joel Beasley at 00:06:01) So for people who don't understand, let's help. There's a wide range of listeners. People don't understand exactly what a SOC is and why does it matter. What's the answer for that?
(R.F. Huq at 00:06:11) Yeah. Good question. And, you know, I think I'll give you kind of like the traditional version of what security operations is and then maybe a more modern take. Like how I see modern enterprises kind of thinking about security operations. So if you think about, again, going to the mid enterprises, it's typically you have vertical functions. People own specific things. So if you think about somebody that owns security operations, the task at hand is, how do we centralize alerts that are coming in from various tooling and technologies that you have in place? And in security, I'm sure you've spoken to a lot of security founders and people in security. Everybody will tell you there's no dearth of tooling. There's tooling for everything. But there's a reason why it exists, because it's so vast. You've got endpoint technology. You've got email. You've got cloud. You've got SaaS. You've got network. All of these technologies have some sort of monitoring, and so they're producing data. They're producing alerts. And typically what's happening is all of this information is coming into a security operation center where traditionally you have humans kind of go through this information. There's some level of enrichment, some level of prioritization that's happening, but you can think a lot of tasks are still human driven. Somebody looks at a ticket, tries to figure out, okay, what was the root cause behind it? Maybe there's some enrichments around it, some questions are being answered, most often not. And then they're having to kind of look at additional data, maybe call somebody or Slack somebody, ask questions, and go through this process, repeatedly. And if you think about more modern organizations, I would say companies born in the last five years, this function is not just siloed. It's not just a dedicated individual. What I see happening is, it's kind of like full stack security. So you've got the security engineers that are doing the proactive stuff. They're also starting to look at this because it's kind of like you don't have siloed functionality anymore. So I think that's sort of how I frame this concept of a SOC. Like you could have a dedicated, but I also see small teams where, you know, they're doing everything. They're doing the operations, plus they're doing the engineering.
(Joel Beasley at 00:08:34) Yeah, that makes sense. It's like in the traditional ones, it's like maybe almost serial or like isolated into the silo, and then it's more like a parallel functionality where everyone's just kind of trying to make it happen in the modern SOC space.
(R.F. Huq at 00:08:47) Yeah.
(Joel Beasley at 00:08:47) Yeah. No, that makes complete sense, especially with how everything's been evolving. Now in cybersecurity, is there, are these like, let's say I am a company and I do have a ton of money to throw at it, and I don't mind hiring a bunch of analysts to keep up with it because I'm mid market enterprise. I'm just going to do that. Is there a shortage of talent, or can I just pull that off? Is it available?
(R.F. Huq at 00:09:11) Yeah, there's certainly a shortage of talent and skill set. I think it's a combination of trying to hire the right people and also the right type of skill set. Because, again, as I mentioned, you know, just like we talked about earlier, security is so vast. You've got five different domains. And so having expertise in every single domain is not possible for you to have. You know, it's almost like the unicorn hire, like somebody that knows everything and is able to have a deep domain of expertise in every single area. So, yeah, it's a combination of, I would say, talent shortage as well as just the skills that you need to have in being able to look at all these different systems. Because they are fairly complicated. Like even if you think about public cloud infrastructure, AWS and GCP and Azure are very different. Think about SaaS, like, you know, GitHub versus Snowflake. All of these are critical services that people are building on, and having a deep understanding of every single one of them is very tough.
(Joel Beasley at 00:10:13) Yeah. You can't build a business on the unicorn hire by definition. That's ridiculous. Now, AI and SOC, the main thing here is prioritize and look, dude. Just so you know, my background is software engineering, but my expertise, the area I went a mile deep in, was business logic. Whether it's, you know, routing stuff for transactions or real estate or whatever the business people wanted to happen, I would focus on that. So I don't have a deep understanding of security. But I am curious, like, when AI is tying to SOC, is it mostly in the conversation of managing large volumes of alerts or no?
(R.F. Huq at 00:10:53) Yeah. I think it's, again, if you go back to the first question you'd asked, like, you know, what are the pain points? So if you think about it from the perspective of a larger organization that has complex systems, many of them, it is going to be, one of the big pain points is going to be the number of alerts that are coming in and the amount of time somebody has to spend in triaging these alerts. So there's this concept of an alert budget. So, you know, number of alerts coming in versus how many can I triage in a given day, and that gives you the number of headcount you need. And, you know, you have to make really important prioritization calls because you are not going to be able to triage every single thing that comes in. So now you have to think about, okay, I only look at the criticals and highs, and now I have to make a business decision from a risk perspective. I don't look at anything that's below a high. I avoid the mediums and lows. So yes, that's certainly an important decision and a challenge that a lot of organizations run into. And leveraging AI to do that repetitive work that a human will end up doing is certainly going to relieve the burden for that type of organization. And then if you think about the smaller organization, it's really about moving fast. How can I move as fast as possible to meet the needs of my business and augment my existing team with technology and services, AI-led technology and services, that can make them function like I have a security operations center without hiring dedicated people? So I think it really boils down to where you are in that journey. It could be I've just got too much, I can't throw enough people at it, or I have nothing and I just need to start putting things together as fast as possible.
(Joel Beasley at 00:12:46) What's the false positive rate on all these alerts?
(R.F. Huq at 00:12:50) Oh, man. It's really, really high. It's like 98% plus. That's the false positives. And, you know, it's, if you think about a lot of things that happen in organizations related to alerts, you know, sometimes it's like humans being humans, developers being developers, because at the end of the day, how an attacker is going to potentially behave and the patterns, some of the things that they may end up doing, may be normal things in organizations. You know, if you're writing a detection like, oh, you know, somebody may be listing S3 buckets or describing EC2 instances because that's sort of reconnaissance-like behavior, you know, there's a lot of people that are going to be doing that type of thing. But the important thing is under what context was that action taken? That person, you know, what location did it happen? Do other people in the organization perform this type of behavior? What user agent was used? There's a lot of context that you can bring in, and, you know, those are the questions that somebody's answering. Like all the things that I just read aloud to you, that's what somebody is trying to gather from writing complex queries across systems, putting it all together in their head and rationalizing it. And then they may even not have the answer. So they may just send a Slack message or Teams and ask that individual, like, hey, was it you that performed this function? Why did you do it? And now they have to wait for that person. So all of those things are things that they have to do to figure out, you know, why this is something that should be happening or shouldn't be happening.
(Joel Beasley at 00:14:28) Oh, yeah. Dude, one time, I don't know if this will make it into the show, but we were launching this software and we thought we were under attack. Like we thought our systems were like our database was getting attacked. Turns out, long story short, we use this, it was a Ruby project. We use this gem called Faker to help, you know, create fake data for all of our testing suite. And a line just made it into production to turn on Faker.
(R.F. Huq at 00:14:55) So you thought you were being DDoSed, but it was just like super data.
(Joel Beasley at 00:14:57) Attack. It took us like an hour to figure it out. We're like, oh, no. This one line of code where it shouldn't have been loaded in production, it got there. So, yeah, like weird stuff like that can happen.
(R.F. Huq at 00:15:11) And yeah, just take that example. Think about it from even your perspective as a developer or even as security person. How would you go troubleshoot that? Like it's a combination of understanding, okay, do I have some sort of WAF logs?
(R.F. Huck at 00:15:22) Do I have some application logs? I have to put that together. I also put together the fact that that was a change that was made in the environment at that time, right? So there's a lot of context building that people have to do, right, in answering that question.
(R.F. Huck at 00:15:36) Yeah.
(Joel Beasley at 00:15:37) Do you guys do, like, static code analysis? Are you actually looking at code, or do you just deal with errors when they? Are you proactively going and finding them in code bases? How does that work?
(R.F. Huck at 00:15:46) No, we're not doing static code analysis. There's enough technology out there that does that for you. Like, there's SAST and a bunch of tools like SCA that will help you do that sort of analysis. We are taking in mostly what you can consider as runtime detection. So it's something that's happening during runtime, right?
(R.F. Huck at 00:16:04) We do proactive analysis as well. It's something that actually a lot of our smaller organizations benefit from. Just simple example, we onboard your Google Workspace, your AWS cloud environment, maybe GitHub and others, and there's like good hygiene that should be in place. Like, just, how many admins do you have, and are they all using their permissions, and do you have MFA enabled? You know, just like, do you have branch protection enabled? And, you know, just stuff like that, right? Like, good hygiene that every organization should have that would prevent a potential attack from happening, right?
(R.F. Huck at 00:16:39) We have that in place as well. So those are things that we do. In larger organizations, you know, there's enough tooling out there that they will leverage for that function specifically, but smaller organizations benefit from that.
(Joel Beasley at 00:16:52) Yeah.
(Joel Beasley at 00:16:53) And then so once you detect something's happening, how do you remediate it?
(R.F. Huck at 00:16:58) Yeah. Good question. You know, remediation can be complicated. So there's aspects of remediation you can automate. There's aspects that you want a human in the loop.
(R.F. Huck at 00:17:10) So simple example, low hanging fruit. We already talked about it. One of the first things that you want to do if it's, like, say, there's an anomaly, you know, anonymous login or some sort of behavior, reaching out to an individual, asking that individual a question, recording that as input and making a decision on that, that's completely automated. You know, many of our customers are doing that today. If you want to take actions such as, like, reset a password, reset a session, that's stuff that, you know, people feel very comfortable with automating.
(R.F. Huck at 00:17:41) And we have this concept of an automation agent. Like, it's almost like an agent you can build in our platform, right? It can be bespoke to things that, you know, your organization needs. We have sort of like a template of things that we already have, like the most common things that you want to automate, like I talked about reset password, reset a session, isolated instance, those sorts of things.
(R.F. Huck at 00:18:04) Those are things, actions that you can leverage using our automation agents, and they can be done automatically, right, for you. So depending on the alert, the action can be actually taken automatically. What we find is if the action is somewhat disruptive, like isolated an instance, whether it be your endpoint or cloud, there's typically a human involved in triggering that action, right? Because you don't want to just isolate for, you know, something that is a potentially false positive, right?
(R.F. Huck at 00:18:31) But, yeah, we have this capability where these automation agents can be built within the platform. They're done through prompting. Like, you literally layer a prompt that says, hey, if I see this thing happen, go get additional information, and then go take this action, right? The actions themselves require integrations with different systems, but, yeah, we can do that.
(Joel Beasley at 00:18:52) Where were you? What were you doing when you and your cofounder realized this is a problem? It's a big deal to start a company. I've done it a couple times. It's always a huge undertaking. So the problem has to be really obvious. It has to be very clear that we've got a good idea for the hook, for the solution. We've definitely proven the problem before you actually, you know, get going. Where were you, and when did you realize this with your cofounder?
(R.F. Huck at 00:19:18) Yeah. I mean, we started the company in 2023, and we, you know, were ideating various things for quite some time. In fact, even before we were thinking about infrastructure and cyber, we were actually thinking about the crypto space because 2022, the crypto space was big. There were some ideas we were thinking about there. But in 2023, there was this moment, right? ChatGPT came in, and we knew to build a company, you need a technology disruption and you need a business disruption. You need tailwinds. There has to be a reason why you're going to be successful. There has to be a reason why people should look at you, right?
(R.F. Huck at 00:19:52) And so when you have a big enough technology disruption, like what happened in 2023 when ChatGPT came in, we're like, we have to use this as a tailwind, right? This has to be something that it's going to disrupt every single industry, every vertical, right? And our vision was that the biggest impact is going to be productivity, efficacy of human beings across any vertical. Like, you mentioned an example of, I think, one of your relatives leveraging AI. Like, think about coding. Like, you know, you're a developer. Like, the things that you can do with Claude, Codex, and all of these technologies is unbelievable.
(R.F. Huck at 00:20:37) Things that it allows me to do as a product person, I would've never imagined doing, like, you know, ten years ago, right? But come back to our strengths, our strengths was infrastructure and security. We're like, how can we, where is this most applicable? And so if you think about productivity efficacy, you want to target an area where there's large human capital, because it's easy to prove value. And so we thought, hey, like, you know, think about security operations. That's where human capital is largest. It makes sense to essentially leverage this technology in that area to increase productivity, right?
(R.F. Huck at 00:21:20) And that was the vision from the start, and that's really still the vision. And fast forward, what we, you know, what we from that vision, what came out was, you know, task-specific agents to perform functions in SOC, and we have a data platform that we built as well. Yeah. So that's kind of, like, you know, the thesis of and how we started. Yeah.
(Joel Beasley at 00:21:38) So did you start, like, you have this idea that you want the target large human capital area very, very clearly. I understand that. But from security, how did you then go about, did you already have backgrounds in security? Did you already have a friend who, like, how did you validate it out from there?
(R.F. Huck at 00:21:57) Yeah. Yeah. It's a good question. And and I think it's super critical in going through that validation phase. So, yeah, myself, I came from a cyber background. I was at Palo Alto Networks prior to starting this company.
(Joel Beasley at 00:22:10) Oh, great. You like them.
(R.F. Huck at 00:22:11) Yeah. Yeah. Yeah. You know, it's a very well recognized name in the cyber space, obviously. Yeah. So I was at Palo Alto Networks, and I actually ended up there because of an acquisition of my last startup, which was also in cloud security.
(R.F. Huck at 00:22:20) So for me, I knew the pain points, and, you know, one of the things that I've always, being in cyber, I always felt like there's enough tools. Everybody has a tool for something, right? So what I was always thinking about is if I want to go tackle this problem, it shouldn't just be a tool that does something. It should actually help humans that are consuming all these tools. And that's sort of, like, where I was thinking to begin with.
(R.F. Huck at 00:22:47) And I partnered with a number of folks that I know, Ankur, Marco. They come from infrastructure background. They built, they actually had another company, Volterra. They sold it to F5. And so we were kind of noodling on these ideas, and we felt like, you know, as soon as this ChatGPT thing happened, we were like, this has a huge impact.
(R.F. Huck at 00:23:06) One of the things we realized is we have to stick to our domain. And that goes through, you know, coming back to the critical question that you asked, how do you validate? If you stick to your domain of expertise, you have a network. And within that network, you start to ask questions, you start to get feedback from people around problem statements, those sorts of things, right?
(R.F. Huck at 00:23:30) And, yeah, so I think, you know, for us, we, even before we raised money, we did a ton of validation amongst our network, talking to individuals in security operations. Some of my cofounders were actually running a SOC as well, and so they certainly validated this problem because at their last company at F5, they saw it happening by themselves. We built kind of like an advisory board where we just, you know, get a lot of good feedback from lots of friends and people we knew in the industry, and so that's kind of how we did the initial validation.
(Joel Beasley at 00:24:11) I love it. I love it. It's like, it's so beautiful to watch it get done right. You know? Oh, trust me.
(Joel Beasley at 00:24:19) The story.
(Joel Beasley at 00:24:20) It's, it, I, maybe I may have sounded, made it sound easy, but it is,
(R.F. Huck at 00:24:25) uh, it's like, you know, it's like fog, and you're trying to make sure you're heading in a good direction, right? Like, that's the idea. Like, you can never get complete clarity at that phase of your company, right? You're literally driving through a fog. And you're just trying to make sure I got to just make sure I directionally land in the right way, right? So it's hard, but I'm glad we're past that and, you know, this is a market now, right?
(Joel Beasley at 00:24:54) Yeah. I like it because I've, you know, I've done the create a business and sell it. I've done that a couple times. And every time was bigger than the last, right? And I've got a couple friends too that have had exits, and they just kind of, like, they're just done. Like, they're not, it's, they're some of the smartest engineers that I know, like, the most brilliant people, and they're just, like, hanging out playing disc golf and stuff. And I'm like, what a waste. I was like, you finally, like, the way you got there is you were scrapping so hard. You were doing anything you could possibly do to get it going, and then you get it going.
(Joel Beasley at 00:25:29) And it's like, now we could do something bigger. That's my mindset. And then a lot
(R.F. Huck at 00:25:33) of a lot of the other people
(Joel Beasley at 00:25:34) I know, they're just like, I'm good. And and so I love it when I hear that, several people that have done successful companies or have had some exits like to some degree, the experience of building and selling get together and they want to take all that knowledge and leverage it into something. I guess when I was saying you did it right, that's what I'm kind of referring to more than anything, is the fact that you had some success and you continued, and you're like, what more value can we bring to the marketplace? How can we do it even smarter than we did it before? I love it.
(R.F. Huck at 00:26:06) Well, that's what keeps the industry growing. It is actually, you know, cyber is actually one of the fastest growing industries. For this reason, I think cyber founders somehow solve one problem, you know, whatever the exit may be, you're like, I want to solve the next big problem, right? So it's, I guess it's an industry thing. Yeah.
(Joel Beasley at 00:26:24) I love it, R.F. You're my people, man. We're we're officially friends. So does anybody ever give you, like, the, ah, it's just LLMs slapped on existing tools situation? Do you have to battle that at all in calls?
(R.F. Huck at 00:26:35) Oh, trust me. Like, we've certainly had to do that quite a bit. We did a ton of testing ourselves initially, just learning lessons, right? You know, when we started building this company, we're like, okay. Let's leverage the frontier models, take detections from a bunch of sources, and see what we can do with, you know, some good prompting with these technologies.
(R.F. Huck at 00:27:20) And what we realized is to get predictable and precise outcomes, it's very difficult to just leverage an LLM wrapper, right? Build an LLM wrapper on top of, you know, third-party sources that you're ingesting. What we found is, you know, and this is true to AI in general, right? You have to go back to data. You have to have high quality data, right?
(R.F. Huck at 00:27:35) And so, you know, when we kind of did our initial prototyping, we realized that we have to build a strong data foundation. Go back to first principles, so get the right data into the platform, whether it be, you know, events, configurations, identities, code context, putting it all together, building relationships. Because what we've realized is if the data is easily understandable by humans, they can certainly be understandable by AI agents, and they can do it all day long, right? They can do it repetitively, and they can do it with high precision all day long, right?
(R.F. Huck at 00:28:03) And so that was, I think that is one of our core differentiators. And it took us a good amount of time to get it right, because it is not a simple problem to solve, right? And we, you know, within the first in our first year, before we built our first AI agent, this is what we were doing. We were putting data together, building a scalable data pipeline, and then we started to think about, like, okay. Now we layer on the AI agents to do the tasks that humans end up doing. So it is a big differentiator, I believe, in the approach that we've taken. Yeah.
(Joel Beasley at 00:28:37) Did you, by chance, catch that Ben Affleck, Joe Rogan interview a couple, when did you?
(R.F. Huck at 00:28:44) Yeah.
(Joel Beasley at 00:28:46) So he's, like, very knowledgeable about AI, apparently.
(R.F. Huck at 00:28:49) Oh, really?
(Joel Beasley at 00:28:49) Yeah. He was, like, crumbling his new movie. Yeah. Ben Affleck. Yeah. And then he just started, like, giving all of this. Now I was, like, wow. You know? I was, like, this is good. Now I think he got, I think he's a very smart guy, and I was surprised too because you just don't typically think of these strong, like, actor, you know, handsome man actor guys as, like, you know, incredibly brilliant with technology because he never played any roles really that, you know?
(Joel Beasley at 00:29:15) Anyways, so he, I'm on his team. I'm on his side as he's on his rant. And then he completely fell off the edge and lost me at this one point you kind of alluded to. So he was talking about, like, scripts and script writing, how AI is great for like if you want to bounce an idea off of it like the scene potentially happen. He goes, but it will never produce like a script with heart. Like it'll never capture that. And I was like hold on. I was like, maybe he's just newer to AI. Maybe he's just a very smart guy who's been researching it recently. Someone who's been in the field for twenty years and watched this progress, you could tell the base principles are if a human can do it, you can teach the AI to do it. It's just whether or not someone sat down and said, there's enough money here. There's enough tension in the marketplace here. I'm going to spend a bunch of time to create specialized models to do this one thing a human can do.
(Joel Beasley at 00:30:15) There will absolutely be script producing models that are dedicated for that. That will produce it with all the heart and soul of a human. And I noticed that there are some incredibly brilliant people, Ben Affleck aside, even that I talk to on a day to day basis like this in technology, who will sit here and understand that concept and then still say, well, like, it'll never be able to write a poem like this or it'll, and it's, it's hard for me to, like, kind of piece that together. Do you come across that at all?
(R.F. Huck at 00:30:34) Yeah. And I think, okay, so there's some truth to it can never be 100%, but can it be 80%? Can it be 90%? And then, to Ben Affleck's point, you give the 10% of the heart.
(R.F. Huck at 00:30:47) It's done a good amount of work for you. And I kind of see it in everything that I do today, right? Yeah. To be honest, I was just telling my kids the other day, I have a really good coworker. Any question I want, I just go to Claude and I start asking Claude questions and we riff on it. If I want to build a presentation, I want to think about some ideas, we riff on it. And it really makes you smarter because you think about things differently, because you have somebody to actually have a conversation with, right? And obviously, beyond cyber, this is applicable in every industry, and to Ben's point, right?
(R.F. Huck at 00:31:24) Yeah. You can probably write a script, and maybe you're not happy with that one area, but you got there much faster, and now it gives you the opportunity to kind of really make it yours. Right?
(Joel Beasley at 00:31:35) I love how optimistic you are. No, no. It really is great because so many people will point to, like, the brain studies. That's a popular one across pop culture right now, just pointing to, oh, if the person uses AI, their brain atrophies.
(Joel Beasley at 00:31:51) And it's like, well, I can understand that there's truth to that. I can 100% see it. But there are people that'll use this tool to make their brains stronger. You know?
(R.F. Huck at 00:32:05) Yeah. And I think, look, there's fundamentals. Right? Like, I was just—you know, again, I'll bring my kids in.
(R.F. Huck at 00:32:11) Actually, this is their parent-teacher conference. So I think one of the parents was like, hey, you know, should we let our kids use ChatGPT for, you know, a lot of things? And I forget the exact topic that was brought up, but I think there's foundational things that every kid should understand. Language, grammar, before you even get to ChatGPT.
(R.F. Huck at 00:32:34) If you just go to ChatGPT to actually just write an essay for you, you're not learning, right? You need to know the foundational aspects of essay writing, the grammar. And then as you grow older, if you want to leverage this technology to make it much better, absolutely. And I see that parallel in every aspect, like, you know, as humans. You have to know the foundations.
(R.F. Huck at 00:32:53) Like, you can't use a calculator for everything. You still have to know some of the math behind it, right? So, yeah.
(Joel Beasley at 00:33:00) Yeah. I made the mistake. I told my kids—I've got three under 10—I said, you only have to go to school until you learn to read, write, and do basic mathematics.
(Joel Beasley at 00:33:10) Then we can get you into, like, self-education. Well, they were pretty smart. They were pretty fast.
(R.F. Huck at 00:33:15) Yeah.
(Joel Beasley at 00:33:15) Yeah. I'm like, hold on a second. They're catching up pretty quick. But, yeah, my goal as a parent—and how old are your kids?
(R.F. Huck at 00:33:22) I have a 15 and a 13-year-old.
(Joel Beasley at 00:33:24) Okay. So they already have those softwares. They're already shipped with that. So once they get to the point, and you tell me because you're ahead of me, right? Can you just point them in, like, an area of their interest and then say, hey, go, like—in, you know, essentially finance, like, help them buy the tools or whatever they need to do to explore?
(Joel Beasley at 00:33:44) Like, how are you approaching it right now with their technology? And then, I'll say it in better words: my foundational philosophy as it stands today is to introduce them to several things, find what they're naturally gravitating towards, and then make that easier for them so that they become a specialist and, like, learn one specific thing. Is that happening at all with you?
(R.F. Huck at 00:34:04) Yeah. I mean, I think that's the way I've been approaching it. I think on the AI side, I don't think they're allowed to use a whole lot of it in school. But at home, in just general things that I see them do, like one of my daughters is very good at drawing and, you know, she was just scribbling and doing things by hand. And so I finally got her—you can get these notepads that are specific for drawing.
(R.F. Huck at 00:34:32) And it just takes them to the next level. Like, she got the foundations of, you know, art by doing it by hand, and now I've given her kind of this notepad that she can do it digitally, right? And it just, like, elevated her that much. But I don't think if I just gave her that notepad day one, I don't think it would work. Like, she got the foundations right by practicing by herself, and now she can actually elevate it with digital art.
(R.F. Huck at 00:35:00) It's the same way. I think same principles apply, right? You've got to get the foundations right, and then, you know, you use technology to just elevate it.
(Joel Beasley at 00:35:10) You're a big fan of Claude? Do you use Claude a lot in your personal life?
(R.F. Huck at 00:35:13) I do. I find it incredibly valuable in the work that I do. Incredibly valuable even in, obviously as you're building a company, you need to think about messaging, you need to think about how do you even, you know, build great slide decks. It's actually just recently, I used it to build some slide decks and just, like, not the content itself, but structure the slide. Like, I'm thinking about these things.
(R.F. Huck at 00:35:40) I want to put it all together. Can you give me some examples? And it was, you know, it came back with some decent examples. But yeah, I use it in every aspect of work. I'm not a big fan of—like, I haven't used it a whole lot in my personal life, like, oh, planning a vacation, that kind of stuff.
(R.F. Huck at 00:35:56) But, yeah, on the work side, I use it quite heavily. And I think as a product person, it's just giving me, you know, superpowers, like, you know, just understanding APIs. And before I ask my team to do integrations, like, I understand the APIs, I understand the schema, I understand what needs to be done, and so I can point them in the right direction, and they can move really fast. As an example, like, I was setting up a demo for a customer, and I wanted to simulate some potential—I think in this case, I was simulating session hijacking, like, sending a phishing email and somebody clicking on a URL, and I hijacked the session. You can actually build these systems very, very quickly now.
(R.F. Huck at 00:36:37) It's kind of crazy. But, yeah, it's so powerful.
(Joel Beasley at 00:36:41) I use it a lot in my personal life. I use it to help see different perspectives. So, like, let's say you and I were having a conflict or we were working on something that was particularly sensitive, right, where there could be potential conflict or something, or we were doing a business deal. Whatever it is, I can use the AI to see different perspectives.
(Joel Beasley at 00:37:02) I'll tell it, I'll say, like, look, this is what's going on. Here's the background. Here's how I see it.
(Joel Beasley at 00:37:07) How might they be seeing it? Is there a third way to look at it? And that'll just—I use it to give me perspective, I guess, is what I'm trying to say.
(R.F. Huck at 00:37:14) Yeah. I think that is the biggest superpower. Right? It's somebody to converse with, somebody to give you ideas that you may not have thought about. Right? Just the level of sort of analytical thinking and aptitude for humans is just going to increase by leveraging this technology. Yeah.
(Joel Beasley at 00:37:32) Yeah. And I can be verbose. It doesn't get annoyed. It's actually helped me become a better communicator because I learned that if you tell it, like, far too much—you get—if you really reduce, refine, repeat is what I—the three R's. I've made it up for myself to survive in life.
(Joel Beasley at 00:37:48) But I'm always trying to reduce, refine, repeat, and then give it the most basic amount of information, and then it gives me the best result.
(R.F. Huck at 00:37:56) Yeah. Yeah. Yeah. Totally makes sense.
(Joel Beasley at 00:37:59) This Claude Code tool was part of, like, the first AI-orchestrated cyber attack. Tell me about it.
(R.F. Huck at 00:38:06) Yeah. I mean, it's the first discovered. We don't know how many others are running. But yeah, I mean, I can totally see it, right? Like why it's being leveraged. It's, think about it this way, right? As an attacker, how do you amplify your capacity, right? Like we talked about the defenders amplifying capacity, and I think you, you know, you guys were talking about the attack wave. I think you can see that, right? What's behind this wave is, you know, the attackers, the infiltrators, they're leveraging this technology.
(R.F. Huck at 00:38:39) And if you kind of go through the paper, it's very methodical, right? So there's, like, a discovery phase. So they're leveraging AI agents to go discover different, sort of exploitation areas, I would say, right? So you're doing a bunch of scanning, figuring out what's potentially exploitable, and then figuring out, can they actually potentially exploit? And then once they exploit, getting into the infrastructure, leveraging these AI agents to do discovery.
(R.F. Huck at 00:39:05) Right? This is all work that potentially teams of people would have to be doing. But you can create these AI agents that, you know, get a persona, and that's a specific task that they have to perform. And they can all communicate with each other in some respects, or they can perform a specific task, write back to a file, and somebody else can pick it up. So it's like a fairly orchestrated mechanism, which I, you know, it was coming.
(R.F. Huck at 00:39:35) Right? I—it was not a surprise to me. Obviously, it's the first one that was discovered, and you can only imagine that if this is being talked about, you know, what is not being talked about. Right? What's actually happening that we don't know, how the attackers are actually leveraging this technology.
(R.F. Huck at 00:39:54) Right? And this is using Claude. Like, as soon as you have, you know, some of these small models that people—they can host themselves—that are, you know, just as good, potentially, and there will be no data for that. Like, there's no API usage data I can figure out for a model that I can host myself. Right?
(R.F. Huck at 00:40:15) You can imagine what you could potentially do with that, right, without anybody knowing about it.
(Joel Beasley at 00:40:21) Was the attack—was it initiated by a human? Did the human, like, organize these agents to go achieve this outcome?
(R.F. Huck at 00:40:30) Absolutely. So it's certainly the human has to kind of orchestrate the agents, as in the human has to go build these agents. And then you can multiply the capability of these agents, as in what the agents can do, right? Because they can do it all day long, right? So they'll just continuously perform the task 24/7 without your oversight, and then you can come back the next day and say, oh, what did you achieve?
(R.F. Huck at 00:40:54) And maybe from there, you go on to the next thing. Right? So, yeah. So it's certainly somebody has to be involved in building and some level of orchestration.
(Joel Beasley at 00:41:04) Yeah. Are most of the attacks that people get from the outside or from the inside?
(R.F. Huck at 00:41:11) Yeah. You know, I think volume-wise, it's going to be outside. Right? Because just purely from an attack surface, right? Every employee is a potential attack vector. Right? Because you've got, you know, phishing and whatever it may be that are, like, ways to get to an organization. Inside is also important. Like, we start to see that more often now in terms of insider threat.
(R.F. Huck at 00:41:40) I think the volume is lower, but the impact can be just as impactful because it could be, you know, reputational damage, IP being stolen. There can be, you know, pretty big impact as well. So that's something that we actually hear—I personally hear from lots of organizations we speak to, small and large. They care about—like, I mean, you know, recently, X, there was an employee that was about to leave X and, you know, stole a bunch of data. Right?
(R.F. Huck at 00:42:05) And, yeah, it was in the press. It's a big issue, organizations small and large. Yeah.
(Joel Beasley at 00:42:14) But they did have systems in place to detect that, though.
(R.F. Huck at 00:42:17) I think in this specific instance, I forget how they figured out—certainly when the action was being taken, it was not discovered. It was discovered after. But I think they had some monitoring in place to potentially nail it down to one individual. Yeah.
(R.F. Huck at 00:42:35) Yeah.
(Joel Beasley at 00:42:38) It's always—he's like, Slack messaged his friend on the company account. Look what I did. It's always something stupid.
(R.F. Huck at 00:42:44) Still, yeah? Yeah. It's like, yeah. Catching somebody, yeah, because when they make that slip up. Yep.
(Joel Beasley at 00:42:50) Yeah. Yeah. They post about it on X. Look what I did. Okay. Exaforce. Give me the name, origin. Like, what? How? Why that name?
(R.F. Huck at 00:42:59) Yeah. So exa is, I think, 10 to the power of 18. It's like how many—you know, it's force multiplier. Right? So that's kind of like how we came up with Exaforce. Force multiplier for your security team. So Exaforce. Right? So it's a very large number and force multiplier for your organization. That's, you know, that's how we came up with the name, and we stuck with it.
(Joel Beasley at 00:43:26) It sounds cool, by the way. It sounds futuristic. It works. It works. And then the little robots that you have, you call them Exobots.
(R.F. Huck at 00:43:34) Correct.
(Joel Beasley at 00:43:35) Yeah. That's pretty cool too.
(Joel Beasley at 00:43:37) You know, you got everything.
(R.F. Huck at 00:43:38) You've got to—yeah. You can't just name it AI agent. You've got to give them a little bit of character. Right? So, yeah.
(R.F. Huck at 00:43:44) Of course.
(Joel Beasley at 00:43:44) Yeah. Of course. That's what's happening now, by the way. Personification of these—you go to websites now, and they have, like, a headshot or, like, a drawing, and they're like, this is John, or this is this bot, R2-D2, and this is how it works. And they have a backstory. It's like this whole thing now.
(R.F. Huck at 00:44:01) Oh, they have a backstory for an AI? How was it born?
(Joel Beasley at 00:44:05) What was my prompt?
(R.F. Huck at 00:44:09) Oh.
(Joel Beasley at 00:44:10) I don't want to give away the details. It's a little spicy. But it was electric. Okay. So in this last section we want to talk about leadership, company-building advice. You've got 17 years of product leadership experience. What's the biggest lesson that you're learning right now?
(R.F. Huck at 00:44:27) Yeah. Look. I think company building is not easy. Let's put it that way. Right? I think there's also—so one of the things that I think about is there's a difference between building a product and a company. And I see that happen, you know, a lot of times when I talk to my friends or others that are looking to start a company. And there's a distinction, and I'll kind of highlight what I mean by that. When you think about building a company, you've got to really think about the business behind it. Right? So it's not just a really cool product, a really, you know, cool problem that you're solving, but you've got to think about who would care about it? How big is the market?
(R.F. Huck at 00:45:05) And then from there, you have to kind of, like, think through that entire step. It's actually very fundamental questions. Right? We went through the process ourselves, even though, you know, I was fortunate enough to have done a startup before this.
(R.F. Huck at 00:45:22) I was not a founder, but I was an early employee, and it helped me build a certain muscle and skill set. But my co-founder is the same way. Right? They've co-founded a couple of companies before. But we still went through this exercise, and I think Unusual Ventures has this Startup Field Guide that was—it's really, really, you know, powerful because it's an easy exercise for any founder to go through. It's a set of questions that you start asking.
(R.F. Huck at 00:45:51) You know, start with who's your ideal customer profile, target market, how big is this market, who are the competitors in the space? I'm just rattling off some of the things that it asks. But if you go through that exercise, it starts to really frame and help you think about, am I just thinking about something that could be a product and a feature in a larger company versus, no, there is a potential here to build an enduring company. And I think that is one of the most powerful lessons I've taken starting my, or being part of my last startup and then being part of Exaforce, going through this method of figuring out is this a product feature versus is this really a company?
(Joel Beasley at 00:46:38) I like that. I'm gonna put a link down there in the podcast notes for the Unusual VC product market fit because that is a good resource.
(R.F. Huck at 00:46:48) Yeah. And I'm really happy that it's something that they made available for everybody to go through and leverage because it's just sound fundamentals.
(Joel Beasley at 00:46:57) Well, I mean, the incentive's clear. They're gonna attract founders who follow the frameworks we believe in.
(Joel Beasley at 00:47:05) I'm sure there's a reason why they did it.
(Joel Beasley at 00:47:08) There is. They were not a charitable act. They're smart, man.
(R.F. Huck at 00:47:14) That's what you want. Of course.
(Joel Beasley at 00:47:15) You really do.
(R.F. Huck at 00:47:15) Yeah.
(Joel Beasley at 00:47:16) Oh, man. What's the one thing from managing humans that you've learned over time, maybe a piece of advice somebody gave you, but you've actually implemented it and you stuck with it and you've kept it for a while?
(R.F. Huck at 00:47:31) I think just as a leader, very early on in my career, as you do make career choices, one of the things that one of my early managers told me was, don't ever run away from something, run towards something that's better for you. And that's always stuck to me in choices that I've made, in choices that I have in starting this company, leaving what I did past, or moving from an organization to another. It's always something that I always think about. Like, grass can always be greener on the other side, but think about is there an opportunity for you to change your existing condition, your position, wherever it may be? If there is, then great, go for it, because if you love what you're doing, then that's what you should be doing. Don't ever run away from it because there's just some adversity that you faced, because you will face adversity in every single, in your career many times. It could be sometimes things that you can't control, and then you figure out what's better for you.
(Joel Beasley at 00:48:31) Yeah. And you'll wanna run. You gotta tell yourself, no, I gotta figure this out.
(Joel Beasley at 00:48:37) Yeah. Last leadership question. It's gonna be a yes or no question, so I'll make it super easy. Has being a parent made you a better leader?
(Joel Beasley at 00:48:45) Oh, yes. Oh, yes. So that's like a resounding yes. I mean,
(R.F. Huck at 00:48:52) it's patience. Oh, man. Like, there's a ton of patience that your kids bring to you because, you know, you say it once, they're not gonna listen to this. And then
(Joel Beasley at 00:49:05) you gotta figure out how to convince them that it's their idea so that they do it. So there's, oh yeah, there's
(R.F. Huck at 00:49:12) a ton of lessons there in terms of parenting and managing organizations.
(Joel Beasley at 00:49:21) After I started having kids, I just can't not see it. It's like, oh, this is the same situation at work. You can see that they're gonna make a mistake, but you have to, as the leader, you have to decide, is this a mistake I'm willing to let them make and learn from, or do we not have the time for this mistake because they're gonna lose a hand? And we just gotta tell them no. When to step in and
(Joel Beasley at 00:49:42) Yeah. Oh, man. This is so good. I really enjoyed hanging out with you today, RF. Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.