Episode 378 ·
Michal Pěchouček, CTO of Avast (Hosted by Derek Knudsen)
Today we have another special guest host episode, with Derek Knudsen, former CTO of Alteryx, hosting Michal Pěchouček, the CTO of Avast. And they discuss how Avast is combatting adversarial AI used by hackers with AI for security that can scale. Michal’s goal of decreasing the cost of online freedom for all, and why it’s important to keep users invested in their cybersecurity health.
All of this, right here, right now, on the Modern CTO Podcast!
To learn more about Avast, check them out at https://www.avast.com/

About Michal Pěchouček:
Michal Pechoucek joined Avast as CTO in September 2019. Mr. Pechoucek leads the core technology and R&D teams supporting the work of the Avast Threat Labs, Big Data and innovation teams. He is also responsible for the company’s scientific research in the fields of Artificial Intelligence, machine learning, and cybersecurity.
Before joining Avast, Mr. Pechoucek spent over twenty years as a professor at the Faculty of Electrical Engineering at the Czech Technical University (CTU) in Prague, during which time he led the Department of Computer Science and founded the Artificial Intelligence Center in 2001. He also co-founded a research-oriented study programme, Open Informatics, which offers a choice of different subjects, combines different areas of informatics and approaches and continues to be taught today.
Mr. Pechoucek has authored more than 400 high impact publications and contributed numerous innovative AI applications to research in computer science. Before joining Avast, he was the prime mover behind the creation of the Avast Chair of Cybersecurity at CTU, and in 2019, he also helped to establish the Avast funded joint CTU/Avast AI and Cybersecurity Laboratory. Today, Mr. Pechoucek continues to lecture at CTU and lead the Artificial Intelligence Center.
While pursuing his academic career, Mr. Pechoucek co-founded several technology start-ups including cybersecurity firm Cognitive Security (in 2013 acquired by CISCO), AgentFly Technologies, which specializes in controlling autonomous aircraft traffic, and Blindspot Solutions, which develops AI for industrial applications (in 2017 acquired by Adastra Group). He directed the R&D Center for AI and Computer Security at CISCO Systems and worked as a strategist in the CISCO Security CTO office. He is also a venture partner with Evolution Equity Partners, a VC firm specialized in cybersecurity. Recently Mr. Pechoucek co-founded the prg.ai initiative aiming to transform Prague into world-class AI super hub.
At Avast, we strive to give everyone the power to explore our shared digital world freely and safely. Our team is working to help shape the digital world to be a freer, fairer and safer place through the application of science, technology and human ingenuity, and we are looking for people who share our passion to contribute to a better online world. Avast promotes a rich diversity of cultures, debates, and out-of-the-box thinking. Today, Avast is a FTSE 100 company that safeguards more than 435 million people worldwide, protecting their digital data, identity, and privacy.
Transcript
(Intro Narrator at 00:00:03) Hello, my friends. Today we have another special guest host episode with Derek Knudsen, the former CTO of Alteryx, hosting Michal, the CTO of Avast. And they discuss how Avast is combating adversarial AI used by hackers with AI for security that can scale, Michal's goal of decreasing the cost of online freedom for all, and why it's important to keep users invested in their cybersecurity health. All of this right here, right now on the Modern CTO Podcast.
(Intro Narrator at 00:00:38) Here we go.
(Joel Beasley at 00:00:39) This is the Modern CTO Podcast.
(Derek Knudsen at 00:00:47) A little background on me. I first came to the Modern CTO Podcast. I developed a relationship with Joel when I was the CTO at Alteryx. I'm not sure if you've heard of Alteryx.
(Michal Pěchouček at 00:00:59) I haven't. I'm sorry.
(Derek Knudsen at 00:01:00) It's an analytics tooling company, so I've got an inch level of knowledge versus probably your vast AI knowledge. Alteryx developed analytical tooling for the nontechnical user, so you could go do things like develop predictive analytic workflows in a very kind of what you see is what you get, WYSIWYG type fashion. You can do data automation, if I had any kind of analytics automation work that I had to do. So that's where I got introduced to Joel and the Modern CTO Podcast. I was on, I think, a couple times, and then happened to spend some time with Joel when he was passing through Denver. And he offered, hey, why don't you come on and host it? We had such a good time when you were on the call. Why don't you switch seats with me and spend some time talking? So when I got a look at the folks potentially to talk to, your name was on the list, your company was on the list, and I said, Michal is the guy that I want to talk to. His background is fascinating.
(Michal Pěchouček at 00:01:57) Very good, very good. Exciting.
(Derek Knudsen at 00:01:59) Yeah. So most of my background's in strategy. That was my job at Alteryx, really, to scale up the organization, develop the technical strategy. I know you spent a lot of time doing that. Like I said, your background is pretty amazing. So could you give us a little bit of a brief walk through about you and kind of your journey to where you're at today?
(Michal Pěchouček at 00:02:17) Yeah, yeah, definitely. You know, I'm a kind of hardcore AI scientist guy, and I've been working on AI since I finished my PhD in the nineties. And at the time I kind of learned from my professors in Edinburgh that AI is a great tool, but AI has got its limits. AI will never drive a car. AI will never win in golf. AI will never win in poker. So I'm kind of seeing as the time goes how much I learned while doing AI as opposed to while I was studying AI, and this is pretty fascinating. So getting a degree is not enough. You're going to really need to practice AI to kind of be valuable to business and to companies. So because of my passion for AI and my passion for applications, while doing research and building systems and building teams, I was also attracted by figuring out how what I do can really help people, right? So as scientists, you know, in academia we are driven by citations and publications, which kind of drives me. You know, I really like other fellow scientists to read my papers. But on the other hand, I'm driven by the impact it has on society, on people, on industry, on business, on the way how we live, on the way how our life is more comfortable, on the way how our life is faster in a good way, but how our life is more secure and safe. That's why I was kind of building startup companies with my PhD students and fellow researchers. I built a couple, I was lucky to exit a few. The most interesting gig was when we built one of the first companies in true AI/ML space in cybersecurity in 2008. It was at a time where actually nobody believed that this was at all possible. People thought that this was like smoke and mirrors. That's, you know, AI and cybersec—that doesn't work at all with them. These days it's very difficult to do any business if you don't have an AI sticker on whatever you do. So we thought that the way how AI scientists are processing images can be very similar to the way how we can process network traffic. And we have been using ensemble-based machine learning in order to be able to detect anomalies in that flow and network traffic on the Internet. And through detecting anomalies, we were pointing to ATPs, Advanced Persistent Threats. And this kind of led us to building a great product and getting a good customer base, and in the end exiting to Cisco. So Cisco acquired my business, and I was running AI for cybersec in Cisco for several years. And then, you know, I came back to the university. I started a few other small companies. I exited a few more that I did in VC. And I felt that it's a comfortable life. I can do part in VC, part in being at the university. When Ondrej, at the time CTO of Avast, approached me. And he kind of made me believe that this is a once-in-a-lifetime opportunity to take advantage of my AI experience and passion for building systems and to help not enterprises, but to help consumers, like people who are living digital lives, to help them to solve their problems with security, privacy, freedom in the future. And he just got me excited until I joined the company. He became the CEO, and we worked together since.
(Derek Knudsen at 00:06:20) Yeah. I saw your background. You've started a variety of different companies. Like, I think I saw an avionics company. You did some AI with aviation. Obviously there was a security piece.
(Michal Pěchouček at 00:06:32) Yeah, yeah.
(Derek Knudsen at 00:06:33) Like, your applied AI was all over the place. It's fascinating. Most people will find an industry niche and pretty much stay in that in logical adjacencies, but it looked like you kind of went large left-hand or right-hand turns at different spaces, which is fascinating.
(Michal Pěchouček at 00:06:49) Yeah, so like, the aviation business—it was exciting. You know, it's the company called Agentfly. I've exited this already, but it was, it still is a startup company, a reasonable size now, that is solving a problem: how to model complex systems in avionics, right? We were solving a problem, how to get rid of traffic controllers. If you look into the kind of aviation business, there are people who are running landing and takeoff. It looks stupid, right? This is like a fully automatable process that can be automated and would always outperform people. But the problem that we had at the time was how to bring technology down, how to test and experiment. You're just going to kind of bring a new algorithm and then count the number of airplanes that crash, right? And then go and debug, right? This is the way how you would innovate in this space. So that's why we built a complex multi-agent technology that was used to be able to model and simulate at a higher precision different scenarios of the use of a technology in the air traffic control problem. And today, FAA is the biggest customer of Agentfly technologies and is using the technology for testing and simulating different scenarios of bringing in new tech into the problem, which is still heavily man-controlled and man-involved. It was exciting, right?
(Derek Knudsen at 00:08:30) Yeah, it's fascinating. I know that's not what you're focused on now. One thing that I saw—I was interested in how you moved to Avast given you seem to have a pretty good rhythm with the academic work you're doing, the VC work you were doing. What really compelled you to move to Avast? I know you introduced a little bit of that, but were they approaching the connection between AI and cybersecurity in a very different way that you said, hey, that's a unique approach and something I'm excited about strategically, and that's what got you to kind of look at that opportunity and jump at it? Was there something specific that was different about them? I'm sure you got approached by a ton of different companies for similar roles, given your background is so applicable and so needed in the cybersecurity space. How was this the right path for you?
(Michal Pěchouček at 00:09:18) So I'll give you two pieces of answers that are different but related. So the reason what got me excited and the reasons that make me excited currently, right? So when Ondrej offered me the job, I was excited by the set of values. You know, I'm actually big on citizens' freedoms and liberties. And, you know, me kind of being brought up in the East Bloc of Europe when the Iron Curtain worked—for a part when I was 18—kind of my sympathy with people who are not free, who are manipulated, influenced, who cannot use, who don't have any free access to information, is very exciting. And, you know, I also have philanthropies in this space, and I'm really passionate about people with freedoms and liberties. And, you know, it was the first time in my life where I kind of got an opportunity to marry my professional experience and my knowledge and skills with a set of values that I was supporting in my free time, right? And that was the exciting piece. I can use AI not to help big companies to automate, to make more money. I can use AI to protect people against more and more sophisticated threats on the Internet, against big giants on the Internet, against manipulation. And this set of values and the opportunity to kind of contribute to digital freedom of the ordinary users—that was the exciting piece. So this is what excited me when Ondrej gave me this opportunity, and it continues to excite me now. There is an additional differentiator. I had the opportunity in my life to work with cybersecurity specialists and with AI researchers and scientists. You cannot imagine, like, two other dissimilar technical communities, right? There is a big gap between these two super intelligent, sophisticated, impactful communities. And like with Cisco, when I was with Cisco, I had hard times really to bring those groups together, to respect each other, to share knowledge, share experience, share passion. In Avast, it's working. It's the first time in my life when I see these two communities being excited one about the other and working shoulder by shoulder. Actually, I tell you, by me being able to really excite those two camps to share objectives, it makes actually Avast a unique cybersecurity place. I'm not seeing such a camaraderie and joint or shared objectives in other cybersecurity firms. And this actually makes me excited, the fact that there is a shared workplace where these two gangs like to work together.
(Derek Knudsen at 00:12:25) Yeah. Let's talk to both of those. Let's start with the latter since you just talked to it. I've run infosec in my past. I kind of know that cybersecurity persona a little bit. And Alteryx was an analytics company. We had data scientists and kind of that persona represented in terms of creating new predictive analytic models, et cetera. So I'm sympathetic to the difference in styles with those two. How do you take two very differently wired—instead of engineers, we'll use that generic term—and provide kind of shared vision, shared strategy that both can be like, okay, I get that. That's not specific to either side. That's shared vision, it's shared direction, it's shared strategy. How do you navigate that given that they are very different, you know, resource sets, for lack of a better term? Very different motivations, very different experiences. How do you—is it communication style? Is it finding a compromise in messaging and goaling? Talk through how you motivate both sides at the same time with the same message.
(Michal Pěchouček at 00:13:30) Yeah, that's a great question. So it is mainly on being able to understand what are the technical problems that will be the best place in the middle, right? To be able to figure out what the problems will be, those that will be exciting for both camps. And you'll get to this. But before I list some of those problems, I'll tell you that the hardest part for me was to make the AI scientists to really appreciate the subject matter expertise of the infosec people. Your AI scientists are more about data. So they are not so excited about people. You give me your data, I train your model. And that's like—I would say that your AI people are very transactional when it comes to kind of providing value to users, to customers. And to be able to change this mindset and to figure out that it's not data, it's this great skill that the infosec people have, which has been trained for years and years and years, where they need to be able to take advantage of and understand, and to turn them into exciting customers. Because without doing that, the AI research doesn't have an impact in this problem, right? So they would still stay swimming on kind of more abstract problems, kind of demonstrating what can be done, but not providing value to the infosec people. So it was actually one of the changes of the mindset of the AI people. The change of the mindset when it came to the infosec people was the scale. You know, in Avast we see how many attacks happen, right? We see how many viruses we catch every single day and how much does it grow. There's a massive growth of the infection on the Internet, and these smart infosec people started to realize it's not scalable, it doesn't scale. So they started to really appreciate the automation, better tools, kind of pushing more decision-making to the algorithms, as soon as they still are there, they keep the control, right? So you need to give them the opportunity to kind of retain a lot of control. When I was trying to figure out what is the problem that would make those parties excited, it's AI explainability. AI explainability is a problem which is exactly in between these two camps, right? Because for AI scientists, irrespective of the domain, explainability of machine learning models—it's an exciting topic, from healthcare to autonomous driving, right? So people like it. If you provide good explainers on your detectors and classifiers that would kind of be supplied together with the technology to the infosec people, they get more excited. They trust AI more. They see better relevance. And through explainability, the infosec people started to see the value. You know, kind of my infosec people are writing YARA rules. You know, we use YARA rules as a language to represent rules that we deploy on the endpoints through which we are protected against malware, right? So now the AI people are building detectors and classifiers, and they represent the result in the same language, in YARA rules. So for me it was super important to come up with a representation that would be similarly accessible to the infosec people as much as for the algorithms that are producing classification and anomaly detection. Does it make sense?
(Derek Knudsen at 00:17:31) Totally. I, you know, on a related point, I was on a podcast a while back and that was the topic they wanted to get into the most, was kind of the explainability side of it. When you look at your ensemble-based models or your deep neural network models, the explainability side—whether it's security or whether you're making an underwriting decision on a loan candidate—like, that's a really important part, kind of for the morality and the ethical side of analytics. So I can only guess how pessimistic a cybersecurity expert is in terms of specific outcomes of a machine learning model if they can't understand it, right?
(Derek Knudsen at 00:18:08) That by nature, that's how they are. So I can only understand to a great extent that that's probably a huge challenge for them, and that explainability part is really valuable for them. It lets them participate more on the AI side than they probably could have before, and you're kind of beginning to bridge the skills gap between the two parties. You're not gonna, I'm guessing, you can't go out and hire, you know, five new data scientists who have deep understanding of cybersecurity.
(Derek Knudsen at 00:18:36) That's a brand new skill set. If it was, "Hey, I'm a data scientist who spends time in fraud detection in financial services," there's probably, you know, relative to cybersecurity, there's probably plenty of those. But in the cybersecurity space, there's probably zero of those. So you're developing a very specific data scientist skill set that allows them to bring context to their work, and that probably creates much greater value to your point.
(Derek Knudsen at 00:19:01) So super interesting.
(Michal Pěchouček at 00:19:03) Yeah. I would add this, Derek, kind of one more thought. Classic AI scientists are motivated by replacing people, right? So whatever people do, you know, you try to model and replace that capability. In cybersecurity, I don't do this. I'm excited about making the cybersecurity specialists and paraprofessionals so that with the proper use of AI, their time is 100x more impactful, right?
(Michal Pěchouček at 00:19:28) So this multiplier of the time of my SOC analyst, this is the metric. That's what I optimize. I don't optimize how many people I can fire. I optimize the impact of the people that I have. So that's one thought.
(Michal Pěchouček at 00:19:44) And the other thought is the world is changing because the infection that we see is AI-based, is automated, right? We see more and more infection which is created by the algorithms, right? And we all understand that, you know, the AI-constructed or AI-empowered or AI-based scaled attacks can scale like nothing.
(Michal Pěchouček at 00:20:10) We just pay for the compute, so we can scale exponentially. If we, as the defenders, would be weak on AI-based defense and would be using people for AI-based attacks, we can never win. We would always lose because we cannot scale the way how the attackers are scaling. So it is super important that every cybersecurity innovator or CTO or somebody who is in charge focuses on maximizing the amount of AI, the AI-based automation, machine learning, to be able to fight AI-based attacks with as much AI as possible so that you keep human intellect and human power for the cases that are human-crafted. So that you have, you're gonna keep attackers finding people and AI finding AI.
(Michal Pěchouček at 00:21:07) Right?
(Derek Knudsen at 00:21:08) Yeah. That's fine. Absolutely. That's spot on. That's really well articulated.
(Derek Knudsen at 00:21:12) You know, it's a one plus one equals three thing with, you know, you take the cybersecurity expert, you take the data science and the artificial intelligence, and it becomes you give them that tooling, and they can do their job exponentially better. And I love your point around, you know, let's keep people focused on people problems, and let's let the technology focus on the technology-specific intrusion vectors that, you know, these entities are trying to attack people with. That makes tons of sense. Yeah. So on that side about the cyber and the AI side, what are you seeing in terms of where that industry is going in terms of what types of malware is being developed, what type of intrusion vectors are being developed?
(Derek Knudsen at 00:21:52) Is there something that listeners of the podcast should be aware of in terms of being thoughtful on? You know, you talked about, "Hey, bring AI into how you think about cybersecurity protections." Is there anything else in terms of new attack vectors or what have you that you think folks should be aware of that you're seeing now, given your seat?
(Michal Pěchouček at 00:22:09) Okay. So I do three things. One is, we see new attack vectors constantly. We see new types of attacks. And the truth is, it's very difficult, you know, once you're going to get a new attack vector or a new source of data that indicates a malicious behavior, it's very difficult to kind of sit down with your people and kind of build a new classifier for these attack vectors that you see, right?
(Michal Pěchouček at 00:22:42) So what we are trying to bring is deep learning-based methods, featureless machine learning methods, methods based on hierarchical multi-instance learning, which are kind of generic enough so that they can kind of easily let the classifier train on the new data that are describing the new behavior. You do not need to do this in a laborious machine learning engineering together with the security experts and craft independent classifiers. So the generality of machine learning is very important to be able to respond in a timely manner to the new intrusions. As far as the trends are concerned, what we see, obviously as any other cybersecurity specialist, is that the humans are in the center of the attacks. So the attackers no longer attack machines, devices, network.
(Michal Pěchouček at 00:23:39) It's boring. Attackers attack people, because people are the easiest way in. 90% of the attacks are based on people's errors and clicking on things that they shouldn't click on, entering their private data to places they shouldn't, right? And the capability to deceive people's intellect and people's attention, this is the most prevalent trend these days when it comes to new vectors. And that's why we are starting to really focus on what is more important now than it was before, which is trying to understand how people are vulnerable and what makes people click on things that they shouldn't click on.
(Michal Pěchouček at 00:24:24) And we are learning it's an AI-based problem. It really is. Because if I would write a deceptive phishing email, what I need is your inbox and good machine learning systems that would help me to create a model that will write an email that you will trust. So with the more private data out, with more privacy that we disclose and share, easier is it to write good quality models that will send me an email that I will trust. So this is an important attack vector, human-centric attacks.
(Michal Pěchouček at 00:25:06) And Avast is actually moving in this space to be, to be more valuable to the end users. And the third trend we see is actually in the space of adversarial machine learning, right? As it occurs now, we are running AI under the hood. Okay? We are.
(Michal Pěchouček at 00:25:28) So the whole space of adversarial machine learning and adversarial AI, it's kind of trying to come up with samples that would go around your classifiers. What behavior I can get through the classifier? Adversarial learning is computing those samples, right? This is a new field. People know adversarial machine learning mainly from deceiving cameras and recognizing traffic signs, right?
(Michal Pěchouček at 00:26:00) So you can change the traffic signs so that you see it differently than the algorithm. And cybersecurity is the same. Attackers are trying to deceive our AI by crafting sophisticated samples that will go beyond the protection. What our goal is as AI cybersecurity people, we need to build algorithms that are robust against deception, robust against overtraining, robust against data poisoning, sample poisoning. This is like a problem that wasn't here before.
(Michal Pěchouček at 00:26:38) Right? Before, attackers couldn't care less about our algorithms. They knew their ways, right? So now with the improved quality of protection that is by big part AI-driven, we are seeing attempts by the attackers to overtrain our algorithms.
(Derek Knudsen at 00:26:57) Yeah. The point you make on the people dimension of this problem is really interesting. It's come from, I think, you see a lot of folks in this space that are, you know, these agencies trying to enrich information around people and build, you know, models of vectors to get at people. I know text is something that a lot of us are really vulnerable to. We're used to dealing with the email filters, and email from a terms of protecting you against malware is fairly effective.
(Derek Knudsen at 00:27:25) The text side of it doesn't seem to be as effective. Folks seem to have lower, more trust. If I get a text message, I tend to trust the text more than I tend to trust email. So I know that's probably for you all, you know, trying to inject something that gets in the way of the text stream of things is a huge challenge. I'm sure a huge challenge for you is just trying to educate humans on identifying threats, right? I mean, you know, having run InfoSec and tried to do that within organizations before, that's a huge challenge.
(Derek Knudsen at 00:27:53) And folks only tend to get interested in solving it once they've been duped. Then they recognize, "Hey. This is a real problem. It's not somebody else dealing with cyber issues and not me." Once you get duped, and inevitably somebody will get you duped, you begin to recognize that's important.
(Derek Knudsen at 00:28:09) So is there a way that you or the industry's working to bridge the human knowledge gap, the awareness gap? Because I will tell you, in trying to run continuous education programs within the companies I've worked for, we always seem to be hitting a wall in terms of getting folks to really value that level of training and find that it was important. It was always, you know, pulling teeth to get folks to want to invest in understanding kind of the evolution of the cyberspace so they could protect themselves from it. And to your point, if humans click on the link, there's nothing your software can do, right?
(Derek Knudsen at 00:28:44) They can make poor choices. So is there stuff that you all or the industry's doing to help there outside of just trying to create better software to reduce the opportunity? Is that all you can do?
(Michal Pěchouček at 00:28:57) So, listen, part of my job is to help to reinvent consumer security, right? Some of the kind of big new ideas. I'm not bringing any quantum computing into this. I think it's much simpler than that.
(Michal Pěchouček at 00:29:13) I'm trying to bring humans back in the loop. For the last 30 years, the cybersecurity and the AV industry has made this error of providing the user with "you do not need to worry" security.
(Derek Knudsen at 00:29:27) You got it, right.
(Michal Pěchouček at 00:29:28) You are protected. You don't need to worry. It's a mistake. It's a foundational mistake. Thirty years ago, 20 years ago, the industry shouldn't have done this.
(Michal Pěchouček at 00:29:39) Because by this, the industry created low-engagement products that are now difficult to sell, honestly, because they are low engagement. While cybersecurity shall be a high-engagement problem, we need to bring people into the loop and we need to make them co-responsible for what is going with their privacy and security online. We do this in Avast by kind of building new technologies and new products in this space. We are experimenting with new products, we are doing user research, and we are testing technology where the technology can provide. And you know, one of the interesting ideas that we have is a combination of AI explainability and gamification, right, to figure out what is the best representation of the information to user, and how can you make the user engaged in trying to act on it?
(Michal Pěchouček at 00:30:44) And the approach we are taking is we are building a cybersecurity Fitbit, right? People wear their smartwatch, and they monitor their heart rate and their oxygen. And before they go to sleep, they see all their charts, how they improve their behavior, how they sleep, how they drink. People are excited, but people aren't excited to understand how safe they are online because they think they are safe because they paid somebody $10 a month and they are covered.
(Michal Pěchouček at 00:31:16) So we would like to build a cybersecurity Fitbit that would give everybody transparency, visibility into how they behave, how often they change their passwords, where do they click, what sites do they watch. There are sites that are dangerous, but still okay if you are careful, right? So if you go there, you're going to need to be more careful than if you're going to read your email in your Gmail, right? So this is a non-trivial concept for many people. And I think it's a duty of the cybersecurity industry to kind of come to people and to start giving them advice, giving them continuous monitoring, and try to make them improve their cybersecurity behavior online.
(Michal Pěchouček at 00:32:04) It's not only education. It's the technology plus education.
(Derek Knudsen at 00:32:08) Yeah. That sounds like kind of the holy grail of products. If you could, you know, get the user, the end user, involved in increasing their cybersecurity protections, I think that would be amazing. I know that if you take an average sales guy who doesn't care about that space or an average consumer who doesn't think about it, my, you know, my parents, et cetera, right? They don't have any consideration for those types of things, and they have issues constantly. It seems like my father specifically always seems to have security issues with his computer where he makes poor decisions.
(Derek Knudsen at 00:32:31) So if you can get the human side involved in some of the edge decision-making in terms of what they select and why they should select it or why they shouldn't select something or take a specific action, I think that's
(Michal Pěchouček at 00:32:55) Yeah.
(Derek Knudsen at 00:32:55) That'll take the industry, you know, a quantum step forward.
(Michal Pěchouček at 00:32:58) Yeah. I would add to this, Derek, that, you know, it's not only providing users with visibility and gamification, but also providing them with personalized cybersecurity. We are different. We have different lives. Our lives are kind of dangerous online from different perspectives.
(Michal Pěchouček at 00:33:16) So kind of the danger that I experience is different than my father does, and it's different than my daughters do. And because we have data, we understand, we can learn more of the behaviors of the users online, we should be able to provide them a custom-tailored security, which is specific to each of our lives, each of our Internet needs. And also, we have also different attitudes to risk. Like, my parents are very risk-averse, right? My kids, they understand Internet much better than them, and they are more risk-open, right? So personalization of cybersecurity, this is a big thing.
(Derek Knudsen at 00:34:03) Yeah. 100% agree. Well, let's pivot a bit because I wanna learn more about how you do your job. So I think you're, I was looking at your stock symbol, and the progress of it's been remarkable, the growth of the Avast stock. I'm sure that the organization scaling out probably looks very similar.
(Derek Knudsen at 00:34:23) What are some of the big challenges you're facing in terms of like the organization? We talked a little bit about bridging the gap between the data scientist side of the organization and the cyber expert side of the organization. But in terms of org design, distribution of work, making decisions on where you deploy resources, what are some of the primary challenges that you're really focused on right now?
(Michal Pěchouček at 00:34:46) Okay. So I would say the biggest challenge is the horizon. In my organization, there are 200 people, and each of them have got different horizons, different horizons of impact and delivery. So there are people who are fighting with the attackers by the minute, right?
(Michal Pěchouček at 00:35:08) So they need to deliver now or in a minute or in half a day. So the horizon is imminent, immediate. There are people who are building systems for those people to be paraprofessionals. So their horizon can be a quarter, can be a year, can be 18 months. This is a horizon.
(Michal Pěchouček at 00:35:28) And then in my organization, in the technology group, also on innovation. People who are trying to invent new products, new services, new values to users. And, again, there is a different horizon, and there's also different risk, right? So the people who are protecting our users now, there is a zero tolerance to risk.
(Michal Pěchouček at 00:35:51) We need to deliver, we need to protect every single user on the Internet. People who are innovating on a future digital freedom product portfolio that will matter in three years from now, they have a different horizon. And if I silo, I'll be losing the opportunity. The interesting soup gets from the mixture, right? So to be able to mix the perspectives and the experience and the job description of these groups with different horizons is a huge challenge. But I believe that in this challenge, there is a value.
(Derek Knudsen at 00:36:26) Do you guys have distributed teams? I know you're Prague-based. By the way, I've been—Alteryx had an office in Prague. It's one of the great cities in the world for folks that haven't been there. You gotta go there.
(Derek Knudsen at 00:36:38) It's amazing. Do you guys have offices in other places—India, China, other markets? And if so, how do you think about distribution of work given you said everybody's got different horizons? Do you limit a location to a specific horizon? Do you have teams that span different locations who have shared horizons?
(Derek Knudsen at 00:36:55) How do you think about that?
(Michal Pěchouček at 00:36:57) So it would be actually exciting to have this discussion two years ago because we would be able to speak about geographies and team locations and geographical studies—where you hire, where your people are. After COVID, it's all different, right? We have learned how to work from anywhere. Our people are working from anywhere. There are people who joined the company a year and a half ago and they never saw each other, right?
(Michal Pěchouček at 00:37:28) So there is a huge opportunity in this flexibility. And also, for some, the asynchronicity of work is actually great—to be able to work in a more asynchronous way. And also, people hate Zooms, so that's why they try to be more rational about meetings. The face-to-face meetings have some charm, right? People really like to meet each other. Once they cannot, they need to get together on Zoom. It's much less pleasurable. It's more troublesome. People are less excited about Zooms, which in the end is driving efficiency.
(Michal Pěchouček at 00:38:08) People need less meetings. People spend more time using asynchronous work tools. We use Asana to perfection, we use Jira to perfection, right? We have rules that if there's a meeting, there needs to be a pre-read. The person who is calling for a meeting needs to provide pre-read material. There needs to be everything in conclusion that are stored somewhere in Jira or Asana.
(Michal Pěchouček at 00:38:35) So this pandemic thing has made us more responsible to the meeting times, and actually I see this as a positive effect. We in Avast have offices in tens of countries around the world, but the engineering hubs are really Prague and Brno, Czech Republic. We have people in London—there is a good engineering site in London. We have engineers and researchers in Silicon Valley in Berkeley. We have engineering teams in Serbia and Belgrade.
(Michal Pěchouček at 00:39:15) That's pretty much it. So we are learning that it's less about location. It's more about the time zone. We're going to need to really figure out how to bridge time zones because the time zone is an obstacle. Being across sophisticated time zones—this is a huge challenge.
(Michal Pěchouček at 00:39:31) But we are getting where we want to be. The second huge challenge is to be able to attract good quality talent, right? The talent in our industry is a rare asset. Prices are rising, skyrocketing. The availability is dropping.
(Michal Pěchouček at 00:39:49) I would say that the average quality of available people on the market is lowering because good people have their jobs and they are not interested to pick up a call from a recruiter. So the current talent availability is a non-trivial problem. In my field, I'm betting as a former academic—I'm betting on university collaboration. Here in Avast, we work with UC Berkeley, we work with Stanford, we work with King's College London, UCL in London. We work with the best engineering schools, and this puts us into a great position to get to know the capabilities and show our logo to students and excite them about our mission.
(Michal Pěchouček at 00:40:35) So we are very successful in being able to tap the junior talent. However, as a manager, you know, the right mix of junior and senior is very important. We couldn't stay only on the level of being able to turn grads from the best universities.
(Derek Knudsen at 00:40:51) Yeah. I think there's a lot of companies that are trying to approach it your way. I think access to talent is a huge challenge. All the CTOs and CXOs that I talk to, they ask me two questions. One is, how do you manage innovation in this distributed situation?
(Derek Knudsen at 00:41:07) What we found, what a lot of folks in industry found, is the core engineering aspect during COVID—we saw way better productivity. But where we lost momentum was in that white space around innovation, collaboration. If you're talking about net new strategy decisions or thinking through some innovative concepts, doing it through a digital medium doesn't create the same amount of energy that you had in person. So the biggest question I get asked is, "Well, how did you guys overcome that?" The answer I had was, "Well, we kinda didn't." Like, we were struggling with that.
(Derek Knudsen at 00:41:45) And if somebody can solve, "Hey, how do you bring that same kind of in-room whiteboard energy into a digital format?"—I think that'll bridge the gap significantly. And the other question they ask is, "How are you doing on talent?" Because we are struggling to find good talent, even in the distributed model.
(Derek Knudsen at 00:42:02) And I think the answer a lot of folks come back with is similar to yours, which is it takes time to get the cycle going, but let's start engaging with university-level hiring or nontraditional educational fronts to build from the bottom up and build that growth model through the organization. But to your point, you always still have to hire a certain amount of senior resources to develop and mentor those more junior, less experienced resources. That just takes time. So it's a difficult challenge to overcome. I'm sure you'll get there over time.
(Michal Pěchouček at 00:42:36) Yeah, definitely. To the digital means for innovation and collaborative thinking, we had good experience with Miro, with Miro boards.
(Derek Knudsen at 00:42:45) Yeah.
(Michal Pěchouček at 00:42:46) We use Zoom as a mechanism to work together and co-create. From the innovation aspect, what is difficult—in my opinion, and this is independent of pandemics, it's also independent of industries—is to bring everybody to the table, share the perspectives of people who have different burning platforms, right?
(Michal Pěchouček at 00:43:12) Everybody has a burning platform. Everybody is stressed and passionate and needs to deliver. But in order to be able to come up with a new product that you can sell and that users would be excited to buy or to install, you need to have different professions on the table. But in a company like us where we are really passionate and fighting attackers, it's non-trivial to bring in people who are trying to deliver in the next quarter, people who are willing to deploy in three weeks, and people who are ideating about the products that will matter in two years, right?
(Michal Pěchouček at 00:43:54) Different horizons of different burning platforms—that's a challenge that we are trying to learn how to overcome.
(Derek Knudsen at 00:44:01) Yeah, I'm not surprised on that one. How about the academic side of things? Are you still finding time to engage in academic work given everything you're doing professionally? It seems like a full-time job in itself. What do you focus on academically now? Anything of interest there that you're looking at? It doesn't have to be cyber-related, but just in general, are you looking at anything in that space that's got you excited?
(Michal Pěchouček at 00:44:24) Yeah. So I'm still a professor at Czech Technical. I do not teach anymore. I don't have time for this. I'm spending time with PhD students and using this creative environment to get some ideas from and to provide some inspiration to, right? So I mean, I continue to be an academic, part of an academic.
(Michal Pěchouček at 00:44:50) And the problem that excites me when I speak with my fellow researchers and scientists is the concept of a cognitive antivirus, right? How to transform the problem of the antivirus, cyber antivirus, to cognitive antivirus. In the past, people were debating, you know, if Elon Musk and his Neuralink will provide brain implants, right? Will it be helpful? Will it be healthy? But also, is it a danger for cyber attacks? Can we get hacked? Don't we need a totally different level of protection on the internet if our brains get hacked?
(Michal Pěchouček at 00:45:47) My response to this is, this will never happen. I don't believe Elon is doing that. If we were not able to lift Google Glass, which was substantially less invasive technology, I don't believe that we will get brain implants. They will never get an approval. It is unethical. And it's interesting times where ethics is getting more and more important in research, science, and technology.
(Michal Pěchouček at 00:46:12) So I feel that we do not need to worry about the brain implants. But we need to worry about getting hacked without brain implants, without cell phones, without PCs, right? It's not difficult to make me click through my cell phone. It's not difficult to hack me so that I can make actions with unintended consequences. It's not so difficult to hack me so that I hurt myself physically or psychologically or I will make a decision that is not good for me if somebody hacks me, right?
(Michal Pěchouček at 00:46:51) And this space where protecting against phishing attacks meets misinformation and disinformation—that's super exciting. Those two problems seem to be from two different worlds: cybersecurity and media manipulation. But when I work with my research scientists at the universities, I'm learning it's just the other way around. Those two problems are so close, so similar.
(Michal Pěchouček at 00:47:22) Clicking on a link which makes me give out my credit card number is a similar mental cognitive attack as me choosing not to get vaccinated. It's another cognitive attack with unintended consequences. I just don't intend the consequences, but I got hacked, right? So this problem of preventing our brains to be hacked is here now, and we do not need to wait until Elon succeeds or doesn't succeed with his brain implants.
(Michal Pěchouček at 00:48:00) And this problem of our brains—to keep them away from hacking—is very topical today.
(Derek Knudsen at 00:48:12) Interesting. So how do you find—as I look at your background and the balance of all the academic work you do, all the business-centric work you do, obviously you've got the Avast job, which is full-time, and I think you mentioned you have at least a child, maybe more than one, a wife. How do you manage your time? Because you seem like a person who has to work a hundred hours a week to get through all the things you have on your plate. Do you have any good life hacks that you use to manage your personal time and your, we'll call it your professional time, which includes your academic time?
(Derek Knudsen at 00:48:46) How do you manage all that? You've got a lot going on.
(Michal Pěchouček at 00:48:49) So the way how I manage is through longer distance running. Because long-distance running makes me disconnect, to run long-term without the phone and be alone with my thoughts. I see it as important. I recommend everybody to read books on Kindle or in paper and to run, because this gives you the time to think.
(Michal Pěchouček at 00:49:19) It's different to the time that the internet wants from us. The internet wants me to provide high frequency of attentions that are one second lasting. That's this is how I'm hacked, right? And to be able to be safe from this hacking, we're going to need to train our resilience in this high-frequency, short-span attention economy. And to me, reading a book and doing a long run—a 20-mile run—that's an opportunity how to build resilience against stress, against lack of time.
(Michal Pěchouček at 00:49:58) Because once you devote time in this particular way, you need to get something out of this, right? You need to either learn by reading a book or you need to really sort out your thoughts while doing a 20-mile run. So that's what helps me. It actually helps me a big time.
(Derek Knudsen at 00:50:19) Wow. So on the running side, are you—I'll call it even if it's a nonprofessional competitive runner—are you a marathon person?
(Michal Pěchouček at 00:50:27) Yeah, yeah, yeah. I'm a marathon person.
(Derek Knudsen at 00:50:30) Yeah. I have the same background, so I've been fascinated by it. I always wanted to get over to Europe and run the London Marathon and the Berlin Marathon. I always heard those were destination runs. Do you guys have something similar in Prague? Do you have runs?
(Michal Pěchouček at 00:50:42) Yeah, yeah, yeah. Prague Marathon is beautiful. It's actually a part of this league together with London Marathon. It's actually one of the most—it used to be before pandemic—one of the most go-to marathons in Europe. Very beautiful alongside the river, quite flat, pretty fast. Got good results from the racers when they come over. So yeah, the Prague Marathon is great.
(Michal Pěchouček at 00:51:10) I'm actually—I've got my mountain house. I spent all the pandemic in the mountains, and there were no races. So I kind of turned myself more from a marathon runner in cities to a long-distance runner in the mountains. So I started to be substantially less passionate about time, but more about the altitude.
(Derek Knudsen at 00:51:37) Yeah. Wow. Okay.
(Michal Pěchouček at 00:51:38) So the amount of meters that you climb while running—that excites me. So you see how pandemic's going to change somebody, especially for running. There were no marathon runs. So what could I do? But seriously, come over to Prague.
(Michal Pěchouček at 00:51:54) Prague is hosting a beautiful marathon.
(Derek Knudsen at 00:51:57) Yeah. What an unbelievable city. I enjoyed it a ton. So I know we're getting close to your stop. Any parting thoughts?
(Derek Knudsen at 00:52:04) Anything you want to share with this group before we call it good?
(Michal Pěchouček at 00:52:09) Yeah. Grant, really thank you for the opportunity to speak about my work. I think that what would be great is if people who share my excitement about this work can make their kids study AI and cybersecurity. This is a hard combination, a really difficult combination, but it's actually one of the most important combinations that are around here. Similar to AI and healthcare, AI and medicine—like at Imperial College in London, the first grade of medical school, they teach you AI. So it's a similar combo.
(Michal Pěchouček at 00:52:49) And I'm a believer in combo. When parents ask me, "Should I put my kid to study AI?" I say, "No way. Do AI and something else." And I think that AI and cybersecurity is very important for the society, not only for the jobs and for the salaries, but also for the society because they will be contributing. For one, we will be increasing the amount of freedom that we enjoy on the internet. And second, we will be reducing the tax that the society needs to pay for being safe online. Being safe online is a very expensive proposition. And with more smart people, we will be able to drive this cost down.
(Derek Knudsen at 00:53:32) Yeah. I tell you, I am super motivated by how mission-oriented you are. And it sounds like you guys are hiring basically almost anywhere. Time zones need to be somewhat supported. So if you're listening to the podcast and you're motivated by the mission, I mean, I will tell you, Michal, I don't run into a lot of leaders that are that motivated by mission like you are. But those are the best people to work for, right?
(Derek Knudsen at 00:53:54) And so if you're motivated by that story, I couldn't think of a better company leader to work for than you.
(Michal Pěchouček at 00:54:00) Thank you.
(Derek Knudsen at 00:54:00) If they go to reach out—if they go to the website, look for careers online—is there a good way for folks who are really buying into your vision to come and maybe come to work with you all?
(Michal Pěchouček at 00:54:11) Definitely. We are hiring. Check my LinkedIn page. Get in touch. There's going to be lots of posts and blogs.
(Michal Pěchouček at 00:54:19) I write and I share and post, and you'll learn more about us and get in touch. You are becoming more excited with every single listen of our podcast. If you would be interested to work with us, either in Avast or at the university, or do a PhD—do a PhD, because education is shortening, right? You know, the future of education will be not five years degree, but kind of two years degree, one year degree, half a degree, none of the degrees. But still, we need scientists.
(Michal Pěchouček at 00:54:53) We still need people with PhDs. And I've heard that people will be less excited about PhDs in the future, but I tell you, PhD helps you. It's a good thing to have.
(Derek Knudsen at 00:54:37) Fantastic.
(Joel Beasley at 00:55:04) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email: [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.