Episode 862 ·
Security for AI, or AI for Security? With Nick Calver, VP at Palo Alto Networks
Today, we're talking to Nick Calver, VP of Financial Services at Palo Alto Networks. We discuss the state of AI ransomware attacks, what the mindset is to best prepare for them, and how to think about product consolidation in order to best serve your customers.
All of this right here, right now, on the Modern CTO Podcast!
To learn more about Palo Alto Networks, check out their website here.
About Nick Calver
An accomplished International Executive Leader, with extensive experience in driving the success of multibillion-dollar global enterprises across diverse industries. Extensive background in working within Customer and Sales organisations, and with FTSE 100, LSE, and NYSE operators. Specialises in transforming commercial performance, reducing cost, and significantly increasing sales using creative value-based initiatives, combined with strong executive engagement based on credibility and trust. Proven track record in leading and building international cross-functional teams, as well as delivering innovative solutions that transform business capabilities and accelerate strategic company growth.
About Palo Alto Networks
Palo Alto Networks, the global cybersecurity leader, is shaping the cloud-centric future with technology that is transforming the way people and organizations operate. Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. We help address the world's greatest security challenges with continuous innovation that seizes the latest breakthroughs in artificial intelligence, analytics, automation, and orchestration. By delivering an integrated platform and empowering a growing ecosystem of partners, we are at the forefront of protecting tens of thousands of organizations across clouds, networks, and mobile devices. Our vision is a world where each day is safer and more secure than the one before.
Transcript
(Intro Narrator at 00:00:01) Today, we're talking to Nick Calver, VP of Financial Services at Palo Alto Networks, about whether you should be using AI for security or security for AI. You're listening to Joel Beasley, Modern CTO.
(Joel Beasley at 00:00:19) One of the things that caught my eye was this phrase "security for AI or AI for security." Can you explain that to me?
(Nick Calver at 00:00:28) Yeah. Security for AI or AI for security is a common thing we're discussing at the moment. I guess on the security for AI bit, people are naturally concerned. There's been some crazy stuff going on that I've seen recently. About six months ago, I was at an event. I was asked to speak. I got a deck from one of our people, and in that deck, it had a few statistics. It said, like, eighteen months, two years ago, it would take forty-four days from the start of a ransomware attack to getting data out. And technology at that time was taking about six days to detect it, identify it, shut it down, protect. So you had thirty-eight days. Great. But the talk I gave six months ago said that that time span, the forty-four days, can now be three hours. So, you know, if you're detecting and it's taking you six days to remediate it, that's no good. But why it's really stuck in my mind is literally last week, I was at this event with the Cyber Risk Institute, and we've gone from forty-four days to three hours to forty minutes. And that's three hours to forty minutes in the last few months. It's just the way that the way that, I guess, AI is being used to increase the complexity of things, increase the actual effectiveness of attacks, unfortunately, and massively increase the speed and the way it actually proliferates across the world.
(Nick Calver at 00:02:12) So AI is having a big impact on the actual threats that we face. So you need security. You have to fight AI with AI. So that was, I guess, one of the elements of those threats. The other element is over 50%, I think it's about 54% of companies at the moment, they have AI applications installed on their network that they don't know about. There's all sorts of statistics, and everyone will pull off. But the reality is I've got a lot of applications on my phone. My children have got them on their iPads. All sorts of things. AI is everywhere, and you need to understand what you've actually got. So to come to Palo Alto Networks, we believe you have to basically go back to basics, and you have to be secure by design. Get that design right in the first place. Understand what you're actually facing and where you want to get to. We often talk about zero trust and the ZDNA and all those sorts of things, and some people don't like the term zero trust. There's lots of emotion around it. But the reality is you have to authenticate and validate every single element. But when you get down to, I guess, understanding you've got your architecture and you're secure by design, you need to know what you're actually securing. So you need to have full visibility of everything. There's no point in me saying my iPad's secure, but my iPad's shut. I don't know what's going on. I don't know what's installed. I need to look. I need to have visibility of every single thing that's happening there. And this is where, I guess, going back to Palo Alto Networks, we have that complete visibility of every endpoint, every element.
(Nick Calver at 00:04:02) And, actually, I'm sitting here staring at my browser. We have a product called Prisma Access Browser. And, again, you've got the complete security there. And just to, you know, from last time, quick funny story. I've been at Palo Alto Networks about fifteen months now. I sold some shares through my company share scheme last year. I used, from the E-Trade account, E-Trade works fine, so no issue mentioning their name. But I transferred them to one of the online banking apps, and I won't mention which company. And then I transferred from that banking app to my, I wanted to come across to my banking app Barclays. And the first time I did it, it worked fine. So I then transferred some money out of E-Trade into the online banking app again, and the money disappeared. And it just wasn't there. So I contacted the banking app support team, and you can only do that. You can't talk to them. You have to do it via AI and app.
(Nick Calver at 00:05:06) So we got through, and they wanted to see evidence. It took a month to get to this point, so the money was missing for a month. And we were sort of sending this element through. Said, try and send some data, some reports, and some evidence, but they wanted screenshots of the actual transactions. The only place I can log on to my E-Trade account is on my work laptop. My work laptop is secured by Prisma Access Browser. So I went in, I did the thing. I took the screenshots, then I tried to send those screenshots to the online banking support team. And that's when the shutters came down, the alarms sounded, my boss is on the phone. What are you doing trying to send data?
(Nick Calver at 00:05:51) So it was nice to see, in some ways, our security, our systems, really in detail protecting us. It was also really painful for me because I wanted my money. It was also really embarrassing for me being quite new to the company, my boss ringing me up. All these things are, but technology is there to protect us. And if it works effectively, it should be in the background and it should be seamless. You know, you're buying technology to monitor, to protect you. It should just work there. You don't know about it. But when you do need something, when it spots something, you want it to be there, and you want it to be effective. And I can't complain about what it did.
(Joel Beasley at 00:06:29) This is a product that Palo Alto Networks invented?
(Nick Calver at 00:06:33) It's a company. We bought a company called Talon. And the founder of Talon is Ofer Ben-Noon, and he's this extraordinary individual, just an inspirational character, and one of these startup geniuses that we often come across. But with Talon, Palo Alto recognized that there was a need for secure browsing. And the business, one of the business cases for that is there's lots of companies growing by acquisition, so they buy another company. And suddenly, you're inheriting all the security risks of the new company, all whatever security, however they access their applications, transmit their data. What you're able to do with the secure browser is rather than let them use their laptops, run everything through the browser. Just give them the browser so that they can then access their systems, but in a secure way.
(Nick Calver at 00:07:27) But coming back to the Talon story, which is fascinating. Great technology. We bought it, but something Palo Alto Networks do, which separates us, really differentiates us from the rest of the market is rather than just buy a product and put a label over the door, like buy a house or something and you just change the name of it. We reengineer. We rearchitect. We make sure it actually fits our core architecture because we often use the phrase "secure by design" and, yes, that's an industry phrase, but we actually live by those values. And so it's rearchitected, then it's actually built in to our suite of products. So it integrates more effectively so you don't get these integration issues. You don't open up loopholes and gaps by accident. Everything is secure by design. And so we have brought Talon in. It's now called Prisma Access Browser. It forms part of our SaaS suite, and it works very effectively. Now I'm talking to a lot of customers at the moment who have rolled it out or are in the stage or in the process of rolling it out.
(Joel Beasley at 00:08:35) Yeah. Well, it's good time to have that conversation because so many people are trying to figure out how to deal with security around these new tools and GenAI. Is this tool that you were just talking about, is that built specifically for that, or is Palo Alto Networks building something specifically for helping with all this data everywhere and going into GenAI systems?
(Nick Calver at 00:08:57) There's lots of things going on. I guess, did we buy this specifically for that? No. We bought this to provide a secure browser capability and to secure the endpoint for customers. We're now investing in other AI companies, and there's been some announcements in the press of recent acquisitions. We are looking at code to cloud. So, basically, from creation of code, making sure that's actually protected all the way through to cloud utilization. In reality, probably every single element of an IT journey with Palo Alto offering protection is one of the great things about actually working here. And one of the reasons I joined here is Nikesh, our CEO, he is extraordinary. And I think it was in about February, March 2024. He went to the market, and he announced something called platformization.
(Nick Calver at 00:10:03) Platformization, there's probably two elements to it from my perspective. There's a lot more elements to it, technically, and I can let the experts communicate that. But the thing that I like from my perspective was it enables you to consolidate. There's lots of legacy problems, companies having anywhere between sort of thirty and eighty products that you can consolidate into five or ten. So there's a massive opportunity for consolidation. And, I love my cars, and I have these various cars, and I have a Land Rover Defender, which is great for the family and the dogs and off-roading, and then I have a nice sports car, and then I have an old classic car because I'm an old man, and I like to restore things and play around. You have all these specific tools for the jobs, but the reality is I could use the different cars for the same thing because there's an awful lot of overlap there. And the same is true of products, where when you actually look at it, if you got three products, there's probably only 10% difference between them. So if you lose two of those products, you consolidate on one. You need to understand. You need to be clear of the use cases you may be compromising. But I think where Palo Alto Networks comes in, it tries to reduce that compromise. So there's very little you're actually giving. We cover everything, and you're able to consolidate. And the level of consolidation can be extraordinary.
(Nick Calver at 00:11:36) I saw one recently with a big European customer. They were looking at spending well over 100 million over the next four or five years on their technology. And by consolidating what would have been seven products into one in this particular instance, they were looking at saving 60 to 70 million. Now, normally, we see 20 to 40%, maybe 50% of some of these really complex savings on platformization. But there is that real technical consolidation.
(Nick Calver at 00:12:11) The bit that really excited me, which probably shows how sad I am that I get excited about these things, was Nikesh also said, if we are going to consolidate, you often have contracts. You know, you've got your phone contract or your car contract, and those contracts have a date, they have an end date. And when you want to consolidate, those dates never tie in. You know, I'm going to change, I want to change my mobile phone. You got another six months to run. Yeah. But I've seen this really nice phone, and I want it now. Yeah. But you're still going to have to pay the bill for another six months. What Palo Alto Networks do is okay. So you're going to come into a five-year contract with us. So you've got another year to run on your existing contract with company A. We won't charge you for that functionality for the first year. So, yes, you'll enter into a five-year contract, and you'll pay us four years for that functionality, and you'll pay us five years for the new functionality. But what it means is from a customer perspective, there's no double pay.
(Nick Calver at 00:13:13) And when I was at HSBC and I was running the cost optimization program there, the number of vendors who would come to me and say, come and buy our product, Nick. It's great. You know, ours is blue, and theirs is red, and ours is so much better and faster and all these wonderful things. But I'd always have that conversation that that's great. However, I've got product A already, and I'm tied in for a year. So if you give me your product free, I will happily displace product A. So I know yours is better, but I will pay you when I stop paying them. And none of the vendors were able to meet that challenge at that point in time, which is around 2018. Now Palo Alto are the only company that I know of that publicly recognize that. They understand what it means to actually run a business as well as to secure a business. And that financial element was one of the key things of me actually joining. I think not only have they got great technology, they've got a great commercial knowledge, and they're willing to be bold and brave and actually go out there to help customers ultimately. So, yeah, platformization is just huge, and we're seeing more and more evidence of that across the industry. I can talk for hours. I'll let you ask another question. Sorry.
(Joel Beasley at 00:14:39) Well, I was curious about the 72% of workers uploading company data to GenAI platforms, mostly because that's what I hear a lot of. I get to talk to a lot of technical leaders, and everyone is kind of experiencing this thing at this time right now where they can see the benefit. We can use them, Nick, in our personal lives, right? And, like, see the benefit of them. And then we're supposed to show up to work nine to five and not use it there unless it's a special version by the company. It's making shadow AI a thing, right?
(Nick Calver at 00:15:14) Shadow AI will always be a thing. And as a programmer, I'm going to take you back a few, I might take you back to when before it...
(Joel Beasley at 00:15:30) It is that old. Time machine. Let's go.
(Nick Calver at 00:15:32) Time machine. Yeah. That would be great, wouldn't it? I worked with a guy at an insurance company. And the guy was called Roy Wilkes, and I, he's a friend, and I know he's retired now, because it was thirty to forty years ago. This is how long ago this was. And we were running batch jobs. And when you talk shadow IT and shadow technology, he was a genius with the assembly language. He knew machine code. He was really in the machine. So he, you had a suite of batch jobs, maybe a hundred jobs. The first couple of jobs that he would run, they went in and they reconfigured the mainframe, and they reconfigured the storage devices to give his jobs priority. Anything with his name, with his footprint, they came to the top of the list. They got access to all the resources first. Everybody else got pushed out. And I didn't know anything about this until a few years later, Roy had left.
(Nick Calver at 00:16:36) Technology had moved on, and we'd upgraded these storage devices one weekend. And the jobs ran, and they failed. And they brought me in, and I was good technically at the time. And I just couldn't figure out. There was some really strange errors. So I gave Roy a call because I knew he knew those programs. Even though he'd retired with friends, he said, oh, yeah. And then I reconfigured the mainframe and the storage devices. All you need to do is take these lines of code out. So you talk about shadow AI. He created his own motorway. There was nobody else allowed in his lane at the motorway. He had complete free reign from East Coast to West Coast. So a very smart guy. He is extraordinary.
(Nick Calver at 00:17:16) Now there are the modern-day equivalents of those. So you're never going to stop shadow AI because there are these people there. But then if you start to, I guess, bring in that secure by design as the initial principle, so you understand what you're looking to deliver. You understand the policies that are actually there to protect you. You then have the complete visibility.
(Nick Calver at 00:17:41) So making sure you understand what AI—we know what AI applications are installed on every single endpoint in our network. We have complete visibility. The browser that I'm working on at the moment manages that visibility or helps form part of that. So we have all that visibility there. We also have a mechanism where, if you download whatever crazy AI app you're using at home, you may want to use that at work.
(Nick Calver at 00:18:14) We have the ability to basically then listen to our employees, our teams. So, yeah, if that makes business sense, we've got no issue with you installing it, but we want to actually run it through our processes, validate it, make sure it's there, make sure it's safe, and then it can actually be on the catalog that you can use. We try to make that process easy and fast, which I think—if you make things simple to actually do, you can avoid most of the shadow IT. Because the only reason people are going down that route is because they just want to get stuff done, and they want to get it done fast, and they're impatient, which I've got no issue with. But it needs to be with that balance of making sure we give them the agility they need, but also making sure we still manage the security they want.
(Nick Calver at 00:19:00) But the data that's also being loaded into AI—well, we're using Gemini. We're using various AI tools now. We've had some training this week. We're starting to use AI much more ourselves because it does take the brunt. It does some great work and some great things.
(Nick Calver at 00:19:19) So why wouldn't we embrace it? We have been—Palo Alto Networks, I've actually been using AI for over ten years, LLMs, et cetera, inside of our technology. So we've built up this data lake, and we've been, I guess, early users, early adopters of AI. So I think we're at the forefront. So there's nothing stopping us from using AI, but it's got to be used in the right way. You have to have full visibility, transparency, and have your policies and procedures in there.
(Joel Beasley at 00:19:45) Absolutely. No, that makes complete sense. My favorite meme with the AI stuff is where you see there's the boss and the employee. And the boss is like, "Oh, look how cool AI is. It took these bullet points and it made them into this long professional email." And then on the employee side, it was like, "Look at this AI. It took this long professional email and turned them into bullet points." That's my favorite meme.
(Nick Calver at 00:20:08) Yeah.
(Joel Beasley at 00:20:09) We've got to let the people use it, though.
(Nick Calver at 00:20:12) A hundred percent. And it's fascinating. The positive benefits that it can bring to society. A friend of mine is running a medical AI that's analyzing patient data and effectiveness for drugs. And so if you start to actually correlate and you can see that the different genetic types that we are, and you can start to understand the different impacts—the positive impacts or negative impacts of drugs on certain genetic types—then suddenly medicine becomes far more effective.
(Nick Calver at 00:20:49) And another friend that is—I've got quite a few. There's a guy called Professor Mark Lowdell. And I used to travel with Mark on the train for about five years. And I've got to ask you a question, Joel. So I got on the same train at the same time every day for a few years. And what that meant is I sat in the same seat because I was a first stop. And I sat in the same seat, and my friend sat in the same seat as well. So we got talking every year. Mark took cancer, and he basically reengineered T cells. So you had custom-built cancer cures which were targeted to your genetic structures.
(Nick Calver at 00:21:37) And he did that a few years ago. This was 2018, 2019 time. If you imagine that or reimagine that with AI taking that data source, just think how much more effective or how much faster that revolution and what he's done in some of those cancer treatments. And now they're out there in the public. They're saving lots of lives, very high success rates, but it's a very personalized cancer response.
(Nick Calver at 00:22:06) So, yeah, once we get more of that data available, I think then the opportunity to save more lives, enrich people's lives is just huge.
(Joel Beasley at 00:22:15) And what's his name?
(Nick Calver at 00:22:17) He was Professor Mark Lowdell, L-O-W-D-E-L-L. I think he may have retired, though, because I see pictures of him on Facebook sailing his yacht around the sea. But he, yeah, he's an extraordinary guy and, yeah, just had some big challenges there.
(Joel Beasley at 00:22:37) Yeah. What are you doing this weekend? I'm just solving cancer, then taking my yacht out and sailing across the country.
(Nick Calver at 00:22:44) I know we're drifting off and we'll come back on to the side. He reengineered—he stripped the cellular markers on organs where he was then transferring. He basically saved lots of children's lives. He specialized in children and replacing their throats, so he would decellularize, if it's okay to say, a pig's throat. And then they would implant the pig's throat by recellularizing it with human cells.
(Nick Calver at 00:23:11) And I'm not the medical professional, and it's a conversation on the train. But, basically, yeah, he was able to save children's lives by giving them new throats without any rejection because he was just removing everything that would cause them to be rejected. That's so—
(Joel Beasley at 00:23:29) That is pretty cool. Yeah. Well, there's got to be a—let's see if we could tie that back in. There's got to be a lot of regulation when replacing children's throats with pig throats, and there's a lot of regulation in AI.
(Nick Calver at 00:23:40) Yeah.
(Joel Beasley at 00:23:40) There we go. So smooth.
(Nick Calver at 00:23:42) Regulation is extraordinary at the moment. Again, my brain works with people. There's a guy called Stephen Bonner. Stephen was the CISO at Barclays Bank when I was the CISO at Lloyds Bank, and we were under threat from LulzSec, Anonymous, some of the terrorist organizations. There were all sorts of things going on, and we used to share information.
(Nick Calver at 00:24:11) And Steven and I, his career path, I guess, moved a little bit. I know he went into consulting. Steven now works at the ICO, the Information Commissioner's Office, in—I think he's deputy chair, so a very senior position. And I spoke to him recently, and I was talking about my concern about, I think, where threats are and where regulations are. It's probably about eighteen months apart because a threat that we identify now, that needs to be fed into the regulation.
(Nick Calver at 00:24:44) They need to build a policy or a capability around that. They need to validate, ratify, communicate. So it takes time, and that's fair and reasonable. And so my big concern is that the threats are here and the regulations are eighteen months behind. But Steven, in a sort of conversation, he said, "But what you could understand, Nick, is we were in the big banks with huge budgets and all these things, and businesses are battling."
(Nick Calver at 00:25:08) Businesses absolutely support regulation, but they need to make sure they're actually trying to catch up. So businesses are still fighting there. And you look at DORA, the Digital Resilience Act. This organization, it was due to be enforced some time ago, and the regulators are now going out and now actively enforcing it. But gut feel, there's still organizations who aren't fully compliant, and they need to move forward.
(Nick Calver at 00:25:37) And last week, at this Cyber Risk Institute event, there's a great guy called Josh Magram who's the CEO of that, and he's trying to basically look at the business outcome that you want from regulation. Ultimately, the key one is you just want to protect customers. But that's such a huge one, so it may be that you have recovery. There's all the different regulations in there. But at that meeting, there were representatives from the PRA and the FCA.
(Nick Calver at 00:26:07) So the UK regulator's Financial Conduct Authority. And they were really—I guess, they're leading with those conversations around AI and other elements. They're very aware of the situation. But we did have a long conversation of the regulation and threat. And, ultimately, what I've seen is Palo Alto Networks, actually.
(Nick Calver at 00:26:34) We have a team called Unit 42. They're our security specialists. They're the—lots of them are ex-government employees. They're absolutely amazing people and completely committed to securing people's futures. We use those people to actually come in and investigate, do a threat-based assessment.
(Nick Calver at 00:26:59) So when I was at Lloyds, I only had the regulation. So I knew to measure my effectiveness, I'd measure how I looked against the regulations. What Unit 42 is, they can come and they can say, yes, you ticked the boxes on the regulation side, but, actually, the threat is over here. It's almost like you shut your front door, but your warehouse door is open.
(Nick Calver at 00:27:21) People can just wander and take what they want, do what they want. There's no security cameras and walk out the building. What Unit 42 is is they actually understand where the likely attack vectors are. They identify them. They report. If they see something urgent, they're all responsive people. They'll make sure it's shut down. And then they work, and they come up with sort of proactive plans. And it's a prioritization thing as well—where's the biggest risk? Where's the biggest threat?
(Nick Calver at 00:27:47) The nice thing about them as well is they can be industry specific because I guess everybody's seen the Scattered Spider attack in retail in the UK with several big firms actually being hit. Whereas, yeah, they are potentially moving their focus into other industries. The Unit 42 people know what's going on. They have an awareness, so they're able to actually provide a more valuable service.
(Nick Calver at 00:28:15) But those threat-based assessments combined with the regulatory assessments, I think, are critical for any organization if they want to protect themselves. And, yeah, Palo Alto Networks' Unit 42 team, I've worked on them on a few accounts now. They've been absolutely fantastic.
(Joel Beasley at 00:28:32) So they do, like, client-facing work. They're not just the internal team at Palo Alto Networks. They also—you can hire them.
(Nick Calver at 00:28:40) They work primarily outside of Palo Alto Networks. So they work primarily with the customer. They're in with customers. They can do red team events. They can do purple team. So they're doing all sorts of stuff, but they do have an extraordinary knowledge. And lots of them volunteer for various other things as well. So as well as doing their positive work for Palo Alto Networks and our customers, I know a few of them are actually doing a lot of community work as well in helping our country. So, yeah, they're an extraordinary group of individuals and so proud to be part of Palo Alto Networks, which employs them because they do such great work.
(Joel Beasley at 00:29:20) I'm never going to say anything bad about them. I like my passwords being safe.
(Nick Calver at 00:29:27) Yes. Yep.
(Joel Beasley at 00:29:27) Yes. Tell me about the Cyber Risk Institute event. Is that something that's already happened? Are you speaking there? What is that all about?
(Nick Calver at 00:29:34) It's something that happened last week and actually—in fairness, because of the industry I've been working, I probably got into this about eighteen months ago. And there's a guy called Josh Magram. And Josh worked in industry and worked in consulting. But he was seeing—he was seeing the different countries come up with different words for regulations, but ultimately wanting the same business outcome.
(Nick Calver at 00:30:02) Can you recover your database within one hour? Have you got multiple cloud resilience? The various things that were coming up here. And Josh took quite a bold step, I think, to found the Cyber Risk Institute. So it's a nonprofit organization which has members.
(Nick Calver at 00:30:20) Those members are organizations. I think—I probably need to be careful on who I say, but I know a lot of the big banks. The banks that you all know, the big banks in Europe, big financial organizations, all sorts of other organizations. They are members of the Cyber Risk Institute, so they pay a subscription. And what Josh does is takes the regulations, the existing ones and the new ones, the ones that are coming out. And he has basically built a diagnostic tool, a profile that says, if you meet our profile, then you will be compliant with regulation A, B, C, and D.
(Nick Calver at 00:30:57) He's also lobbying government bodies and looking, actually, working with those guys to see whether they'd be willing to just use the CRI. And you can imagine the SEC or the FCA. They'd be cautious about that, but I know that they are talking and they're very aware. So Josh is at the heart of quite a big movement, really, and as a nonprofit organization there to provide regulation which will actually help everybody. And the other thing that the events I've been to is—I'm in industry now.
(Nick Calver at 00:31:32) It's just the networking because it's a TLP Amber or TLP Red. Are you familiar with the terms there at all? Or no. TLP is Traffic Light Protocol. So if it's Amber, it has a certain level of confidentiality. If it's Red, it's highly sensitive, and you don't share. So you're in a trusted, secure environment where I think people have got respect. And so there's a lot of networking, a lot of conversations, not strictly, you know, confidential information that will expose anybody, any organization, but really just common sense sharing of where are the trends we're seeing, where are the problems we're getting, what are you doing to solve this? And that networking, those conversations will really help organizations move forward. So I think it's a great idea.
(Nick Calver at 00:32:22) I think Josh has done very well. He works very closely with Palo Alto Networks as well because what we're finding is we're taking some of their diagnostic material and building the reporting into our products. So rather than somebody come along after the event and say, "I want to see what you've done on securing your cloud or key rotation. I want to see your dynamic key rotation. Give me evidence."
(Nick Calver at 00:32:48) We're building reporting capability into our tools, which means that it's there automatically. You just push a button. It's there. You don't even need to request it. It's just there. So suddenly, it makes compliance and regulations a lot easier. And I haven't seen other companies do that yet. I'm sure there'll be somebody out there. It really does actually help organizations work with the regulators, provide them the evidence to give them the confidence that we're all doing the best to protect our customers.
(Joel Beasley at 00:33:17) What's one of the most interesting security improvements or enhancements that you've come across lately?
(Nick Calver at 00:33:24) Oh, that's a really tough question. It's interesting because I'd probably—it's not that. I know with our recent purchases of the AI protection organizations, but I'd probably come back—well, actually, there's probably a couple of things. Prisma Access Browser, we've already talked about. I just love the simplicity. It's sort of like getting a first class ticket on a plane for, like, a dollar. You've got the best technology, the best service for virtually no money, and it's just so easy to use, and it's actually there. The other elements, the big moves, I think, with Palo Alto is bringing together our cloud and our Cortex business, which is basically our XDR, our AI SOC capability and all the monitoring capability. By bringing everything together into a single platform, you're starting to get much better visibility. It was great before, but now there's complete transparency.
(Nick Calver at 00:34:28) And it's a shame I actually can't show you the Cortex XSIAM demo because I love the screen where you basically have your feeds, and I'm looking at sort of back to front here. So put on the left-hand side, you'd have all your inputs. They're feeding in through a number of processes into our systems. And then out of that, 99% will be automatically handled, more than that actually. And out of the thousands of alerts, you'll have a few that need human intervention or need action. So it's all automated, the visibility and the depth.
(Nick Calver at 00:35:04) And I think it just keeps getting better. And with AI and the data lake that's actually building up, going back on some statistics that I saw in this old deck, we were looking at — we were dealing with over 12 billion alerts a day. That's 12 billion and several million unique new attacks every single day. And those statistics, I am confident, have changed.
(Nick Calver at 00:35:34) I'd love to actually get the latest figures. I can only guess you're going to be north of 15 billion a day, and maybe, I don't know, four, five billion. The numbers are maybe beyond human comprehension, if that makes sense.
(Joel Beasley at 00:35:52) That's what we're — humans are really bad at large number comprehension. You know? We're good at three of these, five of these, ten of these. We can make it through the thousands and the millions just because of finance and some — we can kind of understand. Once you get into the tens of millions, that's so hard to understand.
(Joel Beasley at 00:36:04) You know? Question for you. So, you're in the security world. I'm assuming that there's definitely people that are specifically training LLMs for security attacks. Right? Like, if I'm a bad guy, I'm out there. I see this technology. There's no way I'm not going to get an LLM and customize it and train it in a way where it's going to help me perform attacks more efficiently, and then let it go out on its own and do as many attacks as it could do.
(Nick Calver at 00:36:39) It's interesting because yes, I'm in the security world, but I'm probably operating with the regulation. I'm operating in a different area there. We'd need, I think, to bring our product experts in there. But I think from a common sense perspective, you're absolutely right. You've got LLMs. You've got AI. That's what's generating. That's what's taking the forty-four days down to three, four hours, down to forty minutes. That is AI. There is no question. The 12 billion attacks, that is AI. The fact that we used to see it take days for an attack that may be in Asia to be replicated in America, that's now seconds. So yes. So when you get into maybe the specifics of your question, can I answer that? No, because I'd rather be — but just common sense says there is no question that's happening.
(Joel Beasley at 00:37:33) Oh, yeah. I know they're definitely doing it. That would be actually a good — a good — you know, I'm always, Nick, I'm always a little bit scared to reach out to the security guys to do interviews with them. Like, I've thought so many times, it's like, let's go find some of the best hackers in the world and interview them. And then I'm like, I don't think I want to send them an email.
(Nick Calver at 00:37:52) I'm definitely not one of the best hackers in the world. I did meet one of the best hackers in the world in Europe the other week, and he was introduced to me by a friend. It's interesting, actually. IT is a small world. I joined Palo Alto Networks, and there's a guy there called Colin Ferguson. And Colin, I remembered him, and he remembered me. And I got my phone out, and he used to work for Splunk. And I had all the text messages that he'd sent me trying to sell me Splunk when I was at Lloyds, and it was all these things. And there was a mention in there of you need to meet Susan, our chief revenue officer. And I worked for Susan. Susan's at Ledger, Ashley Gorton. Susan is just one — an amazing person. She really is. But all these things. But, no, Colin introduced me to this guy. I can't say his name. I won't even say which country I met him. But he said this guy is just absolutely extraordinary. And he's the only person I've seen, and I — I can't — I'm just checking the back of his card. Yeah. No. I'm not even sure the back of his card. I have his business card, which I think is unusual. But have you ever — and I'm not sure if I should even mention it, but I will — he had a Threema ID. Have you heard of Threema at all?
(Joel Beasley at 00:39:19) No. No.
(Nick Calver at 00:39:19) And neither did I, so I Googled it, and it's a secure messaging service. So I've created the account to Slack. Doesn't cost a lot. You have a one-off fee. It's just a secure message. And there's lots of this that people have heard of — Signal and other things.
(Joel Beasley at 00:39:38) Yeah. I have Signal.
(Nick Calver at 00:39:38) Yeah. There's a coin. But in my mind, is this guy's one of the top positive ethical hackers in the world? If he thinks that's safe, then, yeah, I've signed up. I've got an account with him now. But —
(Joel Beasley at 00:39:52) There's been so much conversation about Signal being owned by an intelligence agency, all this. There's a lot of stuff out there in the world. But, yeah, secure messaging is something that I believe in. I believe we should be able to have private and secure messaging.
(Nick Calver at 00:40:07) Definitely. Yeah. Without a doubt. And it's interesting when you talk about the side of things there regarding messaging and social media. I guess the things that we see at Palo Alto Networks, the things that I see on a daily basis, my children have picked up on that. So where you get onto social media, yeah, I let them use TikTok. They'll see stuff on there. But they can discern — they start to actually, I guess, analyze who benefits from that. Because you often see the fake memes with some very senior leaders in the US who are having a debate at the moment. And you know what's fake and what's actually real. And so —
(Joel Beasley at 00:40:57) Okay. Well, you said that so well. I almost didn't catch it.
(Nick Calver at 00:41:00) Yeah. It's a strange world out there. And I guess, yeah, you just need to filter through what's real and what's not. And, yeah, having the data, having the information there, it is — it's great working for Palo Alto. I love the culture. I love the tech. And I've learned so much, but I've got so much more to learn. And, yeah, it's helping with the family, and I'm even encouraging one of my youngest son. He sort of said, well, can I come and work with Dad at some point in the future? So we'll — who knows? We'll see if I can get him in there. But —
(Joel Beasley at 00:41:32) Yeah. Now have you noticed in your — let's talk about just your personal life. You're a tech leader. You're in security. In your personal life, have you been using Grok or any of the major models on a daily basis? Have you started doing that instead of going to Google? Anything like that?
(Nick Calver at 00:41:51) No. No. I tend to use Gemini at the moment and just use Gemini. But my son is interested. My son's using ChatGPT Plus. So he's — my son's using it. I'm paying for it, which is normal as a parent.
(Joel Beasley at 00:42:05) Oh, God. Well, it depends. If he's thirty, it's not.
(Nick Calver at 00:42:09) He's twenty, and he's using it for university, which is quite — that's a complex thing as well. So —
(Joel Beasley at 00:42:18) It's complex because it's an old system that is trying to adapt overnight. It's going to be messy and hard, but yeah.
(Nick Calver at 00:42:25) Yeah. It's interesting that when you just — one of those things in the IT side of things, and we had the personal conversation. The almost a digital detox and the disconnection. I'm — well, if there's a problem or a customer problem, I am available twenty-four by seven. But there are times where you need to maybe just step away from the tech and, yeah, just enjoy nice times. So with my family, we'll have a Saturday evening where we'll just do something together with no tech. The phones are banned. They're in the corner, so if there's an emergency work, that's fine, but they are banned and, you know, this maybe — it's something that — I don't know whether you do that at all and actually switch off for that at any point. But it's a —
(Joel Beasley at 00:43:09) Oh, yeah. It's tough. We will do it. It's not always, but it's when we need it. Right? We'll just all feel it. We'll be like, alright. We're putting the tech away for the weekend, and we're just going to go do this. And, you know, unfortunately, it is part of our everyday lives from schooling to just work and email. So it's more about having that focused family time together. Like, there's no technology at the dinner table, and we sit down and make dinner every night together. So there's definitely times.
(Nick Calver at 00:43:42) And on the other side, it's interesting from a work perspective, I like the flexibility. Like, I'm going to be working tonight. That's fine. I've got something in my mind I want to do. It takes stuff to the weekend, so it's having the flexibility in the modern world with technology is, I think, really beneficial as long as you — as I think we had the discussion last time of putting those boundaries and those controls so it's not seven days a week, eighteen hours a day. There needs to be some downtime.
(Joel Beasley at 00:44:12) Oh, you can become an addict real quick. You know?
(Nick Calver at 00:44:14) Yeah. Yeah. Yeah. But it's just getting that balance right, really.
(Joel Beasley at 00:44:18) Well, this is great, Nick. You are a friend of the show now. Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn, or send me an email — [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.