Episode 817 ·
Exponential Advancements in Security with Steve Orrin, Federal CTO at Intel
Today, we’re talking to Steve Orrin, Federal CTO at Intel. We discuss the government’s grasp on AI, how cyberattacks are getting wildly more advanced, and how Steve thinks as a top CTO.
All of this right here, right now, on the Modern CTO Podcast!
To learn more about Intel, check out their website here: https://www.intel.com/
Produced by ProSeries Media: https://proseriesmedia.com/
For booking inquiries, email [email protected]

About Steve Orrin
Steve Orrin offers three decades of extraordinary success in a series of high-level roles at top-tier companies that include Intel Corporation, Sarvega, Watchfire Inc., Sanctum Inc., First Genetic Trust Inc., Lockstar Inc., and SynData Technologies Inc. He has developed a reputation as an industry leader, leveraging a history of delivering results in Innovation, Intrapreneurship, and Entrepreneurship. He is a Tech-enabled business professional who has launched and scaled companies and brought innovative industry-leading products to market.
Steve’s invaluable expertise and broad business range have powered a history of developing successful products, technologies, and new markets. Such traits have consistently enabled Steve to achieve an impressive command of the skills needed to manage ongoing business planning processes while developing strategies to meet future challenges.
As the Federal Chief Technology Officer and Senior PE for Intel Corporation, Steve orchestrates and executes customer engagements in the Federal space, overseeing the development of federal solution architectures to address challenges in government enterprise, national security, and other federal areas of focus.
About Intel
Intel’s mission is to shape the future of technology to help create a better future for the entire world. By pushing forward in fields like AI, analytics and cloud-to-edge technology, Intel’s work is at the heart of countless innovations. From major breakthroughs like self-driving cars and rebuilding the coral reefs, to things that make everyday life better like blockbuster effects and improved shopping experiences — they’re all powered by Intel technology. With a career at Intel, you have the opportunity to help make the future more wonderful for everyone.
Transcript
(Intro Narrator at 00:00:00) Today, we're talking to Steve Orrin, Federal CTO at Intel, about the exponential security advancements in the federal sector and beyond. You're listening to Joel Beasley, Modern CTO.
(Joel Beasley at 00:00:18) So what's your official role?
(Steve Orrin at 00:00:20) So I'm the Federal CTO for Intel Corp.
(Joel Beasley at 00:00:22) And what does that mean?
(Steve Orrin at 00:00:23) So as Federal CTO, my job is to represent all of Intel's technologies, capabilities, and solutions for the federal ecosystem. So that's the federal government, the system integrators, and manufacturers that service—we call them the defense industrial base—and the federal portions of the OEMs, like Dell Federal, HP Federal, and the like. And my job is really to help the government adopt the technology, plan for what's coming next in the technology roadmap, understand the nuances of different architectures and ecosystems, and really as an advisor to the federal government to help them achieve their mission and enterprise goals, whether it be performance, security, how to take full advantage of AI. Because for the most part, the government doesn't buy direct from Intel.
(Steve Orrin at 00:01:11) They buy through the channel and through the ecosystem. They buy planes from Lockheed. They buy servers from Dell and HP, and it's Intel ingredients inside. And so we work closely with the government and with that channel to help them get the best out of the systems they're purchasing and plan for the next generation of architectures.
(Steve Orrin at 00:01:30) Have you guys gotten into nuclear at all? So nuclear is really an area that's separate. The government has tight controls on and export controls on those, so we don't do much in that space.
(Joel Beasley at 00:01:42) Okay. Cool. Cool. I've been particularly excited about it. I've seen all these new startups get funded.
(Joel Beasley at 00:01:48) One's publicly traded called Nano Nuclear, and just watching what's going on in that space to me is very exciting as a nerd.
(Steve Orrin at 00:01:57) And the fact that they're looking at that from an energy production perspective now—again, there was that article a few weeks ago about Microsoft looking to get Three Mile Island back up and running to do data center. It's an interesting play. There's a certain amount of FUD that we as a society have been dealing with, but I think Europe has really embraced it. And so it may be time for America to look at that again.
(Joel Beasley at 00:02:25) Now, so I'm 36. Right? I got a young family. I got three kids under 10. And when I look at Congress or Zuckerberg trying to explain technology to some of these people, it is just depressing for me.
(Joel Beasley at 00:02:39) You're in it, you're eating it, and breathing and sleeping it all day. Does the government have a decent understanding of AI or no?
(Steve Orrin at 00:02:48) So it's an interesting question. I want to expand it a little bit. So the question is, does the government—and there are absolutely people in government who have a firm understanding of the technology, are trying to apply it to their day-to-day missions, to the enterprise, to the data that they're having. And then, obviously, there are folks in some of the executive leadership that are a little bit more removed from the day-to-day technology. And I think what you find is there's groups of folks that get it and understand it, and the groups of folks that they've seen the articles, but that's about the level of their understanding.
(Steve Orrin at 00:03:22) It's been my experience that the ones that don't understand typically have staff that do. And so, I'm not going to pick on whether it's Congress or executive leadership at any agency. But even if that individual leader doesn't have a firm grasp on the nuance of these technologies, if you look at the people who are supporting them, helping to write the policy, they hire the right people. They've got a team of young professionals who are digital natives who understand the technology better. That being said, I think the industry writ large is still trying to understand what does it mean to take advantage of AI.
(Steve Orrin at 00:03:58) You see the hype, you see, well, yes, you apply AI and it will solve all your problems. Well, no. That's not actually true. And we're starting to see some of that where there was a large uptick in acquisition of AI technologies, both the hardware, the software, the solution sets.
(Steve Orrin at 00:04:14) And the next question that a lot of people are asking now after I've been playing with this for a couple years is, okay, where's the value? Where's my return on investment? How much utilization am I actually getting out of this infrastructure? And that's sort of the, in business terms, the crossing the valley of death problem. You know, we have all these great exercises and demos and really cool widgets that we can use online, but how does that translate into something that saves me money, executes the mission faster, saves lives, whatever the industry is?
(Steve Orrin at 00:04:43) And it's that transition that we're seeing a lot of people struggle with of how do I actually get value out of this AI? And it comes back to this notion—you can't just say, well, I'm going to sprinkle AI pixie dust on every problem and magic AI is going to solve it all for me.
(Joel Beasley at 00:04:58) You can say that.
(Steve Orrin at 00:05:00) You can say that. It doesn't work that way. Right. And it comes back to fundamentals. A, are you asking the right questions? Or are you defining the problem correctly in order to be able to apply the right set of technologies? And not every AI—sometimes you don't even need AI. Simple machine learning would solve it. And then the other question is, do I have the right data to drive that outcome? You want to do things, but when you actually dive into it and, whether it be a security use case or a certain type of sensors, I want to be able to detect this new kind of threat.
(Steve Orrin at 00:05:34) I want to be able to detect this kind of cancer. The question you have to ask is, do I have sufficient data to train a model to be able to augment what we're doing today? And oftentimes, you find you don't have either the volume or the diversity of data to get you where you need to go. You could do a great little experimental lab, but that doesn't necessarily translate to something that can go scale. And so a lot of the challenges we're seeing people have are in getting it out of the experiment phase and into something real.
(Steve Orrin at 00:06:04) They're just not seeing the return on their investments there. And I think that goes back to poor planning or buying into all the hype as opposed to what is practically achievable and where can we start first? So I think, going back to your question, I think there's absolutely opportunity to see AI in government and in broader private sector and industry. It's picking the right, Goldilocks, use cases to tackle that has the right data that you can answer a question. And then at the end of the day, when you're done, it provides value to the organization or to whoever you're servicing.
(Steve Orrin at 00:06:40) And, a ChatGPT isn't going to solve a mission problem. It's a cool toy, and it can give you answers to questions in the form of Shakespeare. But can it actually give a warfighter information that they need in time of battle? Can it give a logistics person understanding of what their risks to their supply chain are? Those kind of questions require a very concerted look at how do I achieve that goal?
(Steve Orrin at 00:07:07) What is the right data? What's the right implementation? What sensors do I need in order to be able to collect that data? All of that has to go into the planning process.
(Joel Beasley at 00:07:15) Oh, absolutely. I mean, I could totally see how—my biggest frustration is when I meet really brilliant people who are down on AI. Like, they don't like it for helping program. And when I dig in deep, I won't name any names, but when I dig in deep, I find that they heard about it, some headlines, people were talking about it, they opened it up, they typed a few things, it wasn't perfect, and so they just walk away. And I'm like, man, my favorite thing about large language models is you're limited by your own creativity.
(Joel Beasley at 00:07:46) Your ability to prompt it to get it to do something is actually an incredibly valuable skill, because it's the whole GIGO thing. Right? Garbage in, garbage out.
(Steve Orrin at 00:07:56) Garbage out. Absolutely. Yeah. And it goes back to what I was saying, asking the right question or in the case of the prompt there is, what is the thing you're trying to get it to do? You know, if you just say, well, write me code that does all these different things and you don't give it specifics, you're going to get garbage out.
(Steve Orrin at 00:08:11) But if you're looking for—and I've seen some really cool examples of, you know, hey. I need to do something weird with the BIOS. And if it's trained on the right data, so that's step one. You know, let's say I've trained it on the specs of the architecture and the specs of the code for the past 20 years, then I can ask it a particular question. How do I enable this kind of feature in a downstream?
(Steve Orrin at 00:08:30) Like, you have to be specific, and then you'll see the magic will happen. It will actually get you answers that work, but you have to ask the right questions. Or in your example, you have to prompt it with the right set of queries that leads you to what you're actually looking for.
(Joel Beasley at 00:08:45) Oh, even I was getting frustrated with it. Right? Seventeen years as a software engineer. And then what I did was I was like, alright. So I've got these two blockers.
(Joel Beasley at 00:08:56) One, I'm actually trying to put it into practice and I'm not getting the good results, but I'm really making a concerted effort. But two, I hear so many people talking about the positives and how they're crushing it and moving so fast. So I said, okay, Joel. There's a problem. There's a disconnect.
(Joel Beasley at 00:09:11) To solve that disconnect, the way I did it, I watched YouTube videos of people actually building with it. And what I realized is I was using the tool wrong. There's a very specific way to use it that will yield incredible productivity gains and make things super fast. But if you try to just describe a full application, hit go, it's going to take you more time debugging it than it's worth.
(Joel Beasley at 00:09:36) But if you know how to apply it and where to apply it in your workflows, well, now it just now it can take 90% of my job, and I know how to use it. So I think that we're going to see a lot more of people getting exposed to it because we know the technology exists. We see highlight reels and videos and demos, but you have to actually sit down and watch someone who knows how to use it well and then copy them.
(Steve Orrin at 00:09:59) Absolutely. And I think, you know, you've mentioned YouTube, which is a great resource for everything, whether it's how to use a language model to write code or how do I fix the refrigerator that's on the fritz. I mean, it's amazing. But it goes back to—and this is one of the things in that didn't get as much fanfare as all the other executive orders about AI was targeted funding for education and helping to train the next generation workforce on how best to use those tools. Because what you want is a workforce coming in knowing what you've learned in YouTube and being able to then use that as the baseline.
(Steve Orrin at 00:10:38) And I think what we'll see over the next several years is more, earlier in people's education, they're getting exposed to the technology. They're learning it like we learned fundamental programming back in the past. And then when they get into the workforce, they're that much further along and are already the AI native, if you will. And I think this, having the government help drive funding for both university and K through 12 that adds AI to the mix will give us better outcomes downstream.
(Steve Orrin at 00:11:09) But in the meantime, like you said, whether it be YouTube videos or online courses, or I find that sometimes just getting it, sitting down and playing with it and getting familiar with the tools, I like to get your hands dirty. Try it out. But also, like you said, don't say build me an application that does transaction processing. Rather, pick the function that you're trying to do and say, I'm trying to build a Python tool that does, you know, like, get very specific, and you'll find that it has been trained on so many examples that it can give you a fairly decent—now AI code is going to be buggy just like human code. You're still going to do some testing there, and you're going to want to secure it, but it can speed the process. And I think I would offer one change to your term that you used a moment ago.
(Steve Orrin at 00:11:53) It's not going to replace 90% of what you do. It's going to make what you do that much faster and more efficient.
(Joel Beasley at 00:11:59) Yeah. I'm not—just what else are you going to do? Sit around all day? That doesn't work.
(Joel Beasley at 00:12:06) It really doesn't. Like, I don't know anybody that can do more than two weeks of vacation and be okay with themselves. I mean, at two weeks of vacation, my wife's like, please go back to work.
(Joel Beasley at 00:12:21) Right? So I need to get out there into the world. So, um, how do we compare as far as our AI strategy from a federal standpoint to other countries? Are we the most progressive? Are we the least progressive in sense of progress?
(Joel Beasley at 00:12:36) Or like, where do we stand against other countries?
(Steve Orrin at 00:12:39) So it's a really good question, Joel, and I think we have to look at it from a variety of different angles because an AI strategy covers so much. There's the infrastructure to support AI. There's edge education we were just talking about. One of the hot topics is ethical use of AI, reliable use, that goes alongside with privacy and protecting data. So you look at it, an AI strategy, so the U.S. government, the EU, India, China, and others all have strategies that cover all those different domains.
(Steve Orrin at 00:13:10) And so I think when you look at it, the EU is probably in the forefront of data privacy and ethical use. But that goes back to their history starting, you know, before even GDPR. They've been very focused on the citizens' protection of data, the right to forget, and those other kinds of things that drive those kind of policies going forward. I think where the U.S. has been ahead is obviously the technology, for the most part, is being developed and advanced here. So we have a lot more industry involvement. So the technology is much further along. Where I think that the policies are really is, okay, how do we then do the industry government collaborations to take full advantage?
(Steve Orrin at 00:13:52) And so there's a bunch of initiatives out of the latest set of AI executive orders and mandates that came out of the Biden administration and even prior to that that are driving standing up, you know, NSF funding for research into AI, funding into energy-efficient use of AI because let's face it, AI data centers are power hungry as they are data hungry, but also requiring that we have implemented the governance frameworks. And I think in the—if you look at the government's internal policies, which is sort of an indicator of where our government is, that each organization was tasked with coming up with what is your policy for how you're going to use AI? How are you going to use the data? How are you going to protect the—you know, if you're a citizen-facing organization, how are you protecting the citizen's data? If you're a DOD or something, how are you protecting the data, both from privacy and from security as you deploy these kind of assets?
(Steve Orrin at 00:14:49) And so I think one of the key things, and if you look at a variety of the executive orders of the last several years, it hasn't been lofty goals alone. It's been you have a deadline to meet those goals. You have to have a plan. You have to start implementing the plan. You have to apply funding.
Steve Orrin at 00:15:04
So they've laid out a framework which actually helps the government achieve those goals in a much more natural fashion where they're held accountable. They publish—you know, the DOD, when it was tasked, published their AI policy, not just internally, but to the internet. Here's our policy. Here's our seven or seventeen precepts, and here's how we're going about it. And I think that transparency is one of the things that's really been highlighted by the US government.
Steve Orrin at 00:15:31
On the flip side, if you look at some of the other countries, there are some that are much quicker to adopt AI at large scale. China is a great example, but they're much more focused on the benefit to the government, less concerned about citizen data privacy. But they have a different way of valuing citizen privacy than, say, the Western world. And so there's a balance as far as adoption technology versus how do I protect my citizens' rights, how do I—you know, having that as a fundamental right is something that we find in the West. We don't find in every country.
Joel Beasley at 00:16:06
Yeah. I loved what they did with the GDPR and the privacy, and I was team EU when they were coming out with stuff. And yeah, it was annoying, and we had to adapt, but I liked the idea of forgetting the data and all of that. I did enjoy that.
Joel Beasley at 00:16:22
I don't enjoy their laws about saying certain words gets you thrown in jail online. So they kind of missed out on that free speech thing, hashtag why we built America. But yeah, I don't know. I'm pretty excited about the—I did read some of the executive orders regarding AI as they went around on text chains. One that kept coming back to me from multiple different sources was something about model size being reported to ITAR. Essentially, if you have a model of a certain size, it has to be registered or similar to a weapon being a certain size being registered. And when that happened, there was an explosion in the open source community. And it was beautiful to watch because everyone's like, we're gonna get all of these models out there so fast, and we're gonna make them all open source, and you're never gonna be able to put this genie back in the bottle.
Steve Orrin at 00:17:16
I mean, at the end of the day, they're also looking at it from a national security, but also an economic security, and they're—you know, if everyone in the world was operating as a fair and, you know, working for the common good, we wouldn't need some of those protections. But let's face it, there are nation states out there that aren't. And so I think that the—and I'm not gonna comment on the nuance of that particular executive order precept, but I think, you know, just thinking about it from the perspective of—if you think about what is the IP of an OpenAI or with ChatGPT or of Lambda or any of these others, the model and its weights are the power. That's the thing. And that itself is, you know, critical to our economic and social economic success.
Steve Orrin at 00:18:01
So I think there is a concern about those just being given away to adversaries that would use them in ways that maybe don't align to the American value. So that was, I think, some of the nuance behind it. As we've seen with all regulations, regulations are hard, and they typically don't really understand the nuance of technology. And it takes years to figure out—you know, when PCI came out, it took us a long time as an industry to really figure out how to do this and actually achieve the spirit because the letter just really didn't make sense from a cybersecurity perspective. We see that with a lot of regulations because they have to be so open-ended and yet prescriptive.
Steve Orrin at 00:18:38
And so I think that's gonna happen with AI. These things are gonna bottom themselves out as we get beyond the here's the policy to the implementation and looking at what's the right thing to protect. And that's, I think, the fundamental question. What is the important thing that we wanna protect and what isn't important? And that's hard to determine before you've really done the analysis.
Joel Beasley at 00:18:59
Who is the most knowledgeable person you've come across in regards to AI and the government? When you start talking to them, you're like, that person's brilliant. They get it.
Steve Orrin at 00:19:10
So there are lots of people I've dealt with that really understand this technology. And it's funny. Some of them have been in the government for many years, and they're finally having their day. You know, they've been the data analyst leader, the data science leader with—you know, they didn't call it AI because that wasn't sexy. So they were, you know, the analytics or they were the intelligence. And now that AI is having its day, you find that there are people in the intelligence agencies and the Navy and others that, you know, they were the chief data science person. Now they're chief AI officer. So their titles change, but they get it.
Steve Orrin at 00:19:30
I think the Navy is a great example where their chief AI officer understands the fundamentals, technologies, and where they can get the value out of it. Several of the intelligence agencies have ridiculously smart people. And you think about it, they've been doing data analytics and really AI for years, decades.
Joel Beasley at 00:20:02
Oh, yeah.
Steve Orrin at 00:20:03
And so when you start talking a bit to them about AI, they were dealing with it back when we were using mainframes to do AI. So they understand the core technology and how to apply it to an actual problem. I've got data coming from multiple sources. I need to be able to fuse it to actually make anything intelligible out of it. So we've seen a lot of really smart people there.
Steve Orrin at 00:20:24
And then you find, less on the top leadership, but in the programmatics, some really smart people. I'll pick on forestry as an example, understood what they could do with the technology in a novel way to go solve a problem they have. And forestry's example, and they did an experiment, it's almost five years ago now, where today, if I wanna have—if the National Forest wants to understand what the current status of blight is in the National Forest, they have to send a forest ranger out on the trails, and they have to go take pictures and look and see how many trees are diseased. And so you're getting a ridiculously small sample size, what you can see from the trail, and usually one or two people doing that survey. You're not getting good data.
Steve Orrin at 00:21:08
And so they looked at an approach where they use drones with cameras. They implemented an AI that was able to detect blight on trees in differing lights, different aspect ratio. They created a really good AI, worked with some universities and some commercial entities, loaded that up onto the system, and then sent them out semi-autonomous. So you've got a region, and then they flew autonomously to be able to navigate through the environment. And they were able to get a much larger percentage, a significantly larger percentage of the forest covered. And the numbers—I don't remember the exact numbers, but the time to detection before it became a catastrophic event dropped significantly. So they were able to deal with the problem much quicker. And so this wasn't some senior leader or forester. It was someone who was looking at the problem of disease control within the National Forests and had an idea of how to actually apply these technologies in a real-world scenario and was able to get amazing results. And it's, you know, and then move it on into a—from a great experiment in a couple of forests to a more programmatic approach across the National Forest to, again, detect blight quicker.
Steve Orrin at 00:22:15
We're seeing that kind of thing being used now in California for forest fires and being able to detect areas before the forest fire picks up, being able to detect the humidity levels, the dryness of the leaves, the growth of the brush using camera sensors, heat sensors, and the like. And they're getting much better. You can't prevent every forest fire, but if I can have resources available, I can significantly reduce the impact. And that's work that's happening again sort of in theater, in the field, with sponsorship from leadership. But, you know, leadership, they say the buzzword AI, and they say, okay, I like that. It's the people on the ground that actually understand these technologies in many cases.
Joel Beasley at 00:22:54
You touched a couple times briefly on security. What are some of the new security threats that have come about because of AI?
Steve Orrin at 00:23:03
So there's a lot there. There was a whole track at DEF CON this past year just on AI and AI security and AI hacking, and the year before as well. So things like prompt inject and model poisoning and all those kind of targeted attacks on skewing the AI, disrupting the AI, changing what it's gonna recognize, to stealing model weights or being able to infer IP from the what has been trained by using prompt injections in order to figure out what somebody may have trained it on if it's not—if the data may have been sensitive or corporate IP. So there's a lot of those kind of threats that are just a new category of threat that we have to deal with.
Steve Orrin at 00:23:46
I think the other is looking at the adversaries themselves are leveraging these very same technologies, whether it be through deepfakes, really well-crafted phishing campaigns, much more efficient discovery of support services and weaknesses doing vulnerability scanning with an AI backend. And I think one of the challenges that cyber defenders have to deal with is that it may take us years to really adopt AI because we want it to be secure. We want it to be trustworthy. We want to be able to play. We gotta get budget. The adversaries see a new widget in their arsenal. They adopt. They're already out there using these advanced techniques long before the defenders are able to even get a line item on the budget for next year's budget to adopt some technology. So that cat and mouse is really enabling the adversaries. So they're not only targeting AI systems themselves, and we've seen a lot of examples of AIs being skewed or attacked, but also they're using those to prosecute their ransomware, their data breaches, and their phishing campaigns.
Steve Orrin at 00:24:46
I mean, there was a great example, now it's almost six, eight months ago, where a bank was attacked, where a deepfake along with a chatbot was used to trick a financial analyst to transfer $25 million out. And it was a deepfake of the CFO with the chatbot talking to that analyst. And so they're using—that's a very exquisite attack. They had to train that deepfake generative AI on, you know, pictures of the CFO. Of course, CFOs go on CNN and talk to the press, so there's lots of media about them. And so we've seen the example of these kind of technologies being used against us. And so how do we come up with, you know, mechanisms that defend is gonna be a key question.
Joel Beasley at 00:25:27
Did you say $25 billion?
Steve Orrin at 00:25:29
Million. Million.
Joel Beasley at 00:25:30
Okay.
Steve Orrin at 00:25:31
Yeah. $25 million. Still a large number.
Joel Beasley at 00:25:33
It's large. It's big enough to where you don't have to do it twice. You can do it once. Yeah. Interesting.
Steve Orrin at 00:25:41
And that, you know, it definitely made the news as far as the, you know, this is a—it's not like $25 out of your bank account.
Joel Beasley at 00:25:48
Did they join on a video call, or did they just do it text? How did that go down?
Steve Orrin at 00:25:52
So the hacker had gone—you know, spoofed the internal IP address and done, I don't know if it was Teams or Zoom, but an internal video call with the analyst.
Joel Beasley at 00:26:01
Oh my goodness. So the analyst is just sitting there and their boss gets on and is like, hey, we need to do it. It's coming from inside my company tools. There's no security issue. And I just do it, and I can see them and hear them. It's them. And then they—they get caught?
Steve Orrin at 00:26:17
So they did not get caught. But—
Joel Beasley at 00:26:21
They didn't get caught? How do they do that? You would think that the banking system's coordinated enough to where if a wire happened, they could figure out how to get it back.
Steve Orrin at 00:26:30
Yeah. We would love to see that with a lot of these large-scale breaches. Oftentimes, they quickly transfer the money to multiple accounts, and it ends up in Bitcoin or something like that and goes off into other, then into other fiat currencies. There's a whole ecosystem of what's called money laundering that the dark web and the adversaries are using to basically get their finances out. Bitcoin or other cash systems are definitely part of that puzzle, you know, cards and other things. They don't just say, take $25 million, put it in this account, leave it there. They have a mechanism. They're very—you know, it's a trillion-dollar industry, the adversaries. They have the tools and techniques to be able to get their revenue out.
Steve Orrin at 00:27:15
And I think that's been one of the challenges. And as much as we think the banks all play nice and work well together, there's a lot of interbanking rules and regulations that's hard to share information, especially across geo boundaries. And so it's still something that I know that the US government and the allies and all nations are trying to work together to better identify these bad actors, the networks they use, and the financial mechanisms that they're using in order to be able to get—now we've seen many examples. There are a couple examples I think the FBI announced a while ago about how they were able to track down the transactions and get some of those funds back in many other cases. But I don't think in this particular case out of a bank in Hong Kong that they were able to get the money back, but they did identify that it was an internal attack. So they did the full forensics on it.
Joel Beasley at 00:28:04
That's exciting. They can make a movie about that.
Steve Orrin at 00:28:07
The next, you know, Mission Impossible, those are gonna be—it's gonna be instead of putting on the mask, it's gonna be a deepfake.
Joel Beasley at 00:28:12
It's gonna be a deepfake. Yeah. I haven't checked DARPA in a while. This was an open question at least two years ago about detecting deepfakes and it's being very difficult, very low success rate in detecting GPT-related text and deepfakes. But yeah, for me, it's like, how do we know? How do I know I'm actually talking to Steve and you just didn't send your digital twin today to do the interview?
Steve Orrin at 00:28:38
So it's a good question. And also, let's take—let's separate into two buckets. To the deepfake detection, there's been a lot of research over the past couple of years about how to do that. There's some technology in Intel Labs using biomarkers as one example. So the camera you see here, you see my face, but the camera is actually much more sensitive than what our eye can see. And so being able to detect the blood flow in my veins and whether in a generated image, the blood flow isn't gonna follow the natural heartbeat rhythm. And so being able to detect a deepfake by the biomarker, in this case, of blood flow in my veins is one mechanism that's highly accurate for facial deepfakes.
Steve Orrin at 00:29:18
Another one is the eye gaze. A lot of deepfake videos, you know, your eyes will do one of these jobs, or one will be pointing this way, one will be pointing that way based on what it was trained on. And so there's a lot of those biomarkers as one area of research. Another is there are certain signatures that can be detected on the video based on the generator. And so analyzing the various deepfake generators and using an adversarial model to be able to identify some of the nuance of how that image—you know, is that image generated by a known generator? In that example where the financial analyst was deepfaked, there was a couple of folks on HIBP. It was Gadi Evron. He was one, you know, cybersecurity expert out of Israel.
(Steve Orrin at 00:30:04) He's currently at Gnostic AI. One of his comments was, well, you know, if that analyst had just said, "Hey, can you raise your hand for me?" that would have solved the problem for that particular deepfake because most deepfakes are just your face, and they don't capture hand gestures. And so if you had just said, "Hey, give me a thumbs up," the deepfake would typically not be able to do that unless it was already pre-trained to add in hand gestures. And so that might have been a way that the analyst could have just said, "Hey, I just want to verify that I'm really talking to... So if you want to talk to me, ask me to give you a high five or a thumbs up." That's something that most deepfakes aren't trained on today.
(Joel Beasley at 00:30:41) Yeah. Then we just get into the whole antivirus cycle concept. It's like, yeah, you detect the common generator, script kiddies out of the game, but the people who know how to work the technology, I'll just make my own custom version. I'll make it blood flow match. I'll make it eye gaze match. Yeah. I'll just program to the tools.
(Steve Orrin at 00:30:58) And it's funny, but you think about it. We've been in the antivirus game for forty-seven years.
(Joel Beasley at 00:31:03) Yeah.
(Steve Orrin at 00:31:04) And the deepfake detection is going to follow that same kind of model.
(Joel Beasley at 00:31:08) The model as it will never be solved.
(Steve Orrin at 00:31:10) Well, it will be a back and forth cat and mouse.
(Joel Beasley at 00:31:13) All right. We talked a little bit about everything. Let me just scroll down here. I want to do a little bit about leadership. Okay? Because a lot of the people that are listening, the reason why they come in and find us is because they're experiencing some problems with their teams or they're trying to grow. And they want to know, like, how did Steve become the Federal CTO? How did you get to that high ranking position, and what skills did you teach yourself in order to ascend up there?
(Steve Orrin at 00:31:41) So Joel, I look back at my career, and I've been doing this now for just over thirty years, not Federal CTO, but being CTO of various organizations. And I think it comes back to a couple of key things. Number one is surrounding yourself with people way smarter than you and listening to them. I go back to a book, and also I got to meet the author, Jim Collins in "Good to Great." And one of the things he talks about: get the right people on the bus. And when he gives his talks, he talks about surrounding yourself with the really smart people in each of their domains. And I took that a step further, and you want to have a diverse group of people surrounding you, so people who are experts in a variety of technologies and business functions, and listen to them and get them to interact with each other so that you can get the best answer. And so I find that having teams of people that are smart, that are experts in their domains, and bringing them together with different backgrounds and really using them as a team to solve those problems has been something that has led to a lot of my successes over my career, and building up your teams and growing your teams so they become the next CTOs of whatever organization they go to next. So that's one. I think the other is, and especially when you're whether a product CTO or a customer-facing CTO, talk to customers. Get out there and speak to the people who are actually going to deal with the pain of your technology or of your ideas. Understand their needs, understand their requirements. Oftentimes, CTOs fall into two traps, either, you know, we know everything, so we're going to figure it out ourselves, or, well, the customer doesn't know what they want. They're going to want this. And there is a certain amount of that. You the CTO, you're seeing a lot of technologies that an individual customer may not see. But the benefit of talking to lots of customers across different verticals and different areas is you get to see that amalgam. You get to see what different people are struggling with and can see the trends that individually they don't. The other is oftentimes you can see where they're struggling today and figure out, you know what? They're actually going to have a bigger issue in the future, so I can help them today, but I also want to plan for what they need next. And so I'd say that, you know, definitely getting out there and speaking to your constituents, speaking to customers, speaking to partners, and hearing what they're trying to accomplish, understand their use case. I think the thing that served me in my current role for the past ten years is not only understanding the technology, but understanding what the customer is trying to do. You know, the Navy has a problem, has lots of problems. They're trying to solve those problems. What is the environment they're trying to solve it in? What are the things they're trying, what the outcome they want? And then apply the technology to it as opposed the other way around, try to come up with cool technology and force it on the customer base. And then the last one is understanding the, I'm going to call it the internal ROI. You know, you always want to have your product have a return on investment for your customer. But one of the key successes throughout my career is understanding who the key stakeholders inside the organization are and what are their outcomes they're looking for. How do I get them on my bus? How do I get them to be aligned with what I'm trying to do or to at least align what I'm trying to do more closely to their mission? Because then when you get partners together, everyone then raises, you know, you along, you know, for the ride. And so I find finding those key players within the broader organization that you need their help, but aligning what you're trying to do to what their objectives are. What are they getting measured against? How are they successful? And aligning yourself or at least being able to say, you know what? I can help you in this one area. And that then brings them, you know, brings the connection much better than saying, well, you're on the team now. You're going to help, give me your resources to do whatever I want. That just doesn't work in the real world. So I think those three things are probably some of the key things that over the course of my career I've learned that have helped me grow into the role and the various roles I've had over the years.
(Joel Beasley at 00:35:28) They were well articulated. At what point did you sit down and write those out?
(Steve Orrin at 00:35:33) That's a good question. I have not written the book of how to become a CTO yet. I need to do that.
(Joel Beasley at 00:35:38) You should. By the way, just to give you, I guess, a compliment, I've done about a thousand of these interviews with CTOs, and the three things that you mentioned are the most common three things I hear amongst the top 1% of all CTOs. You're dialed in, dude.
(Steve Orrin at 00:35:58) Well, I have to say I've had some really good mentors over the years, and not all of them were CTOs. I've had great business people that have helped shape me along the way, VPs of marketing that have, you know, you've got to be able to communicate in a way that a customer understands. And that was something I learned very early in my career that has helped me immensely. One other thing that I think, you know, for CTOs that has been useful is early in my career, I had the opportunity to be on the other side. I was a CISO for a clinical trials company. So I was in the customer's shoes and had to deal with adopting technologies from vendors and getting them to interoperate and dealing with compliance regulations and specs and things. And that was actually a really good training ground for the pain that we as vendors often impose on our customers is to be the customer. And so I think having that experience at least once in your career as a CTO is absolutely critical. And vice versa for a CIO or CISO to spend a little time as a vendor to see the other side of just how hard it is to get a product out the door with every requirement under the sun that the customers are asking for. Getting both sides of that is actually, you know, has helped serve how I build better products for customers and how customers can see the value of those features more naturally.
(Joel Beasley at 00:37:14) Who do you report to?
(Steve Orrin at 00:37:15) So I report to the GM and Vice President for Intel Federal at Intel.
(Joel Beasley at 00:37:21) Okay. Very cool. Do you know Pat?
(Steve Orrin at 00:37:23) I have met Pat multiple occasions, yes.
(Joel Beasley at 00:37:26) Have you had conversations with him, like, one-on-one?
(Steve Orrin at 00:37:28) Not one-on-one. In a group.
(Joel Beasley at 00:37:30) In a group? Yeah. What would you say his personality is like?
(Steve Orrin at 00:37:34) He is a barrel of energy. I have to say he is always on cue, on target. And one of the things, and I worked with him both when he was here the first time on a team that was doing some of our early security technologies, and I've obviously had the opportunity to work with him in the federal world, but now that he's come back. And his understanding of technology of all the different domains is just mind-bending. He really understands everything from the deep manufacturing of silicon to cybersecurity needs of the end customer. So he has a breadth of knowledge and experience. And like I said, he's just an infectious energy that inspires.
(Joel Beasley at 00:38:12) Yeah. He seems like a pretty good dude, and everybody I've met says he's a pretty good dude. And so, yeah. Can you, like, is he an available person? Like, if you wanted to meet with him, would he meet with you?
(Steve Orrin at 00:38:22) Oh, yeah. Absolutely. I've had the opportunity, and you could, he responds to emails. When he first came back, I popped him an email. I mean, he was probably getting, you know, a deluge of everyone from Intel has been here for a long time, and he sent back a personal message. So he, you know, he does respond. He remembers. You know, like, I've run into him at various different government meetings. He is, like I said, his brain has got a lot of information in there, and he's still able to remember it all and keep it all sorted.
(Joel Beasley at 00:38:46) Nice. Nice. Better than me. I did a call with a guy about an hour ago who was on the show 300 episodes ago, and I was like, it's good to meet you. He's like, yeah. Oops. Oops. It happens.
(Steve Orrin at 00:39:00) See, that's where you need an AI. You'll be able to look at the face and say who's on the show.
(Joel Beasley at 00:39:04) I know. I need a co-pilot to, like, come to my meetings with me and do more than transcribe. Like, actually, for a little fun side project, Steve, what we did was we built, we took all of my episodes and we did speaker identification across all of them and then we trained models on me. Because I've got a thousand plus hours of recordings of me talking with people about different topics.
(Steve Orrin at 00:39:29) So now I have to ask: am I really talking to you, Joel?
(Joel Beasley at 00:39:32) That's the question you should be asking and the answer is no. I was kidding. No. We will get there one day and, you know, I don't know. Like, I think to myself, if the technology were perfect today and you couldn't tell, you know, how will we deal with the sync of information issue? Meaning, my digital twin goes and has a conversation with you, has new topics, but then learns. But then how do we sync that learning back to Joel, like, the original Joel? And that's actually an open-ended question right now. It's like, how do we do that?
(Steve Orrin at 00:40:09) That will be trouble. You know, it's the same problem we have with, you know, AIs training on things that we have no idea how they got to the, you know, good conclusion, but it's understanding how we do it. I don't think the human brain will be able to keep up as we let these things loose. So that sync problem, you're going to have to ask the guy, give me the Cliff Notes version of what you learned today.
(Joel Beasley at 00:40:27) Yeah. Yeah. And that or we're just going to do the Neuralink implants, and then I'll handle the syncing of your digital twins with you. And then we walk around. Now we're like bees. Right? Like, I control a hive, you know?
(Steve Orrin at 00:40:37) Well, the other question though is when does it stop being your digital twin? You know, at some point, it's, it's learned more than you know. So is it really a digital twin, or is it now a different entity because it has knowledge you don't have?
(Joel Beasley at 00:40:50) Yeah. It's diverged from the branch, of course. Yeah. Interesting questions.
(Steve Orrin at 00:40:55) Tough questions and themes for upcoming movies.
(Joel Beasley at 00:40:59) I know. Isn't it great how our imagination as a society, like, solves a lot of these things in movies and media? Yeah. I think it's interesting.
(Steve Orrin at 00:41:08) We wouldn't have the cell phone if not for the communicator in Star Trek.
(Joel Beasley at 00:41:12) Right? Right? Of course. Well, thank you so much for coming and hanging out with me. If there's anything that we didn't get out there that you want to share with the next generation of technical leaders or your peers as CTOs, go ahead and shout it out. Otherwise, we'll wrap up.
(Steve Orrin at 00:41:27) Sure. I think the one thing that I would just reiterate is, you know, as whether it be AI or the next wave of technology is that, you know, play with it. Get your hands dirty. Understand it. Don't be afraid of it. Go try it. And that's what you find is that getting yourself involved in it, whether it be security or, I find, you know, I often mentor many cybersecurity up and comers, and I'm like, go play with the technologies. Go download, you know, Kali Linux and try to hack for a while. You know, that's the best way to learn it. You know, go watch the YouTube video and then try it for yourself. And I would say for CTOs that are, you know, the innovation of new technologies, the only way to keep abreast is to really get out there and play with some of these new things.
(Joel Beasley at 00:42:08) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email: [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.