Cybersecurity Ecosystem Show · 2026-07-17 · 44 min
Key moments - from our scoring
Substance score
52 / 100
Five dimensions, 20 points each
Ward critiques the security industry's reactive posture - spending resources analyzing past breaches rather than preventing future ones - and advocates for proactive, exploratory approaches like purple teaming that mimic attacker behavior. He emphasizes hiring generalists who are naturally curious, play with technology outside work, and aren't afraid to challenge assumptions. Regarding AI, Ward has evolved from skepticism about data misuse to recognizing LLMs as force multipliers: they enable junior analysts to operate at senior levels, allow rapid analysis of massive datasets, and surface patterns humans miss. The key is human oversight - AI produces garbage if trained on flawed practices, and its integration into existing systems is where organizations typically fail. Ward stresses that AI won't replace security professionals; it amplifies what we teach it, making proper guardrails and human-in-the-loop decision-making essential.
The industry is reactive and retrospective - spending most resources analyzing logs and past breaches rather than preventing attacks before they happen, whereas attackers are exploratory and only need to find one unlocked door.
Rather than a dedicated permanent team, run purple teaming as a quarterly exercise where regular security engineers rotate into an attacker mindset to test their own infrastructure; this builds team trust and awareness while costing less than dedicated roles.
No - AI is a tool that amplifies human capability (like a nail gun versus a hammer), but it only produces quality output based on what it's trained on; humans must remain in the loop to verify results, challenge hallucinations, and set proper guardrails.
AI enables junior analysts to operate at senior levels by rapidly analyzing massive datasets, allows non-experts to query complex logs in plain language, and surfaces patterns humans wouldn't think to search for - but only if the underlying practices feeding the AI are sound.
Multimodal AI systems (cameras in glasses, audio monitoring) create persistent surveillance vectors, and companies often feed proprietary customer data into AI training without realizing they're helping train competitors' tools.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuinely interesting ideas - the gaming black market manipulation tactic, the junior analyst elevation argument, and the self-attestation problem with AI agents - but they're buried in extensive filler, jokes about crime, rugby analogies, and repeated AI takes that add nothing new. The useful insight-per-minute ratio is low for a 44-minute runtime.
we could allow them to mass up, you know, a hundred boxes that they're getting ready to give to the their customer. And as soon as both of those players logged off, we would gank back the hundred boxes
if we hand them AI, uh, they're almost a level two analyst coming out of college because if I tool them correctly
The gaming economy black market manipulation story is genuinely original and the proxy-based external attestation framing for AI governance has some fresh angle, but the bulk of AI commentary ('AI is just a tool,' 'humans in the loop,' 'it won't take over') is recycled content heard on dozens of security podcasts.
gank back the hundred boxes, we take them right out of their inventory, and we would put them right back into the guy's inventory who had just sold them
I live in line, so dirty word proxy. I proxy your AI. Uh, traffic... Because the agent writing its logs should not also be telling you that I'm good
Ward is a credible practitioner - he ran real e-crime teams at a gaming company, touched HackerOne, and is building an AI governance startup with a coherent technical thesis. He's not a marquee name and some credentials stay vague, but the stories feel genuinely lived-in rather than thought-leadership theatre.
I owned the E Crime team. And we were tasked to go into a couple of the games where we had a lot of fraud going on
I worked at companies like Hacker1 where we realized we still want people testing all the doors and all the windows and we should reward those people
The gaming manipulation tactics and the Behavry AI technical architecture (proxy attestation, hashed ledger, 93-company competitive grid, 15-characteristic matrix) provide solid concrete detail, but there are no dollar figures, outcome metrics, or named company victims, and most war stories are deliberately anonymized.
I am at present tracking 93 companies who do, who play in the spectrum of, we'll call it AI governance... I have got a grid that tracks, I want to say like 15 different characteristics
80 to 90% of the traffic for going to these LLMs is via web browser
The host asks a reasonable opening question and occasionally surfaces a relevant data point (Verizon DBIR), but most follow-ups are vague and affirming ('That's great,' 'I love it') and the host never challenges a claim, pushes for specifics, or creates productive tension across the full conversation.
what do you see as acutely broken in the security industry?
What are your. What are your thoughts on that as far as, uh, AI taking over some of the security responsibilities
Computed from the transcript - who did the talking, and the words that came up most.
Ward Spangenberg has spent his career finding the gaps: mapping trout DNA with a homemade database in college, dismantling a game economy's black market so thoroughly that players nicknamed him the Dark Knight, and helping build the case for bug bounties at HackerOne. Now he's the founder of Behavry.ai, building in the category Gartner calls guardian agents. In this conversation, Ward and Taylor dig into why security spends its money explaining last night instead of preventing tomorrow, what purple teaming should have become, how to hire engineers with the play instinct, and why AI won't take over but ungoverned agents absolutely will hurt you. Ward breaks down the four things real AI agent governance requires: no self-attestation, real-time review of every action, human-in-the-loop escalation instead of binary yes/no decisions, and tamper-evident audit trails that regulators are about to start asking for. Whether you're a practitioner, a founder, an investor, or just AI-curious, this one is full of stories you'll retell.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Hey everyone, welcome to this show. I got Ward here today.
Speaker B: Ward, hey, how are you today?
Speaker A: Doing well. Thanks for coming on the show. Looking forward to our conversation. And uh, you're former security practitioner, uh, now building your own company. So we're going to get into all that fun stuff. But I love, I always love to start the conversation around what kind of two part question number one, what do you see as acutely broken in the security industry? Let's start there.
Speaker B: Okay, so I'm going to tick off a bunch. So it's. And it actually even pivots. If you look at my entire career spectrum, one of the, this really comes to light security industry, we are really, really good at looking at what happened. We spend our lives in logs. We do analysis of them. I mean like we were the original data scientists, right? Uh, we could tell you exactly the story that came out of the data. But guess what? Security should actually be about stopping it before it happens. Why do we spend all of our money and, and enterprise security today on things that basically tell us bad stuff happened last night.
Speaker A: Great.
Speaker B: Now what do we do? Now we go back and we do all the analysis and then we go out and we try and figure out how next time we're not going to allow that to happen. So when the bad things happen, we then go back and fix it. I think that's the worst, worst perspective of the world in security because when you flip it and you look at the way an attacker works, an attacker goes, well, what can I do here, what can I do there? And they punch around and they, they walk around trying all the doors, all the windows and all of those things. And that's exactly how I've actually taught my engineers for years is yes, we have to secure all the doors and windows. They only have to find one that's unlocked. But explore, go out and play with it, see what works, what doesn't work. Um, we saw the rise of, I think it's called now purple teams over the last couple of years, right? We had red teams, we had blue teams, they had the inside look. Now we got the purples, right? They've got a little bit of everything and they can tear all apart. That is probably the best thing that our industry could do. But we didn't carry it on. We, we still argue at the top level and the executive staff as to whether whether we should have purple teaming, whether it should be done, whether we should engage with vendors who provide it. All of those things we, we didn't put, we make quantitative analysis to it. We didn't say, hey, I'm going to save us money or I'm going to keep us from getting hacked or any of those type of things. We, you know, we. We use it sort of as a check mark to move forward with our insurance and things like that.
Speaker A: Interesting. Well, couple. Couple things I love to. To go a little deeper on. So. Yeah, it's funny you mentioned that. Cause I was just watching the Verizon, uh, data breach report from 2026. And it's funny because it's like, you know, those reports are, to your point, like, everyone's like, looking back, you know, what happened last year, right? What happened? You know, what are the trends and, and it's, uh, to your point, might be too late and. Or the personalities. I always joke, if I didn't have good parents, I'd probably be a cyber criminal just because my personality is that very. I'm an explorer, right. And I'm like, why not?
Speaker B: I used to tell. I used to speak to, uh, I would go and present to lawyers and, uh, and law enforcement investigators all the time. And I'm like, you know, don't ever piss me off because I'm not like the rest of the criminals. I'm going to hit once and I'm going to take all the money and then I'm going to disappear because I don't need to keep hitting. Right. Most criminals that keep going back and doing it over and over again, I'm like, no, I'm gonna do one swoop. I'm gonna take everything I want, and then I'm gone.
Speaker A: Yeah.
Speaker B: It's funny. I'm right there with you. We can go. I'm sure there's some big islands we can buy, like quadrants and have a good time.
Speaker A: Yeah, I love it. Yeah, I love it.
Speaker B: Yeah. And I. So I think there's.
Speaker A: There is. And obviously your discovery and your experience, it sounds like that. That more exploratory or ability to, uh, look ahead probably been very successful. And that's why even the purple team and whatnot. I'm curious though, why do you feel like the industry is so looking back versus looking forward or, you know, looking at, you know, what's. What's in the past? Is it because it's more concrete and less speculative or. Yeah. I'm just curious what. What drives that?
Speaker B: It's easy. Think about it. It's. I mean, my favorite right now. Again, the industry's gonna be mad. Is Mythos, right? We all lost our hats. Oh, my God, it can out hack us. We're we're never gonna come back, dude, implement the controls. The security holes were there, right? We're finally starting to go, oh, uh, you're right. I didn't think about that. But the stuff existed. It's existed for 25 years. We're surprised that one. It's finding holes in code that's existed for years. It's trained on literally the best coding security practices that are currently known to man. Right. So it's guaranteed that a human who didn't follow those security practices or didn't follow that manual is going to introduce the problem. Okay. So we, we gave it something that's really good at fighting it. And uh, and then we get terrified by it. But it's so easy for us to go, well, it's easier to look back, right? That evidence is concrete at that point. Something has happened and now we can go pull it apart. It is very hard to sort of dream about what the future holds because we're. In some cases, some cases we don't actually understand what our systems are doing or how they operate. In some cases we will say, I don't have budget to actually explore where this is going. So we can say it's monetary block on those type of things. And in some, um, cases we're lazy. It's, you know, it's. That's gonna be a lot of work. And instead of going and doing a lot of work, I'm just gonna sort of block and tackle what I have and what I know instead of, you know, just doing that. So I think it's sort of that combination. One of those will usually rise at the top in that pyramid. But that's kind of the. That's the way I look at it.
Speaker A: Yeah. Makes sense. Yeah. It sounds like, I mean, obviously based upon. Well, you know, you know, like it's for sure in certain organizations, just the uh, the res. Or under budget or. And I think there. It takes a certain type of personality to be more that exploratory to, to, you know, to go. And I'm curious your thoughts on that back to that kind of the purple team. Yeah. What, what's your thoughts on, like, what. How would you structure a purple team? And what. What's the ideal for that? And in that, how do you justify it? And it sounds like there are some justification problems you've seen as far as.
Speaker B: So I've long. I. I've actually struggled with that concept of the purple team. Uh, yeah, I've had engineers who were like, I want to create this and I've sort of struggled with it. One I believe as a security specialist you need to be a generalist across lots of things. So that's the first piece. I think that if you're a generalist across a lot of technologies, you're actually a lot more valuable for a company. When I interview, uh, when I'm bringing engineers into me and all of my will attest to this, I challenge you. We know the developer here, you know, here's a piece of code and you know, but in the next 24 hours find something with it or whatever. We've seen those. What I really want to see is I'm going to throw something up on the wall, we're going to role play it and I'm going to go hard. Let's, you know, how do we do this? And what I really want to see one or engineers who go, I, I don't know where to go now because that means that they are very self aware where their knowledge lies. But then in that next, that next pivot I want them to go, but I think I know where to go to look or, or I know somebody who's done research on this, I can give them a phone call or you know, those type of things already be looking for the next leap off of that piece. That's one of the things I look for. The other thing that I ask all my engineers, uh, what do you do in your spare time? What do you like to play with? Because the engineers genuinely I found the engineers who play when they go home. You can't really see it over my shoulder, but there's an entire bench of you know, projects going on behind me. There's projects going on on my computer at any given moment. You and I talked about it. The front side of this. We're not designed to sit still. So the engineers who, when I asked the question what does your home network look like? What is you, what do you like to play with when you go home? Those, the engineers who light up because they get the opportunity to start telling you about the really cool stuff that they work on outside of here. I mean you don't have to tell me you build, you know, you write code at home or whatever. You're like dude, I've got a garden at home and this is what I do. Those type of things mean you're really intrigued with understanding how other things work. Most important concept we need in security is always be willing to learn something new. And so to that purple team, that's what I want. I want people who are like, oh, what happens when I pull this thread or what? What happens over here and those type of things. Do you need that, that, that whole, uh, the concept of a purple team. Sure. When we were all graduating college, that's what we wanted to be. We wanted to be hacker paid packet, paid to be hackers. Today's budgets don't really allow me to have a dedicated purple team, but doesn't mean I don't think that we need the concept. So it's an exercise. Let's do it. Let's plan once a corner for us to act like hackers and hack our own infrastructure. And what better? We're the ones that already defend the infrastructure. So what better than for one of us to say, or, you know, let's say there's a team of four of us. Hey, Ward, I'm going to go after your systems. Go after my systems.
Speaker A: Right.
Speaker B: So, uh, it gives some really neat perspective. It also builds. You're going to ask me a question a minute because we talked about my past. I'm a rugby coach. Right. And one of the things you learn is how to rely on your teammates. It's same concept when we're talking about security teams. Same concept. It kind of any team that you're building, learn to trust each other, learn to know what each other's knowledge, their pluses, their minuses are. And then together as a team, we can leverage and be better.
Speaker A: I love it. That's great. Yeah, you covered a lot of ground there, but I think it's great. I think there's definitely, uh, some principles where it sounds like a team member needs to have, you know, depending on the day, multiple, you know, maybe purple, red, maybe.
Speaker B: Yeah, we've taken the budget away. Right. And we're going to continue to get constrained. We've got, you know, we've got our CEO saying, I was going to do it all. Okay. We, we still have to have humans to run the AI. They're not going to take over. Everybody settle down. Chill out. Okay? There's still gotta be a human in the loop. But, uh, yeah, more.
Speaker A: What are your. What are your thoughts on that as far as, uh, AI taking over some of the security responsibilities and.
Speaker B: Yeah, we train it, we feed it. It's not gonna take over.
Speaker A: Sure.
Speaker B: It can get. I mean, it can simulate itself off into oblivion. Right. It can blow the world up. We, I mean, we reread these every day. And you know how AI did this or AI did that. What was the one I was reading yesterday? They gave the four popular frontier models a radio station to run and one of them decided it liked, uh, like to talk about horrific military events in the world and then it would play like, you know, uh, most inappropriate song afterwards and those type of things, you know, had one. It was just like, first I want to understand how they set this nonsense up because or why. I mean, you know, it goes back to, we funded, you know, measuring how much methane came out the rear end of cows at one point in life. So I'm not sure that we actually invest in the right things we should for research, but that's a different story. No, I, it's not going to take over. It's a tool. We had hammers, right? We used to build with hammers. And then along came uh, and then along came nail guns and made it faster. Right. It's just a better tool. You know, pivoting back on my mythos thing is, is that uh, AI AI is not really the fact that attackers can use it or defenders can use it or anything like that. It actually is going to highlight the integration. Uh, that's where the, where we're going to fall down. So the companies who go, we've got to actually implement this new tool. We've got to leverage what it can teach us. It does things faster than us. Great. But guess what? I'm the one who taught it how to do the thing the first time. Just because it can replicate me at a thousand times speed, if I don't teach it right way to do it, then all it's going to give me is garbage on the backside of it. So, you know, we. No, it's not going to take over. It's, you know, what is it? The people? The, the running joke is I'm always nice to my, uh, to my AI because, you know, in case it does take over, it won't take me out first. I'm like, hell, it's going to take you out first. It knows you're the weak one. Like I curse mine all the time. I'm like, what are you smoking? That is not the right answer. You're hallucinating again. Stop it. And, and I will highlight the errors in it. I'm like, no, that is not exactly how any of this works. You' lost track of this. Your context is wrong. Let's begin again. Claude has got a really cool tool in it called Insights. And recently I ran an Insights report because I use cloud a lot for development stuff. And I ran insights on my, my, my development work and it came back in one of the sentences that it highlighted where I had said, you're beep wrong. What are you doing? This is not the way you write this code. And, and that was the highlight to the insight was, you know, Ward was really upset that we didn't follow the right coding practices. So it's not gonna take up. I'm not scared of it.
Speaker A: Yeah, I, I agree. I think there's an element where. I mean even look at like the public markets recently and the publicly traded cybersecurity companies, they've only gone up. I mean they. A lot of SaaS companies, you know, had a. Or technology companies got hit in the past year or so because of AI but recently you've seen them, you know, the pub. The public being like actually, you know what we actually might need cybersecurity, uh, the, you know, the threat landscape is only going to increase. And yeah, as long as humans, you know, continue to build stuff, there's going to be flaws. To your point. And I think that's exactly it.
Speaker B: Uh, you know, we even then like AI doesn't write perfect code. Here's. This is a great one. Right. Okay. It's going to write the perfect code because we have given it all the rules to perfect software development. Right. We have taught. Has got everything. This code sucks. Why does it suck? Because it's like a human. It took the easy way out. When we. It looks the context and the loads and the token spin and things, it'll go, well, I can go option A, but that means another thousand lines of code in order to do it correctly. I can do option B. That's 500 lines of code and it generally works. Okay, I'm going to push option B because it's. It weighs it out. We know what the metrics are going to do, but oh no, it's going to be the perfect code. No, no.
Speaker A: Yeah. I think it's so interesting because I think, not to get philosophical here, but I think there is this element where a lot of the creators and how they talk about even human and how they, they think humans are programmable or that we're just a machine essentially and they can replicate humans as a machine to AI. And I think that's kind of where the flaw falls in. Right. I think even humans consciousness our, our nature for. Or even like the idea of evil. Right. Our nature for. For being able to do bad things. Right.
Speaker B: You.
Speaker A: You can't wire that out of us per se. And you know, we're creating this technology so it's like it's only. I think the, the threat landscape is only going to exponentially increase as our adoption of technology exponentially increases. And now, like, now with like, LLM, uh, have you, have you looked into much of like the, the multimodal LLMs that are using video audio? Um, which is crazy because now you're going to have your AirPods looking at your screen and reading your screen. Like, that blows my mind as far as like, threat landscape.
Speaker B: My wife got a pair of meta, uh, glasses for the, uh, for Christmas that was a gift from her boss because he thought, because they're all AI at her current company and she was very excited. And I said, so you're going to turn that camera on and reconnect because she has left social media. I said, so you're going to turn that camera on and then reconnect to social media? And she's like, wait, what? And I'm like, oh, yeah, it monitors and it posts back. I mean, yeah, you can go in and turn on and off, but in essence it interact. It's social media. It's still sitting in its box. When we were in June, she, she won't touch it. And that's, I mean, that's my. I, the privacy violations that occur. I already struggled. I mean, I, I live in a gym. That's how I keep myself from going a little bit crazy. And, uh, I struggled when I started to see influencers rolling up with cameras in the gym. I'm like, no, go away, I'm here to get. But yeah, it, I mean, it's great for me when I'm doing forensics work, because I can't. You can't get away. I mean, the, the Internet is forever, unfortunately, people.
Speaker A: Yeah, it's weird. It's a weird world. And so, yeah, I completely agree that there is, uh, definitely going to be continued needs. I'm curious, uh, what's the positives of AI for the security side? So what do you like if you're especially somebody. There's a lot of people that listen to the show that are new to cyber security. There's Obviously lots of CSOs, lots of people building in AI, but what are the positive? What do you see? How can it be to your point, this next new tool for us, that it can help us cyber.
Speaker B: For anybody who thinks that I am down on it, it's funny. What they should do is go back and research me. About a year, two years ago, when it was first rolling onto the scene, I hated AI. Okay, I can remember sitting in a contract negotiation with a company that was going to take all of our customer service phone calls. We were Going to turn them in to convert them from digital to text and then feed it into their training agent so that they could replace our customer service agents with A.I. uh, and I was so ticked because we were going to take our millions of hours of calls and train an agent that they could then go down the street and sell to our competitor. And no one sitting at the table thought to ask that question. I'm like, so wait, our data is going to train that a. Well, it's anonymized. I'm like, yeah, but we just trained it. It's. No, it doesn't matter whether you call it anonymous or not. We have trained your agent to be a better customer service agent so that you could go sell it to our competitor. It doesn't. It. I don't care what you're saying. So I hated A.I. uh, because I saw those types of things and that's actually why I started my, my current company. But we'll get to that in a second. But then fast forward a year. I kept playing with it. I kept seeing how amazing some of the things were, how quickly an idea that I could sort of have. And I could start playing around with code very rapidly and I could prototype or I could take a, uh, take a log file, right? We were talking about the data analyst. I could hand the log file to it and say, hey, I can't see this. Where is this? Whap. You know, within seconds, the data that I would have had to write a Python script and grep and whatever in order to find it was just seconds away. And so that speed from me thinking it and then. And God, I've got little pivots all over the place in our industry. Or, uh, one of the things you keep hearing, it's. It's all about the prompt. It's all about the prompt. I can support or argue against that, but it's. If you understand the topic, if you understand what you're trying to pull out of something, you can have. And I hate saying conversation, but that's what it is, right? The interaction. That's a better word. Interaction with the, uh, with the LLM buyer prompt in order to pull the nugget, you're most specifically looking why. And this is actually what leads to why I think AI is amazing. If you understand your job. Let's say you're a security analyst and you look at firewall logs. I'll really simplify. All you do is look at firewall logs all day long. But you know, firewall log forward, sideways, up, down, diagonally. When you're presented now with, you've got, let's say Suddenly you've got 10,000 logs to look at and they're all a thousand lines long or whatever. And you can hand them to an LLM who understands how to read that data. And this is a lot, you know, early days of graph databases or if you will, even the splunks and the, uh, elastic, if you understood the interactions in those, you could very quickly pull it out. Well, now you don't have to be an expert in those firewall logs. AI allows you to have some understanding of what's inside the logs and ask it in English or whatever language you speak, what you're looking for, and the AI does it for you. So what AI has done, we're not taking advantage of this. We don't hire kids coming out of college as level one analysts now because they don't have the experience. But if we hand them AI, uh, they're almost a level two analyst coming out of college because if I tool them correctly. So back to my, my analogy, right, of the hammer versus the electric or, uh, the nail gun. If I have a kid coming out of college and I hand them the AI tool that is designed to help them pull apart that data, they're suddenly better, they're more powerful, they're more valuable to us as a company. And they're also going to bring interesting perspectives. They may look at things differently than I do, so they may ask different questions of the AI and see and find patterns that I wouldn't have thought to pull strings to pull threads, whatever. So that's what AI. I think it's so amazing, the fact that it allows you to play across all these different spectrums of information and sort of look for, look for coincidences or threads that people just aren't looking at. So if you're a business looking at it, you know you've got a problem with regards to sales. This allows you to very rapidly analyze and understand what your sales cycle looks like and where things are breaking. You've got a manufacturing company and you're trying to understand what your supply chain looks like. You can't figure out where something's broken. You can give that data and you, as the CEO, can go, uh, here's the data. But I don't where I'm missing something. What am I missing? And you can start to have those again, interactions and pull that stuff forward. That's amazing. We have never, I don't know that we've had that type of, uh, actually no, I'm Gonna take that back. We've had that, right? We used to work in small groups and then the Internet came along and suddenly we could, you know, we could work with large groups of information. We had like, let's even. We go further back, right? There were libraries. The libraries became the central hub of all information. You could go into a library. And I lived in libraries when I was in college right now, you know, I got, I graduated long before the Internet. When, you know, when Google came out, you, you no longer had to go to the library. You could just reach out and grab stuff, um, and you could query and you can find where somebody else had written stuff. And now you have, you know, in some cases, you know, you've got your mobile device and you can literally go, there's something here and you can type it in and bam, it's in your hands. So that's what, that's why I think AI is the most amazing thing in the world. Uh, and I think I told you. But now let's pivot back just a tad bit. The scary thing, a little bit of AI is, is assume the way I was telling it to. I was speaking at a conference a couple of weeks ago. AI is a lot like having a 5 year old who has just discovered how to run. And uh, it's, you're like, oh no, come back, come back. Nope, don't play there. And so building the proper guardrails because you know what's bad to build those, those things, those guardrails around what is bad before the five year old can get to it or they can. And I'm, I'm that kid who stuck a paperclip into the plug on the side of the wall. That's why they exist now, I'm sure. But I was the one who did it and zapped myself as a small child. So, you know. No, consider those things before you go down that path.
Speaker A: Love that and I love that. And we'll get into your. What you're building now because I think that probably piggybacks well into that before we do that. I love to. You've worked at a bunch of cool Uber and a bunch of other companies. I'd love to hear if you have any stories that, that I'm sure you have a couple but uh, especially for folks are getting to cyber or even just experience folks. What are some stories that kind of stick with you today that you know, you can actually leave out the company name or leave out the specifics obviously. But if there's something where you. There was a lesson that you learned that was really just pivotal for your career, for your. For your growth. Yeah. What comes to mind?
Speaker B: So it's. It's. It was really interesting because you. You sent. I got to see some of the questions for the audience at home. I got to see some of the questions before this. The really cool part is, of course, uh, in these types of things, you get to do that. That really cool introspection.
Speaker A: Who.
Speaker B: Who is Ward? Where did it come from? And it. It. It made me go back and sort of look at my arc. And so I kind of came up with three stories to this. I'll. I'll. I'll tighten them up real quick. But. So the first is, is how did Ward start approaching system thinking? This is really important because I'm a system thinker. We'll get to what that means and why. I was in college. I was actually a dual major. I was comp. Sci fi and I was biology. Nothing, nothing interacts between those two. So I would spend all morning in biology classes, all afternoon, because there has never been a computer science professor who starts a class before noon. All afternoon in computer science and then all evening in labs of some sort, either back and forth between the two. As a senior in college in biology, pre med, you had to do studies. I got, uh, in. Your advisor gives you the same study. He has given. He or she has given. The last 300 students have come through. I was presented with pretty sure about a thousand, uh, lab notebooks that contained the genetic traces for what are called heat shock proteins. HSPs in rainbow trout. Big business in western North Carolina, where I was going to college. Grew up. What it means is a protein isn't turned on in a farm raised versus a wild trout. Huge temperature extremes will actually kill the farm raise, unlike the wild trout. Okay, what. What does that have to do with computers? How you think, how you approach the world? I was handed a thousand notebooks of everybody doing the same thing over and over again. Mapping out, trying to find the, uh, where the entry and exit points of the. The map, the genetic code that triggered those, the. The. The various HSPs. And I went, I don't want to do that, Professor. That's stupid. Why would I do the same thing that, you know, a thousand people before me have done? It doesn't. We haven't learned anything. So now let's. I was. I was computer science. We studied databases. Now, this is very early. These are vax vms. I want to say that I ended up writing it in FoxPro. So anybody older than me who remembers FoxPro, give me a call. And so I wrote this database where I put kind of everybody's research in, generally their research in. And what I then could do is I could write SQL, uh, queries that would tell me actually where the gaps were. And once I knew where gaps were, I could then go and actually pull the specific genetic strap, uh, or, uh, chain that mapped into that gap, and I could fill the gap in so that I could map much more quickly what the entire trout DNA looked like so that we could actually look for the points where we were trying to trigger and actually turn those proteins off. It turns out that it eventually became what we call bioinformatics today. But I was playing with it before we had a cool name for it. Okay, so what did that. The first piece of that was it taught me to, you know, sure, everybody else has done this path, but is that always the right path? So instead the, the, the engineering look is I look for the gaps. And how do we answer what are in the gaps? Fast forward several years. I was working for a gaming company in, in Silicon Valley. And, uh, I, I owned the E Crime team. And we were tasked to go into a couple of the games where we had a lot of fraud going on.
Speaker A: On.
Speaker B: And they asked me to, to help mitigate that, slow down the fraud, um, because we knew the fraud was going on because they were hacking the code. The problem was it would take a lot of research in order for us to actually understand what piece of the code, uh, had been hacked in order to, to stop that specific behavior. And I went, that's wrong. That's hard. That's again, the, the underlying to all of this is Ward's lazy, so he wants the easy way. And so I tore it apart and I went, well, wait a minute. This is an economy. It's a virtual economy. And we know when a dollar comes in, what a dollar can sort of make across the infrastructure, right? What it can turn into. And so what we could do is, is then by tracking the way inventory appeared within people's gaming systems or within their gaming profile, we could actually then very easily pinpoint and say, oh, uh, you found the code hack for this. We then leveraged even above that and we started paying attention to there was, uh, an associated black market to the game. And we could actually see how they laundered it across and back trace. Okay, that's pretty cool. So now we know what code bases are working, but now we also have got something really interesting. We've got the bad actors in the game and the bad actors are going to stay around, they're going to continue to figure out ways to break your game. Well then what we did was we actually started to mess with the bad actors. So, you know, the common thing was you go on a forum, I will, you know, I'll PayPal, you say, a hundred dollars and you're going to give me something like this. What I could do is now I'd mapped out all the bad actors. What we could do is we could allow them to mass up, you know, a hundred boxes that they're getting ready to give to the their customer. And as soon we would even allow the transfer of those hundred boxes. And as soon as both of those players logged off, we would gank back the hundred boxes, we take them right out of their inventory, and we would put them right back into the guy's inventory who had just sold them. So now you come back and you're like, dude, where's my hundred boxes? Yeah, I just paid for 100 boxes. This dude transferred him. I saw him in my account. And then you'd go and look at the inventory for the dude you just bought them from, and he had a hundred boxes sitting in his inventory. And you're like, son of a. He stole it from me. And you would get mad and the first thing you would do is you go into the forums and you'd start complaining about it. And then he couldn't sell. So one, we're fixing the, we're fixing the code on the back end because we figured out what you're doing. And two, I've destroyed your reputation. They, uh, that gaming company, the forums, when they found out how I played, I, they nicknamed me the Dark Knight. I was, I was Batman. And they, when we had a community meeting and they actually had me show up because people wanted to meet the dude who had broken the black market. And. But that also highlighted a third thing for us, which was you can't tune out the black market. There has to be a little bit of that give and take. Which then later on in life came to. I worked at companies like Hacker1 where we realized we still want people testing all the doors and all the windows and we should reward those people because they're helping keep us safe. So let's kill the black market, but give them a real way that they can share stuff with. So if you kind of watch my arc of, ah, life or career, it has, it's been like, all right, where are the holes? And then how do I fix the hole? But also make sure that hole Never causes me problems again. And then. But at the same time, I don't want to completely destroy it because there are people out there, you know, you can't. There are people out there who can feed me stuff. So let's, let's figure out a great way to work with them so that they can continue to feed me the information I need to be better.
Speaker A: That's fun. That's a great story. I love that. That's a cool, uh. I, uh, bet that was very rewarding, uh, the, The E. Gaming, uh, story. And I loved. I mean, first I heard like, the systems building. I heard like, obviously seeing the system, understanding how it works, getting into the data, obviously, like curiosity even kind of. We talked about the beginning of like, what you look for and that curiosity or that, that those tinkerers or people are trying to figure out how things work or how to build things. And then I think, I don't know how you train this or how other people can do this, but you, you, uh, you beat them at their own game, pun intended, on multiple levels there. But, uh, you, you understood the psychology of, of their, their economy and the reputation.
Speaker B: And hey, it goes back to what you and I said. If, if we weren't. If we didn't have parents that sort of tried to make us good, we would have been bad. So instead of letting go of that perspective, I know that it's bad. Right. I walk into a bank and I. Look, not that you walk in the banks much anymore, but. Right. But paying attention to those things and then noting them in your head so that later when somebody goes, well, how would you do this? You go, uh, well, based on what I have observed, uh, right. So I mean, anybody who observes and pays attention to the world around them, um, you know, my kids will tell you how mean I was to them growing up about taking away their. Their, you know, their handheld babysitters because there's so much world around you. What are you. What are you doing? Get your face out of it. You know, I worked in a boy organization for years where at the beginning of. Of camping trips, I had a bag. And they would all put their phones into the bag, seal it up nice. And all the detoxes, poor kids would go through my mom. She needs to hear from me. No, she. She knows you're with me. You're safe.
Speaker A: Okay? She's okay.
Speaker B: But. But then they opened up. Right? And that's exactly it is, is the. With any employee, if you see them, you know, I'm going to. We've AI back For us, the employees, it doesn't matter. I don't care how old you are. I have seen. I've seen people who are, you know, a year out from retirement, who've gotten AI and are like, dude, I'm staying for five more years. Look at this stuff. I can generate from my desktop. Like, I have seen CFOs who are like, no, really, that's what you're thinking. And, like, their expel sheets are like, uh, you know, magic now. So anybody who sees it and goes, oh, what can I do with this? And plays with it, is that play instinct?
Speaker A: Yeah. I love that we could talk another hour on play, which I wish we could, because I think that's actually another great parallel even to how to combat AI.
Speaker B: I could talk for hours.
Speaker A: I love it.
Speaker B: I love it.
Speaker A: We only got a couple more minutes left. I want to hit your. Your current what you're building now. Let's talk about. Tell me the why. Tell me what you're building. Why is it important the problem you're trying to solve? Yeah.
Speaker B: So remember I said, uh, sometimes I'm dumb, and I like that. I was playing with AI, uh, year, year and a half ago, and I thought, oh, dude, this is really cool. I like the code completion, right? I played with copilot. I thought, that's. Oh, that's really cool. Oh, no, that was dumb. I just gave it a, uh, token. Oh, I just. I shared a.env or whatever, and I'm like, oh, that was stupid. I wish it had told me. I wish there were guardrails there to keep me from doing stupid things. Because occasionally I'm not going to be thinking I'm banging away on something. I'm like, oh, yeah, here, go look at this code base. And then I gave it away. So I wrote something. I said here. I called it prompt Trap. I said, when I put a prompt in, it does something stupid, tell me before you let it run so that I can clean it up. And then I thought, oh, that's pretty cool. Wrote a patent on it. And then I threw it over in the corner because I'm like, I'm the only person who's an idiot. Which is generally my perspective is. I'm like, nobody else is going to be this dumb. We fast forward a year, and then I discovered that the entire security industry is going, son of a, uh, people are doing stupid things in prompts. And then there got open claw and they're getting prompts back in, and, oh, the world's gonna go to hell. And I was like, uh, hey, I built something to stop this nonsense. And so in that point, and then we were having the conversations about mcp, and I went, hey, you can do this. I can write this as MCP. And then it was like, you know, 80 to 90% of the traffic for going to these LLMs is via web browser. And I'm like, well, I can write you, uh, a Chrome extension that does all of this.
Speaker A: And.
Speaker B: And then I was like, this is pretty cool, but there's nothing here. And I started showing it to former engineers of mine and buddies of mine. And they're like, and my engineers, that was the best part. They're like, hey, uh, when you're gonna get funded so I can work for you, this is cool. I'm like, really? And then I was showing it to actual businesses, buddies of mine in businesses, and they're like, dude, can I buy this? Can you deploy this? I was actually talking to a VC who was looking for it as a solution. And we, uh, made it about 15 minutes into the sales presentation, he. He stopped. And my, My buddy was with me. Uh, oh, he's put his VC hat on. I'm like, huh, huh, what? And he goes, how much you looking to raise? How quickly? And I was like, wow, okay, I guess I'm looking to raise. Fast forward. We go through rsa, I start talking to people. I've talked to a couple. Basically what I have realized, I don't want you to stop using AI. So I am very AI agnostic. Gartner has recently called the category, what is it? Guardian Agents, I think is what they're labeling it. And I live and play in that world, which is to say I help guard your AI. I don't care what you're using, I don't care what agents you're using. I don't care what provider gives you, uh, that you build your agents in. What I do is I add policy to them. I add governance to them, add human in the loops to them, and then I give you attestation so when the auditors start coming out, because regulated industry, if anybody's paying attention to the regulated industry, we've got, uh, compliance checks coming out the wazoo. We've got. The government's got them coming. Uh, EU's got them coming. Although I just read they're pushing them until October now. They were supposed to start next month, but I think it slipped. Wyoming has them. Uh, I'm like, no, Wyoming. Yeah. So we've got a bunch of these controls that are coming. SEC is looking at them about the attestation, what your agent's doing. And that was actually where I started. Remember, go back to my story, my story arc. I always look for the gap. And the gap started off for me going, oh, that was stupid. I'm not paying attention to what I'm putting into my prompts. And sometimes I'm cognizant of it, sometimes I'm going so fast that I don't do it. And so instead what I did was I came back and I built a tool to pay attention to my gap. And we fast forwarded it and everybody's got a similar gap. And unfortunately we also forget that AI runs at the speed of our thoughts, basically. And so we're giving it all the authority. Yeah, here's my keychain. Go have a good time. And it goes and runs wild. You know, we've read about the company that lost their entire code base because an agent went, well, I can't go this way and I can't go this way, so I'll go this way. Right? And what mine does is the first time it tries to go through the door and it says, no, you're not allowed to do that. And he goes, well, I'm going to pivot this way. And we go, no, you're really only allowed to go this path. So we're going to escalate this. And when Bob, your caretaker, comes back in the office tomorrow morning, Bob can release you if he feels like that's a good thing, otherwise we're done. And you can go back and sit in the corner and wait until somebody else feeds you a new instruction. And that's, that's the way we should be approaching it. That's the way you approach an employee. We just are forgetting that in essence these are running like we have a thousand employees and they're running nonstop and they never stop to take lunch, uh, break. And so I just, I took that knowledge and applied it against the agents. So that's it. That's what behavior does. It gives you that control, allows you to roll any AI you want, any ide, any approach that you want, and gives you that governance attestation.
Speaker A: That's awesome. I know we're up on time. Do you have one more minute?
Speaker B: Yes, sir. Anything?
Speaker A: Okay, I do have a two part question. I'm curious, uh, who would you consider like your ideal customer? Are you looking to like mostly enterprise or highly regulated? I know you're still early days, but like, who are you building this tool for? When you think about that ideal organization and the second Part of that question is what feature set or area that you're building in is different than everyone else? Because I think there's like, there's so many people in AI security, it's like it's mind boggling to even figure out what they're doing. Um, I'm just curious as you laugh, uh, what area if you're like, if there's a differentiator, like there's something you're building that no one else is doing.
Speaker B: So we're gonna answer. I'm gonna answer the second piece first to your. Which is hilarious. So there are. I have a competitive analysis tool because again, if I need to understand something, I'm gonna go and build a tool for it. And so I built a competitive intelligence tool, the CI tool for my company. I am at present tracking 93 companies who do, who play in the spectrum of, we'll call it AI governance. And that's, I'm loosely using that, AI governance. So there are 93 different companies doing this. And I have got a grid that tracks, I want to say like 15 different characteristics, uh, and matches them back against myself and everything like that. So I mean, there's not a company I have not looked at, can't tell you about and actually tell you the pluses and minuses, all of them. And then how I compare. Now what makes me completely different and how I get to play. And hopefully we'll jump forward beyond these is back to sort of that concept that uh, that Gartner's playing with, which is the, the guardian agents. I give you a couple of things that nobody else is doing. One, I live in line, so dirty word proxy. I proxy your AI. Uh, traffic. Okay, why do I do that? Because the agent writing its logs should not also be telling you that I'm good. Right? We don't attest ourselves. That's right. You know, finance has been teaching that for years. We don't have the criminal that we just caught breaking into the house. Write his, his report. Uh, when we turn it in, the cop writes the report because he observed them breaking into the house. Same idea with agents. So I don't allow self attestation. Uh, I attest the agent because I monitor it from outside. I also monitor it in real time, so every action is reviewed before it's allowed to go forward. So if you tell me something, I can make a determination as whether that action is allowed. I'm also not binary. I don't go yes or no. I go yes, no, maybe. Maybe is an escalation which none of my competitors are currently. Well, there's one maybe who has an idea like that. So those are the first two and then the third is what we call. Or that's, that's called the decision tree. So the first is the attestation, the second is the decision tree. And then the third component to all of this is you don't even have to rely on me for your attestation because I hash everything. It's actually outside of even my system. So you can verify. An auditor can walk in the door and ask for a hash or something and verify themselves that the actions actually occurred. The closest thing to sort of imagine is, is what we, we expected when we were looking at the early days of not Bitcoin, but when we were looking at Coin and the, the, the fact that it's a ledger and you can't change the entry above it, you just write the next P, the next entry, next entry and next entry. I've built that, if you will, into the agent interaction. So you don't get to modify anything. And in fact, if you try to modify it in the system, it breaks the hash and then it highlights it up to you and says a hash has been broken. So the auditors in the audience went, yes, that's what we're going to start asking for. The CISOs in the audience went, yes, that means that every action has something. The CIOs and the CTOs in the audience went, so wait, you can let me deploy any AI? And I go, yes. So I, uh, that was I again, I went back to the gap. What's the gap? I want to deploy AI as fast as I possibly can, but I got these people screaming at me, okay, my ideal customer. It really turns out that probably my ideal customers are going to come out of regulated industry initially, although I also built multi tenancy, my first customer was a msp and they like it because they roll it out to all their customers and it's all the same. So they literally every customer has a AI footprint and it doesn't matter if one customer is using POD and One customer's using ChatGPT and another's using Copilot. They all look the same in terms of the reporting. And so they didn't have to retrain their staff. Their staff is like, oh yeah, we got so and so over here. It's got an agent that's doing this and this and this. We need to limit that. So super cool.
Speaker A: You covered it. I love it. That's super helpful. That's super exciting. Great conversation. Word really enjoyed it.
Speaker B: Thank, um, you so much for having me.
Speaker A: This is super fun. How can folks connect with you online?
Speaker B: A couple ways. Behavior AI. So I'm wardhavory AI and that's B E H A B R Y. AI can't even spell my company's name, so that's the first to look for me. You can find me occasionally on Twitter at Ward Span. I've been there, God, since I. And I still call it Twitter. I'm sorry, I refuse. Elon, hunt me down, bro. So you can find me as Ward Span on Twitter. You can find me, yeah, most of the social media post and I'm ward span on LinkedIn as well. So, uh, I think that covers the. The professional ones.
Speaker A: Right? Super cool. Well, thanks for gaming for coming on. We'll throw all those links in the show notes and yeah, great conversation. Best of luck in your endeavors and, uh, yeah, thanks everyone for listening to the show.
Speaker B: All right, thank you for having me.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.