The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Down the Security Rabbithole Podcast
Down the Security Rabbithole Podcast artwork

DtSR Episode 712 - Lies My AI SOC Salesman Tells

Down the Security Rabbithole Podcast · 2026-06-30 · 32 min

0:00--:--

Key moments - from our scoring

Substance score

44 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber13 / 20
Specificity & Evidence6 / 20
Conversational Craft8 / 20

This episode dissects the misleading sales narratives around AI in security operations centers. Seth, drawing from 25 years in security including roles at NSA, Mandiant, and Facebook, explains why the prevalent pitch of AI eliminating analyst jobs is both unrealistic and undesirable. The conversation centers on Embed's philosophy that trust in AI systems requires three pillars: accuracy, consistency, and transparency. The hosts challenge the industry's obsession with '99% accuracy' claims, noting such blanket statements ignore the non-deterministic nature of LLMs and the complexity of real-world incident response. Rather than replacing humans, properly implemented AI excels at focused triage problems within constrained spaces - like alert correlation and noise reduction - while struggling with novel threat discovery requiring genuine investigative creativity. The discussion addresses how AI should augment SOC velocity and volume processing but cannot yet provide the clarity needed for legal accountability and comprehensive threat understanding. MSPs and MSSPs must adapt by using AI to multiply analyst productivity rather than reduce headcount, though this creates real concerns for entry-level security talent trying to build careers in an increasingly AI-dependent environment.

Key takeaways

  • →AI vendors claiming 99% blanket accuracy across all alerts are misrepresenting capabilities; if this were true, the security problems would already be solved.
  • →Effective AI in SOCs requires transparency (showing work), consistency (reproducible decisions), and accuracy - not just accuracy alone, which mirrors how human analysts must be trusted.
  • →AI's sweet spot in security operations is deterministic triage with flexibility, not novel threat discovery or persistence mechanism identification, which still require human creativity.
  • →SOAR solutions promised automation a decade ago but failed to deliver; the new generation of AI-powered tools faces similar hype cycles that require realistic expectations about what gets solved.
  • →Entry-level security professionals face legitimate career concerns as AI multiplies analyst productivity without necessarily creating new junior analyst positions.

Topics in this episode

AI in SOC operationsEmbed (company)Alert triage and correlationSOAR (Security Orchestration Automation and Response)Mandiant incident responseThreat hunting versus threat detectionFalse positive reductionAI transparency and auditabilityMSP and MDSR scaling with AIEntry-level security careers

Questions this episode answers

Will AI replace SOC analysts and security operations jobs?

No, roles will evolve but humans remain essential; AI's value is multiplying what existing analysts can accomplish, allowing 50 humans to do 5-10x more work rather than eliminating positions entirely.

Why should you be skeptical of vendors claiming 99% AI accuracy in security alerts?

If AI were truly 99% accurate across all alerts, the security problem would be solved and vendors wouldn't need to sell it; blanket accuracy claims ignore the non-deterministic nature of LLMs and don't account for real-world complexity.

Where is AI actually useful in security operations versus where is it not ready?

AI excels at focused, deterministic triage tasks with flexibility to explore multiple tools, but fails at discovering novel threats and persistence mechanisms that require human investigative creativity and expertise.

What makes analysts trust AI systems in security operations?

Trust requires three elements: accuracy (correct decisions), consistency (reproducible results across runs), and transparency (showing the evidence and reasoning behind recommendations), not accuracy alone.

How is Embed approaching AI differently from simple LLM implementations in SOC tools?

Embed builds systems that expose underlying evidence, queries, and historical context so analysts can verify or dispute AI decisions, rather than simply treating AI as a black box that makes pronouncements.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

A handful of genuine operational insights emerge (trust = accuracy + consistency + transparency; AI best at focused-but-flexible triage problems; AI poor at novel discovery like finding new persistence mechanisms), but they are buried under movie tangents, broad agreement loops, and repeated 'I think' hedging that consumes most of the runtime.

trust is accuracy. Yes, but it's also consistency and then transparency. Right. So do you, not only do you get the right answer, but do, can you reproduce that right answer? And then are you telling me how you came to that answer?
it's going to be best at like focused problems but not like, but, but, but areas where you want flexibility... a triage is fairly deterministic, but you can't put it in a playbook like soar

Originality

8 / 20

The three-part trust framework (accuracy + consistency + transparency) is a modestly fresh reframe of a common debate, but nearly everything else - SOAR never delivered, AI won't fully replace humans, 99% accuracy claims are marketing - is standard 2024 AI-security discourse recycled without new angles.

the marketing promises never really quite delivered
if your AI stock vendor is saying they're 99% accurate on anything and 100% of alerts, you can give it, like, they're. They're feeding it to you

Guest Caliber

13 / 20

Seth has genuinely elite operational credentials - a decade at NSA, joined Mandiant at ~50 people, ran security support for Facebook's business-unit CISOs - making him a real practitioner, not a thought-leader; the episode only partially taps that depth due to its conversational sprawl.

I spent about a decade at the nsa. I spent roughly another decade at Mandiant... Joined fairly early in that, maybe 50 people or so when I joined
I spent a, a few years at Facebook supporting what are roughly their business unit level CISOs

Specificity & Evidence

6 / 20

Almost no concrete data, named clients, or measurable outcomes are presented; the '5-10x per person' productivity claim is asserted without any supporting evidence, and the most specific detail in the episode is Mandiant's headcount when Seth joined.

now they can do five times or ten times as much per person that's there
maybe 50 people or so when I joined

Conversational Craft

8 / 20

The hosts occasionally land substantive questions (where exactly is AI best/worst in the SOC lifecycle; will lower tiers be eliminated; will insourcing resurge) but consistently fail to follow up when answers stay vague, and the episode is derailed twice by film references and long host monologues.

what are the specific, where does it, where is it is this type of technology best? And then at what tasks is it the best at?
I just watched the most insane movie the other night. Uh, total sidebar. But, like, it's called Balls up with Mark Wahlberg

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker D44%
  • Speaker B31%
  • Speaker E15%
  • Speaker C9%
  • Speaker A2%

Most-used words

security19different18answer12saying11technology11seth10everybody8problem8back8podcast7early7human7trying7data7rabbit6hole6

Episode notes

TL;DR: Seth Summersett of Embed Security joins the podcast to talk about the snake oil that's coming from the AI SOC sellers. There's such a significant gap between what you're being sold and what's real. Seth and the gang talk about what's real, what you should expect, and where the line of bullsh** is. YouTube video: Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: LinkedIn Page: X/Twitter:

Full transcript

32 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: They say, they say we should have known better than to fall so deep down, um, deep down into this rabbit hole we found. And I was thinking, hi, this is Nikolai, and you're listening to my dad, Rafal, co host James Jordanian, and featuring Mr. Jim Tiller on the one and only down, um, the Security Rabbit Hole podcast. Plug in, listen up and en deep into this room.

Speaker B: All right, good morning, good afternoon, and good evening. Welcome down the Security Rabbit hole to yet another edition of the down the Security Rabbit Hole podcast, the cyber security industry's favorite podcast. Because everybody wants to be on the show. And today, Seth, it's your turn. So real quick, before we get diving too far, I want to keep saying thanks for everybody that's given us reviews and likes and follows and whatnot. Keep that up. The way that people learn about this podcast and the way that people get to know that we exist is when you Repost us on LinkedIn, you know, help us with the likes and reviews and such on whatever platform you're on, because that circulates and gets us to the top. And I really appreciate it. I know everybody else on this podcast really appreciates it too. But today, today it's about, once again, about AI but if you're, if you look at the title of this pod and you're like, huh? What are they going to talk about? Well, hi, Seth.

Speaker C: Hello.

Speaker B: All right, give everybody a little of who you are and, uh, what you do, and then we will dive in.

Speaker D: Sounds Great. Me personally, 25 years in security now. I started out, I spent about a decade at the nsa. I spent roughly another decade at Mandiant.

Speaker B: Oh, you're one of those.

Speaker D: I, I am one of those. I'm a proud ex mandianter. Joined fairly early in that, maybe 50 people or so when I joined. So I got to go on a great journey there. See lots and lots of cool stuff. And then, let's see, then I, I, I spent a, a few years at Facebook supporting what are roughly their business unit level CISOs, and then left to, to, to start Embed. And you want me give a quick rundown on what we do.

Speaker B: I would love this, though. I'd love to hear about Embed, because you just gave me like, the big arc of awesome jobs and the pot of gold you just landed. I want to hear what that is.

Speaker D: Yeah, so I, at Embed, we're looking to solve a problem that I've actually felt I've lived through. I've watched, I've kind of helped tinker with folks, and that is security. Operations. Just watching security operations teams at uh, companies at MSSPs and MDRs and just watching the repetitive nature of what it is that they do. A decade or so ago when SOAR hit the market, I was like, this is exactly what we need. I was like, this is totally going to solve these problems. A decade on, the marketing promises never really quite delivered.

Speaker B: Wait, wait, hold on, hold on. I want to know just how shocked you are by this that the marketing promise of cybersecurity did not deliver.

Speaker D: Yeah, uh, yeah, I guess my price is not super high, but to be honest, I was pretty positive about what I was seeing early on. Um, and it just never quite delivered. So, so an old co worker of mine and I came together and we said, hey, there's been some changes in the market. We're super passionate about this, about this problem and we actually think we're going to be able to come up with something that, that, you know, really moves the needle. And so we left our roles and uh, started in bed to tackle, you know, effectively alert overload and the problems that come and surround that.

Speaker B: All right, well, let's start with this then. As I aptly titled this pod, there has been a lot of security leaders, SOC leaders, cyber defense center leaders that have been told, hey, I've got a product for you. It's going to eliminate the need for people altogether. Forget the sim source stuff, that's all old technology. You know, AI is the future and while I am on board, there's a lot of awesome things AI can do. One thing I don't do not think it can do is replace all those happy people that sit and stare at screens all day in, in like the full capacity replacements. What do you think?

Speaker D: Yeah, that is not our philosophy and hasn't been our philosophy since the beginning. So we actually did a blog post on this maybe a year, year and a half ago where, you know, it was basically like, should I be worried about my career in security? Um, and our answer is no. You know, we do think that people's roles are going to evolve and we hope that they evolve them in a very positive way, which is taking a bunch of the mundane work off of their plates. But that human ingenuity, that human thought process, bringing that stuff in, it's definitely still necessary in our opinion.

Speaker B: Yeah, I, I like that. I, I Anytime somebody tells me we're going to replace humans, my first thought is cool if it's for all the things that we don't want to do anymore because we're sick of doing it and Then my second reaction is, okay, show me. There's been a lot. There's been a lot of sizzle. Right? Very, very little meat behind that.

Speaker E: I've been. I've been.

Speaker B: I've been. I just watched the most insane movie the other night. Uh, total sidebar.

Speaker E: Sorry.

Speaker B: But, like, it's called Balls up with Mark Wahlberg. And, like, if you've never seen it, it's about World cup soccer. And, and, and. And two guys that are just like, these hapless pitch men for adult.

Speaker C: Make sure you get the parental advisory warning on that. Uh, for anybody that's thinking about going,

Speaker B: yeah, yeah, yeah, it's. It's, um. It's definitely not, like, kid friendly. It's got some adult humor, but it is absolutely hysterical. And, like, the, like, the running theme to the movie is, like, one's the sizzle, one's the steak, and they learned that they need each other. So, like, there's been a lot of sizzle in the market.

Speaker E: Right.

Speaker B: There's been, uh, tons of hype. Everybody's got the answer. And much like in times before, I want to be hopeful, but I'm also fairly realistic in that there are limitations on what AI is going to do for us. And, uh, I want to be realistic about what we tell people because it's. No, it's not just a repeat of Soar. Right. There's so much, so much better stuff that's going to hopefully come with this. The technology is different. It's. It's a much wider pool of possibility. But to say that, you know, suddenly let's eliminate humans, I feel like is disingenuous probably, at best.

Speaker D: Yeah. I think, actually I see this frequently where people are like, oh, you know, we're 99% accurate just across the board. Blanket statement. Right. And. And, you know, my co founder, Jeff, always likes to say, if that was really true, like, the problem would be solved and none of us would be sitting here talking about this. Yeah, right. If your AI stock vendor is saying they're 99% accurate on anything and 100% of alerts, you can give it, like, they're. They're feeding it to you.

Speaker E: Like, that's.

Speaker B: There's a really good line from a really good movie. Like, 60% of the time, it works 100% of the time. We could do anchorman quotes all day long.

Speaker D: Listen, I, uh, think we talked about

Speaker B: this when we were setting this pod up. There's a framework within which I'm starting to really get comfortable. It's like these five prongs or maybe five metrics that you think about as technology evolves for us in the operational sense to make cyber defense security operations faster. And the two that we initially had a problem with when it was just analysts looking at screens is velocity and volume. Right. And as we added more hardware, volume went up and then we cloud and now AI velocity shot up and now they're going up at the same pace. So they're both off the top of the chart and into some sort of stratospheric level where I don't think there's anybody that's going to argue, like, put humans back on and we'll do manual correlation. Like, that hasn't existed for 15 years.

Speaker C: Yeah.

Speaker B: However, with technology, and you said it right, 99, accuracy comes the accuracy and precision question. I think earlier AI iterations were

Speaker C: hit

Speaker B: or miss on accuracy and by nature, like outside the bullseye half the time on precision. Which means that, like, they could 50, 50 get the answer right, but they couldn't. They would get to it in different ways and it wasn't repeatable work. Which is terrifying if you're trying to put something before in front of a lawyer. Right. As in, like, this is what I know for truth. And I think the last bit of it is the fifth prong in this, and I think this is the one that sits on top of the other two. Other four. Is this concept of clarity, like, yes, you can take an alert correlated to another one. Pull in some context from here, pull in some context from here, Network endpoint, you know, blah, blah, applications, identity, blah, blah. But you've now solved or addressed that. What I want to know is why did this happen? What else happened? Where did it go? Like, how big is the problem? Should I still be worried? And we're nowhere near that yet.

Speaker E: Right.

Speaker B: First of all. Oh, sorry,

Speaker E: I was just gonna say, but isn't that AI strength is being able to look very broadly pretty quickly?

Speaker B: Is it?

Speaker D: Yeah, I mean, I do think it can. So you are right, Jim. Like, AI gives you the ability to look across and or reason about a much larger corpus of data than what you could do in other types of technologies. But that still leaves you with this, what I think Rafael's getting to, which is how did you come to that conclusion? Right. So I've given you tons and tons of data, but, like, how did you get there? And then if I give you that same data many times, you know, are you actually going to come to the same conclusion or just each time you come to a conclusion, but it's different Right. And I think, I think that's, he's really tapping on the door of what I think makes this a really hard problem, you know, because I think we can all go out and we can create a prompt and we can toss in an alert into that prompt and then we can say, you know, please reason about this. And you know, it might come up with something kind of neat, might come up with something cool and something we kind of agree with, kind of don't, but then if we run it through again, we're going to get a different answer and it'll look different, it'll feel different, maybe the overall decision is the same, but uh, so you end up with this weird thing. So at Embed, we've come up with uh, the operating principle we've been using since the beginning is like a lot of people kind of think like trust in a system comes just purely from accuracy. Does it always get the right answer? And I think no or we think no as a company. And the way that we think about it is trust is accuracy. Yes, but it's also consistency and then transparency. Right. So do you, not only do you get the right answer, but do, can you reproduce that right answer? And then are you telling me how you came to that answer? And that's critical in my opinion, to get security people to want to adopt this and trust it.

Speaker C: Don't we have some similar problems though with people, I mean, same person looking at the same data 2, 3, 4 different times could potentially come up with same, uh, you know, different responses, different outputs. I mean we put a lot of pressure on AI to be right. 100% of the time we say, oh well, it's non deterministic. Yes. So are people even take three different people, give them the exact same data, they'll come out with way different answers and responses. Right. For that same stuff. So I mean, aren't we seeing the same thing with AI? Like we haven't fixed anything there, we still have bias and all this other stuff that we say we get rid of. But you know, we still could come up with different answers. At least we can more easily show our work, I guess as a person versus AI, we, you know, I don't know what happened once I sent that prompt off.

Speaker D: Yeah, I think it's kind of interesting. My co founder Jeff and I had this discussion really early on and actually I haven't gotten the pushback that I assumed I would from the security industry, which is, I thought it would be a lot like, you know, Tesla and the auto driving cars. Right. I think we hold that auto driving car to a much higher standard than we hold a human. And so I was expecting the same kind of thing on the AI side of like hey, we can't be wrong, even though human can be wrong. But I haven't gotten quite that pushback. But from an MSP MDRS that we work with, it's exactly that that they're after James, which is, hey, we have a lot of inconsistency between analysts and so we really want to have a base level of consistency that we're working with. So. Interesting there.

Speaker E: I have two questions for you. One is when you say like I get repeatability, but being able to prove what you did, determine what you did, sounds more like emphasis on forensics as opposed to dealing with the problem. It sounds a little bit after the fact to me. Am I misunderstanding that? Because I think when you're.

Speaker B: It's auditability, Jim, isn't that what you're looking for? You're asking for auditability. Show me how you got your answer. I'd like to know.

Speaker E: Yeah, I mean how, how, I guess how often is that the case when I know when you have a false positive like you take action on a collection of information, you know, different analysts have different perspectives. You kind of come together and say, okay, I think this is happening, we need to shut down X kind of thing. And turns out you just shut down the manufacturing plant for no reason. Right. So I can that from an auditability, from a uh, reportability or forensics scenario. But don't, don't you see value of AI on the upfront? Sort of like in the early days of enrichment activities and early days of automation to, to accelerate these things? Don't we see it more being value on the front end as opposed to worrying about it being to be able to like prove its work because it's non deterministic, you know, I get it.

Speaker D: Yeah. Well I think that's the, I think that's the hard part of what, right. I think if people are just, if people are literally just using LLMs in their AI stock like that, I'd say be super skeptical, be really concerned. There's a lot more that we've put into this than just throwing things at an LLM. And so we're taking that non deterministic and we're trying to minimize the impact of that non deterministic on the outcomes of things. And so part of that is can we show the evidence of how we write decision that we want? So ultimately at embedded we want to sort of Summarize things in a way that makes it really easy for people to say, like, I agree or disagree with your decision. But if we get that analyst, that's like, like, prove it to me. Like, why, why did you come to this decision? I don't want it to. We don't want it to be like the. Those early AIML products where like, you, it said it was bad, and then you were like, I don't know why it said it was bad. So I gotta go redo the whole investigation to figure out why I thought

Speaker E: it was bad, bad.

Speaker D: And so that's why we're trying to like, make sure that we're exposing what is going into this. Where are the queries coming from? What data did we find? How is it that we're like, what old memories are we bringing in? Like, that kind of stuff? And then you can leverage that to say, like, if you really want to deep dive now, you shouldn't be doing that on every tree object.

Speaker E: Right? Yeah, that's where that's. I think that's where I start to separate the two sort of pre event and post event kind of arc, you know what I mean?

Speaker A: Yep.

Speaker E: Ah, so just, just because, um, former nsai, a lot of intelligence, maybe not a lot of intelligence, but there is AI being used in intelligence communities for arguably some of the same purposes. You would use AI and sort of threat detection and threat analysis. So do you see maybe AI being more useful in a SOC scenario just from a combination of intelligence through threat hunting as opposed to maybe just dealing with SOCK activities?

Speaker D: I'm not sure I follow, sorry.

Speaker E: In other words, pre event, like is like. What RAV was about earlier is I want to know all these different things. Right. So AI can be good at trying to connect these dots and at least sort of, you know, bring a color up on your dashboard, saying, hey, I'm sensing this, you know, you know, kind of like. And saying, I'm suspecting this activity and maybe help direct more specific type of investigative activities or that nature. Do you see AI playing a role in that space?

Speaker D: I do. If I follow correctly. I do. I mean, ultimately, like, we have multiple decisions that come out of, out of Embed's engine when looking at these things, which is basically, hey, like, I think you can ignore this. You should. You don't need to worry about it. It's just noise. This is actually malicious and you probably really need to take action. And then there's that concept of like, inconclusive. Right. Which is, hey, I tried to gather a bunch of data But I'm still kind of left like wondering, like a human needs to come in here and, you know, make these last, you know, connect the dots on these final things. And so our goal really is to escalate those things. Kind of like you're saying, like, bring a highlight to that, but not in a sense that like we're looking for the needle in the haystack to tell you. It's like, hey, we're looking at all of these things and these are the ones that need to come up. So it's, it's less about like that needle in the haystack and more like we looked at everything and these are the ones we think you should pay attention to. That's.

Speaker E: I think that's going to be pretty powerful, you know, if you're doing that. Because I think we have everything tells sort of the needle in the haystack. Right. I mean, we just got to find the needle. We've been given the shape of the needle is length, size, you know, and we know what haystack it's in. Sometimes we're not even paying attention to the haystack. Right. So I think that, I think that has, that has a pretty interesting sort of argument there because sometimes it's the bigger picture, like Raph was saying, that wider perspective, kind of that hundred thousand foot view. I think it's going to make a big difference.

Speaker B: Yeah, uh, I'm, I'm still a little bit. It's not even the word's not skeptical. What, what I want to know is, give me the, give me the places where this new technology, this new line of technology is, is best used, where it's useful and where, like, it shouldn't be applied. And I don't have, I've asked that a bunch of times. I don't really ever get a great answer. And uh, it's not just because, you know, I'm trying to avoid getting the salesperson answer. No offense to salespeople, but you all try to. Everybody try to tell me like, hey, no, no, this is, uh, applicable to everything. It's not. Right. So there are certain things non deterministic platforms like an AI are good at. There are certain things like the agentic conversation becomes very, very narrow. AI becomes good at. Seth, where is in terms of. In. Let's take Jim's. Sorry, let's, let's take Jim's line of thinking. Left a bang bang and right a bang, right. We're talking about socks. So we're talking about that little narrow time window before when we notice it hopefully before it come goes kaboom and then as it's happening afterwards, what are the specific, where does it, where is it is this type of technology best? And then at what tasks is it the best at?

Speaker D: Yeah, it's a good question. That's pretty, that's pretty broad. But uh, you know, it's going to be best like, it's going to be best at like focused problems but not like, but, but, but areas where you want flexibility. So think about like, like a triage, right? Like I think this is why we've seen so many companies pop up in the, in the world of triage is because a triage is fairly deterministic, but you can't put it in a playbook like soar. You know, it's, it's, if you do that, then you're only going to catch the one thing you know about, right? So like you get that creativity of the LLM and the rest of that stuff by giving it the right tools or agents or whatever you want to, to, to leverage and use and then it can pick those things and apply them. And I think that gives you a ton of flexibility within a confined space. Now where I don't think it's great, at least not yet, in my personal opinion, is spots where you need like real true creativity, right? So I think back to some of the things like at ah, Mandiant, right, when we had a compromise and it's like, okay, this box is compromised, but now you got to figure out, okay, how did they get on the box and what did they do while they were on the box. And you know, we had folks at Mandit, uh, that discovered new persistence mechanisms. The LLM isn't going to find something like that. That's where you really need the human to be in there finding that, pouring through the stuff and linking those things in that way doesn't mean it won't get there. It's just not there today.

Speaker E: That's a fantastic example. That is so spot on. You're absolutely right.

Speaker D: Yeah, that is, that, is that.

Speaker B: Okay, so that's good, right? Do you, do you think that the market broadly is repositioning itself that way?

Speaker D: I do think it's starting to sort of reposition itself that way. I think we're starting to see soc roles evolve. I think we're going to see companies, especially like your MDRS and MSSPs that are not adopting, building, buying, using this type of stuff. They're going to fall behind. Right? And it's not because you don't need humans it's because they can't do as much with the, you know, 50 humans that are doing that work. They, you know, they have to scale that linearly with the AI. If they're leveraging that, you know, now they can do five times or ten times as much per person that's there, like, that kind of stuff. So I do think we're starting to see it. I do think there's a hype cycle here though, of us still trying to learn, like, what it can actually do versus what, you know, these companies are telling you it can do.

Speaker E: I, yeah, I want to, if I may just comment real quickly on something that you said and I've, and I've gotten in discussions about this where you say it's not going to replace jobs. And then when somebody says, well, if you can, if you have X amount of work and X minus Y amount of people, right. And you empower them so effectively, that stops growth in the job market because it's being replaced in AI. So the net result is the same kind of thing. And I think there's some young people that I've interacted with that are trying to find their place as they go through this, uh, early trail and they're like worried about by the time they get to that point, there won't be any jobs left because the 50 people are, uh, now X minus Y is zero, right? Yeah. And so I think, I just wanted to point that out because I do think there's a lot of people in security, especially in the entry level, that are starting to get concerned because how do you keep up with it? And then, uh, the ones and then ones are using it, right. They're just using it to tell them what to do in some cases, which I think I probably done the same thing if they always around when I was doing it, you know.

Speaker D: Yeah. The way I think about it for the entry level folks, I think they're in a tough spot. Right. It's unknown. I can imagine it's scary. And like you said, will they be able to build the right skills to get to the point where they need to get to before AI takes over? Like, I understand that angst for sure, but I don't think if it was like, hey, security is mostly a solved problem and we're going to do this, there's nothing left to do. No, I think it's just like Ralph was saying earlier, yeah, you're taking these mundane things off of my plate, but the cool stuff is still there. I think the cool stuff exactly there. And I think it can really speed people's learning. I think they can. Rather than it taking years to move between these different levels, maybe they can move between those levels in less than a year or half a year or something. Right. Because they're able to learn so much from. From these things.

Speaker B: Seth, do you believe, like, as some others do, that we're effectively going to be able to eliminate the lower tiers of the soc?

Speaker D: Well, I think it depends on what you define as like, the lower tiers of the sock. I do think there are some pieces and parts that would get eliminated, but I don't think it's like, across the board. Right. I think tier one, tier two, Tier three is like a, uh, a way for us to use the language, but it's. It's not all that often. At least most companies where people like Square, they just fit in one thing. Right. People typically move between the different roles and stuff like that. But I think that we're still going to have to understand what it's doing, right? So, like, there is still an understanding and a need to understand the triage and why things were triaged and why that means it's good or bad, even if something else was doing it. So I think there's going to be a lot more, like, probably, like, rather than the tier one analysts sitting down to triage the alert themselves and pull that IP address out and contextualize it and network tools and do all that kind of stuff, I think what you're going to see is them validating the stuff that the LLMs and that the AI soft tools and stuff like that have done. Right? And so now their role is much more like, okay, well, let me poke around at what it's done to make sure that I agree with it. So they're going to need to understand it to do it.

Speaker C: But I'm curious to know, Raf, we talked about this so long ago. The idea of, do you build your own sock or do you outsource it? Does this make it. Will we start seeing more people insourcing their socks? And like, you know what? I'm going to do it myself. I got AI to help me. Like, why would I go pay some other vendor to do this? I mean, it's the cloud thing all over again. I went to cloud. No, I'm bringing it back. I went to manage sock. Nope, I'm bringing that back. Like, if I don't need one of the five experts in SOC work to be able to do my stuff, does that change the tone?

Speaker B: I'm gonna let you answer this, Seth, because you guys know my opinion on this.

Speaker D: So I'm a big fan of MDRs and MSSPs and stuff like that. Like, I don't. I am a lifelong security person, but I don't think that every company needs the. Try to find and hire security experts and keep them happy and employed and the rest of that stuff. So I think there's a lot of value in saying, hey, I'm going to let some other folks take care of this. But I do think there are a number of organizations that have outsourced, not because it's what they want to do, but it's because it's what they have to do for right now. And so I do think for those organizations, this technology does allow them to bring that back in house and manage it there. So.

Speaker E: So you think it's going to. You think that's going to create a trend to pull it back in?

Speaker D: I do think for organizations that are outsourcing because they have to, not because they want to.

Speaker E: Wow. Uh, I'm on. I think I'm probably on the same plane as Raf on this one. I think it still represents an investment. You have to still get the right people. I think it's going to be. It's going to be very interesting. But I get it when you say if a company didn't want to outsource in the first place, now they have a path to do it internally.

Speaker B: I think that. Seth, Jim and Seth. I think that number is very. I think that number is relatively small. The number of companies that had to. I think it's relatively small. I don't think it'll make a significant dent. And if we're talking about the whole. I think what we're going to end up with is. You know, I've said this before. I probably said it 10 years ago, and I'm going to say it tomorrow. The number. Every day I wake up, there's probably a few less companies that should have their own stock. It's because no matter how amazing the technology, Seth, you and your peers put out into the market, it does not solve the fundamental stuff that's between the ears. And technology is just a piece of it. You need process, you need funding, you need pipelines and pathways. You need process. And you're going to have to have that human. I just. I don't think that anytime before I retire or maybe before they put me in the ground, we're going to replace all security with. With robots or. Or computers. There's just too much that humans do that is Unique to us in the ability to have a hunch, a, A gut feeling and, and just, you know, take a chance.

Speaker E: And

Speaker B: if, if we're talking about, you know, do we need it, should it be a manager? And I think that that kind of stuff doesn't scale well inside of an organization. It just doesn't. You spend a lot of money as a company to effectively, hopefully never have to use it. Right. It's like writing a really big insurance check, paying a really. And hoping that doesn't happen. But it's not insurance you're buying. You're spinning up a really big team and going, man, I hope they never find anything or end up with having to actually go do that. Go do that bad day. I think that's my opinion.

Speaker C: Uh, and I'm not advocating for people to bring their sock in house. I'm just. A lot of the reason people didn't do that was because I can't go find 50 people qualified to go work my stuff. And if I only need two people to do it, because AI can do the rest, it becomes much less barrier to spin that up. Uh, and look, do you think people are outsourcing development work as much the CEOs are writing their applications now, right? Like, I mean, we're getting into a world where everybody and their brother and sister are like, listen, I can write that production app. We'll get us up and going in no time. Like, no. Say goodbye to the SDLC and every other piece that happened. We're just going to create it, we'll spin it up, we'll push it to production, we're good to go.

Speaker B: James, I love you to death, but as somebody who lives in AppSec, I know you don't mean a damn thing you just said.

Speaker C: No, I mean, people are doing that. Don't get.

Speaker B: They're doing it, I guess, whether it's a good idea or not.

Speaker C: No, it's not a good idea. I'm just saying, like, this is what's happening. The same to the point of, um, I don't. I'm not saying it's a good idea to spin up your own sock. I'm just saying, like, look, if, if the means are there, why are people not. Not everybody, but some people are going to make that choice?

Speaker D: It gives optionality, right? Yeah, it's hard to have that optionality. And, and to be honest, like, not all MSSPs MDRs are like, created equal, right? So a lot of folks that I talk to are like, I feel like my MSSP is just like a a turnaround type of thing.

Speaker B: Right.

Speaker D: It sends them a ticket and then they say, I think this is bad, but you got to figure out the rest of it. So then it comes back to them and they got to figure it out.

Speaker E: Right.

Speaker D: And so it's like it just depends.

Speaker E: And we.

Speaker B: That is a. That is a different but also very relevant conversation. All right, we're going to end it there. Seth, it's been awesome. Where do people find out more about what you do?

Speaker D: Thanks. Yeah, you can visit us@, uh, embedsecurity.com and not AI. Not. We didn't. We own AI, but we didn't. We didn't do that one.

Speaker B: Thank you.

Speaker C: He's bought into AI, but he hasn't bought into AI.

Speaker B: That's right. That's right.

Speaker C: Listen, where for. I'll get the domain name but our main things.

Speaker D: Dot com.

Speaker C: Thank you.

Speaker B: Thanks for being on the show, Seth. It's been great. I'm hoping people go check out what you guys do because it sounds interesting and again, technology is one thing, but actually being able to. To match what's between our ears, at least for most of us, is probably going to be the challenge of, of, of, uh, the lifetime of several, several generations. So anyway, Jim, James, thanks for being back, guys. Folks, thank you so much for listening for to another down the Security Rabbit Hole podcast. I hope you've enjoyed it. Until next time, we'll see you another time, another place, on another down the Security Rabbit Hole podcast.

Speaker E: Ciao.

Speaker A: This is Bella. Thanks for listening. Don't forget to leave my dad a review and share this with your friends. Bye. La.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • XDR, EDR, SIEM, SOAR…Snooze: Cybersecurity Marketing Real Talk with Gianna WhitverHuman-Centered Security · on SOAR (Security Orchestration Automation and Response)71 / 100
  • #127 - Douglas Brush (Part 5): Analysis ParalysisCyber Security Interviews · on SOAR (Security Orchestration Automation and Response)64 / 100
  • Evo Cyber Security #62 - Is AI A Threat To Cyber JobsThe Evolution Exchange Cyber Security Podcast · on SOAR (Security Orchestration Automation and Response)53 / 100

More from Down the Security Rabbithole Podcast

All episodes →
  • DtSR Episode 711 - Tim Chase Boring but Necessary
  • DtSR Episode 710 - Leading and Innovating in Security
  • DtSR Episode 709 - Zero Trusting OT
  • DtSR Episode 708 - Does AI Give Threat Actors an Advantage
  • DtSR Episode 707 - Impact of AI on the Intelligence Game
Explore the best B2B Engineering & DevTools podcasts →
All Down the Security Rabbithole Podcast episodes →