
Threat Vector by Palo Alto Networks · 2026-07-30 · 41 min
Key moments - from our scoring
Substance score
60 / 100
Five dimensions, 20 points each
Whitmore draws on her background as a special agent in the Air Force's cyber crime unit to explain why curiosity and continuous learning are essential traits for cybersecurity practitioners. She describes how her experience building teams at CrowdStrike Mandiant, IBM X-Force, and Unit 42 taught her to align talented people with organizational missions, using the metaphor of finding your 'catcher' - identifying people with the right skills for roles they may not initially envision for themselves. The conversation then pivots to her new role as Chief Security Intelligence Officer at Palo Alto Networks, where she synthesizes insights across the company's product portfolio and research teams to deliver actionable intelligence to customers. The episode culminates in a discussion of two major Chinese threat actors: Volt Typhoon, focused on military pre-positioning within U.S. critical infrastructure (water, power, electrical grids), and Salt Typhoon, engaged in telecommunications espionage. Whitmore emphasizes that CISOs and CIOs must now understand both technical security and geopolitical context - a demanding combination that requires practitioners who think differently and listen more than they speak.
Volt Typhoon is primarily focused on military pre-positioning within U.S. critical infrastructure (water, power, electrical grids) using existing administrative tools, while Salt Typhoon conducts telecommunications espionage and data theft targeting sensitive communications data between high-level individuals.
Curiosity drives continuous learning because cybersecurity practitioners work with intelligent adversaries using novel techniques, creating daily opportunities to solve new puzzles and understand attacker objectives in ways that prevent boredom and maintain engagement.
AI can assist by generating written and verbal scripts to explain security situations and craft status reports more quickly, but practitioners must actively learn from each iteration and modify outputs based on how they land with audiences, or risk losing the nuance that makes communication effective.
The best engagement managers combine technical depth across network traffic analysis, host-based analysis, cloud, and telemetry with the ability to translate findings for stressed C-level leadership, requiring strong listening skills focused on understanding rather than responding.
Volt Typhoon avoids detection by leveraging existing administrative tools already present in target environments rather than installing new or unfamiliar malware, making them harder to identify and evict because their activity blends into normal operations.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains some substantive points about AI-accelerated attacks (39 seconds to exfil, 72 minutes to breach) and the need for 'security for AI' as a counterbalance to 'AI for security.' However, much of the runtime is spent on leadership philosophy, team-building anecdotes (the softball catcher story), and soft advice about curiosity and mission alignment. The core cyber-threat insights are present but diluted by non-technical content.
we've seen a 400 time increase year over year in terms of being able to see data exfiltration in as little as 39 seconds
we see cases where in 72 minutes that we've seen from initial access into an environment to data theft
The framing of 'cybersecurity for AI' versus 'AI for cybersecurity' is useful, but much of the episode recycles conventional threat-briefing talking points: Volt Typhoon vs. Salt Typhoon threat classification, the need for speed in detection/response, and calls for better public-private coordination. The leadership and team-building segments are personal anecdotes but not novel to cybersecurity discourse. Few truly contrarian or first-principles arguments emerge.
Volt Typhoon typically related to military pre positioning
Salt Typhoon, typically more traditionally espionage related
Wendy Whitmore is a credible operator: former Air Force special agent, leadership roles at CrowdStrike Mandiant, IBM X-Force, and Palo Alto Networks Unit 42, now Chief Security Intelligence Officer. She has hands-on incident response and threat intelligence experience at scale. However, this is an internal Palo Alto Networks employee speaking largely within her own company's ecosystem, which limits the independence and breadth of perspective compared to external expert guests.
I'm David Moulton and this is Threat Vector. And I'm back with Wendy Whitmore, our chief security information Officer
You've led teams at CrowdStrike Mandian, uh, you and I met at xforce over at IBM, uh, and then led teams here at unit 42
The episode includes concrete numbers (39 seconds, 72 minutes, 400x year-over-year increase) and named threat actors (Volt Typhoon, Salt Typhoon, Iran, North Korea). However, the specifics remain largely at the briefing level - no granular technical details, named victims, timelines, or dollar figures. Most claims are framed as general trends rather than detailed case studies. The engagement manager role and AI-assisted communications are discussed conceptually rather than with concrete examples.
we've seen a 400 time increase year over year in terms of being able to see data exfiltration in as little as 39 seconds
Volt Typhoon typically related to military pre positioning
The host (David Moulton) asks reasonable follow-up questions and draws the guest out on team-building and threat distinctions. However, the interview lacks sharp pushback or productive disagreement. Questions are mostly open-ended and conversational rather than probing assumptions. The host doesn't challenge claims about AI acceleration or press on gaps in coordinated defense. The tone is cordial but soft, with little tension or rigorous interrogation of the guest's positions.
Yeah. Um, I wanted to talk to you about something that, uh, is maybe a different angle on AI than all the other conversations that are out there
And when you say in an environment, this is across the corporate network, it's an uh, OT networks, it's pervasive that way?
Computed from the transcript - who did the talking, and the words that came up most.
Enjoy this encore episode of Threat Vector by Palo Alto Networks. Can your organization survive a breach in 39 seconds? That's how fast attackers are moving now, and if your defenses are still running at human speed, you're already behind. Wendi Whitmore, Chief Security Intelligence Officer at Palo Alto Networks, returns to Threat Vector for a candid conversation with David Moulton about what it actually takes to build resilience in an era where AI is accelerating both the threat and the defense. Wendi brings more than two decades of experience leading incident response and threat intelligence at organizations including Mandiant, CrowdStrike, IBM X-Force, and Unit 42. She's an inaugural member of the DHS Cyber Safety Review Board and serves on cybersecurity advisory boards at Duke University and the University of San Diego.
Transcribed and scored by The B2B Podcast Index.
Speaker A: You're listening to the Cyberwire Network, powered by N2K. The biggest thing today is building networks and organizations for resilience. So not preventing every single attack, but being able to survive through the breach when they occur and keep your systems operational.
Speaker B: I'm David Moulton and this is Threat Vector. And I'm back with Wendy Whitmore, our chief security information Officer, uh, for another conversation. Uh, Wendy, welcome back to Threat Vector. Appreciate you making some time to come in today. I know you've been very busy, exciting
Speaker A: to be on again. It's been a while.
Speaker B: Yeah. Um, I wanted to talk to you about something that, uh, is maybe a different angle on AI than all the other conversations that are out there. Uh, but you'll have to tell me. AI and automation together, that's what I want to get into. Sound good?
Speaker A: Let's do it.
Speaker B: So I know you've been in the industry for quite a while, special, ah, agent in the Air Force, uh, doing cybercrime, cyber intelligence. And folks, I can't tell you some of the stories that Wendy has given me little bits on, but they do keep me up. Um, how did that foundational experience inform how you think about cybersecurity problems?
Speaker A: You know, I think anytime that you enter into solving a problem or a challenge with an investigative mindset, you're thinking about it like putting a puzzle piece together, uh, or using puzzle pieces to construct the entire puzzle. And I think that mindset and that curiosity is the foundation of what we are doing today. When we look at solving much larger breaches at scale, uh, when we look at putting together patterns across, uh, clients and data sets and really getting that big picture idea of what's going on so that we can then stop as many attacks as possible.
Speaker B: You said something interesting, and I've heard that quite a bit this week, is this idea of curiosity, um, and how important it is to this role. What makes the job one that requires curious people? What is it that allows a curious person to be successful in this role?
Speaker A: You know, that brings me back to when I was first, I was still in college and I had decided that I wanted to be a special agent in the Air Force. And the cool, sexy job to do at that point was to solve regular crimes, right? So drug offenses, murders, although thankfully there's not very many of those, uh, in the military. But that type of crime, that was seen as kind of the cool thing. But when I interviewed with the, at the time was the computer, uh, crime investigators office. And I was getting a computer science degree, so I was Already interested in that. And I talked to them and said, you know, hey, uh, these crime guys are really trying to, you know, bring me over there, but I'm very interested in the cyber side of it. What's your perspective? And I will never forget what the person who ended up being my first boss told me. And he said, you know, the thing that I like about our job is that every day I work with criminals who are smarter than me. I am solving problems that I need to figure out how these very intelligent people conducted this crime, what their objectives were, uh, what they're going to do after the crime in terms of stealing this data and what comes next. And he's like, you know, I would really much rather work with people that I feel like I can be learning something new every day versus maybe people that are making bad decisions more generally and committing other types of nefarious crimes. And so I think, to me, that kind of summarizes what is so exciting about the work that we do.
Speaker B: Right?
Speaker A: You get to constantly solve new problems. And so if you're a person that maybe gets bored easily, probably, I'm sure no shortage of us have ADD or ADHD or whatever, right. We're distracted. Um, it gives you that opportunity to constantly be learning new things. And that's super exciting to me.
Speaker B: And when you get into a case and maybe there's one that comes to mind, is there a moment where you find yourself getting into like a flow state where you're, you're digging in and, you know, time and going and grabbing food or doing some of these other things that you would, you would need that it sort of melts away and you're just like, you, you can't stop going.
Speaker A: Definitely. And I actually think if we then apply that to the usage of AI, I'm sure also there's no shortage of us who find that when we're testing new AI tools, when we're solving a problem with AI, that's a whole new area now where you can kind of get into and just be like, iterating back and forth with this, what sounds like, and feels like a close confidant to be able to solve this really challenging problem. And now obviously with a lot of the, you know, newer versions, uh, of the LLMs, they're continuously prompting that in terms of, hey, would you also like me to show you, you know, this new thing that you haven't thought of yet or this new angle to the problem. And so I think that that actually is going to be helpful for an mindset moving forward.
Speaker B: Yeah. So let's see, you've led teams at CrowdStrike Mandian, uh, you and I met at xforce over at IBM, uh, and then led teams here at unit 42. How do the organizations and their different cultures, different scale, uh, maybe the way that they operate affect uh, what you're doing and, or um, are there through lines that you see across those organizations, uh, because they tend to attract maybe that curious person, uh, or those folks that are always looking to learn the new.
Speaker A: That's a great question. I think each of those organizations is different culturally. And every organization you ever work at has pros and cons in terms of areas where you'd like to replicate more of or maybe areas where you're like, oh man, we're not doing this quite, uh, firing on all cylinders. And so you're constantly trying to then adapt, uh, a bit of the ways you solve problems to those unique organizational cultures. What I think when you ask about the through line though, to me, what's the fundamental challenge that needs to be figured out in every one of those organizations is how to align the right people with the mission. And so even if there's some cultural dynamics, that shift in there, what I'm always trying to do is figure out what problems do I need to solve here at the highest level in terms of organizationally. Uh, I'm going to align the mission challenge we have with what skills I need the leadership team to have. And from there then figure out how can I build the best team of people who is going to be equipped to solve this problem most effectively. And that means you have to understand what motivates people on the team. The more to me, the more that you can align a person or a leader with tasks that they love to solve with a mission challenge that we need to solve this as an organization, one, the better that individual leader is going to feel because they're going to feel like they are having major amounts of impact. They're going to feel good about the work they're doing. And a byproduct for the organization is they're probably going to work harder because they're really enjoying it. And so one of the greatest kind of joys I found is putting people together that maybe didn't necessarily think that they would get along or maybe even didn't want to work with the other people at the beginning and knowing that, hey, okay, I've seen enough now in terms of leadership that I think these skill sets are going to work out or these people are going to really complement one another. And that's what we need to build M as a team. And over time, having someone who's come on board where other people have said, I don't think I'd hire that person, and then you look three, four, six months later, and those people are incredibly close allies, and they're saying, hey, we're so glad that you brought this person on board. They are so fantastic. And we didn't really see that at first. So I, I think that that mindset of aligning what is motivating to individuals with the objectives we need to solve as an organization, that's, to me, always the top level. Figuring out what problems do I need to solve, how can I best do it, what skills is that going to take? And then no matter what that organizational culture is, we can figure out the path to achieve success.
Speaker B: Yeah, I've seen you do that, uh, here at unit 42, uh, watched you do it at IBM. Where did you learn that skill? Where does that come from in your background to be that not quite matchmaker? Um, but the person that can put, uh, a team together that doesn't have the bias of everyone matches, it's the diverse group, uh, of complementary skills.
Speaker A: Uh, well, thank you for that. I think you need people that think differently. That's so important in all of the work we do. And I probably learned that in the intelligence analysis training within the Air Force. So understanding that, hey, I got people with different skill sets. When I joined and entered the military, it was a heart of six months after nine, 11, um, we were straight into the war on terrorism. And it required people with all kinds of different skill sets and backgrounds, language skill sets, regional backgrounds, understanding of different ways to commit crime, to be able to solve all those cases. So I think that was incredibly helpful. But I also think, uh, I grew up. My parents were both teachers and my dad was a coach. And so I grew up on baseball fields, being around, you know, 20 older brothers at all times, type of an environment. And my dad was very good at identifying people's skills and then modifying what they were doing to fit the team's needs. So one example is I was a softball player, and I was a softball pitcher and in high school and then in college. But in high school, uh, we had moved to a new location. I had to go to a new high school, meet all these new people. It, you know, all the things that come along with that. Right. Pretty challenging. And we. So I was new to the team, but I was going in and my dad had kind of already reached out to the Coach of um, this new team at ah, the high school, said, hey, you know, we moved into town, this is what we're doing. And he came to practice. He was an old baseball coach. So we started by that time kind of being interested in what I was doing and came to one of the first practices we had and there was a girl on a team named Jenny. She was playing first base and, and he was looking and you know, he had told me already like after the first practice, like, hey, you know, we're not going to be good if you don't have a great catcher. Like, this team is going to go nowhere if you don't have someone who can catch. I'm going to need to find, you know, figure out who this catcher is. Saw the first baseman, saw that she was exceptionally fast, had the best arm on the team by far and could, was very coachable. And so approached her and said, hey, you know, Jenny, how do you feel about playing? Uh, you know, I see you're playing first base. She's like, oh yeah, I've always played first base. How do you feel about being a catcher? She's like, nope, I play first base.
Speaker B: Yeah.
Speaker A: And he's like, yeah, but you know, catcher gets to do all these things, right? They're kind of the boss behind the scenes. They're doing this or they're really the one that's telling the pitcher what to do at all times. Yeah, the pitchers like to think that they're in charge.
Speaker B: They're not.
Speaker A: And she's like, um, I don't know about that. And he's like, you know, you got a great arm. We could really use you in that position. And she's like, well, I don't know how to do that position. You know what, Jenny? I was a catcher. I played in college. I played in the minor leagues. I can teach you how to catch. It's really easy. You're just going to have to boss the pitcher around a little bit, knowing that was me. So he convinced someone who was very much set in their ways as we way outside of their comfort zone that, hey, you have the skills that we, the team needs for this role. And I think that was really pretty pivotal. Pivotal for me because I saw, oh man, you know, I'm the new girl in school. I'm not trying to ruffle any feathers. These people already have their established positions on and on. She was thankfully willing to give it a try. So Jenny. And by the end of, you know, two years later, as we were graduating, we were both the league mvp. We were on the all state team. She got a scholarship to college to be a catcher, went on to play, uh, all throughout college. And so I think that moment was pretty transformative for me of like, oh, okay. He was just going in and identifying what people did really well that was needed for the team and then molding them into something that was better than they even dreamed that they could do.
Speaker B: Yeah.
Speaker A: And to me that was really fundamental in when I went into the Air Force. It was just figuring out, okay, what are all the things that we need to do in terms of what are the tasks that we have as a team and the problems that we gotta solve and who's gonna be best positioned in each of these positions to do that.
Speaker B: Right.
Speaker A: And so it's really just putting people in the right position.
Speaker B: So you go and look for your catcher, um, they just don't know they're your catcher yet.
Speaker A: Right.
Speaker B: And you put them, you know, behind home plate and you're right, you've gotta have a monster of an arm to bank that throw, ah, to second. Right. Uh, throw somebody out. Um, what have you found in some of the best cybersecurity practitioners? That's that like common thing, but maybe it doesn't show up on a resume.
Speaker A: I'm going to give you a couple different answers because I think it actually depends on the task that they're doing. So let's say for example when you come to incident response, so solving a, ah, data breach, to me the hardest role on the team is that engagement manager who has to have the skill set of not only having the right level of technical depth so that they can challenge the team with the analysis that's being presented. And they need to understand enough about the network traffic analysis, enough about the host based analysis. Now they have to understand some about the cloud and the browser and all the data sets and telemetry that's feeding into the investigation, but they need to then be able to synthesize it in a way that they can talk to leadership at the cloud client and in particular that leadership client who is under fire, under the gun, trying to solve problems as quickly as possible with all kinds of influences and pressure coming at them. That's a really challenging role. You're having to do multiple translations and uh, gear switching essentially in your brain, uh, multiple times throughout a single conversation. And so I think the ability to understand that role as a translator is one of the more important tasks that we have. You can really only master that if you will after you've got proficiency in one or more of the other areas. So that's going to take someone a little bit of time. But it also then, I think requires the ability to observe people, listen more than you speak and really listen to understand versus listening to respond. And I think those are areas that are fairly hard to figure out on a resume.
Speaker B: Yeah, um, as you were talking about that, does AI help accelerate somebody into that kind of role to synthesize data, uh, to bring in a understanding of the emotional state, uh, the hot moment that you're in, uh, or do you think that we're not quite there where that AI is a good assistant for that kind of a role?
Speaker A: I think AI can be a great assistant at the communications piece. So again, AI is the outputs you're going to receive are only as good as the inputs that are crafted for it. Right. But presumably if you're configuring prompts or creating your own, uh, GPT, LLM, um, gem, whatever your, uh, choice is, I do think that you could train it to explain the situation and whether you're applying that to a singular case or a set of case data over time to, uh, explain the dynamics that are going on and then be able to feed in, let's say, a status report and then craft out some outputs that no doubt would actually create the written outputs, but certainly from a verbal script perspective that would help you communicate more quickly. Now, I think if all a person's doing is programming it in and getting an output and then repeating that output, they may not be learning the actual nuance. And that's what's going to make you better and more effective time and again, where you continue to learn. Learn. Okay, set it this way this time. But that wasn't really quite received like how I might have intended it. Right. So I'm going to modify that for the next time. So can a help? Yes, no doubt about it. But can. It needs to be done, I think, very pragmatically.
Speaker B: Hmm. You're making me think of my son. Uh, the last couple years he's really come into his own on his sense of humor. I used to think I was the funniest guy in the family. I'm pretty sure I'm not. But a couple years ago he would land a joke and he didn't land it right. It wasn't funny. You could see the structure of where he was going. But it missed. And he had to have a number of bombing, if you will, on stage just within the house, uh, of telling the joke until he finally got the timing and, uh, this tone and this person at this moment, but maybe that person at a different moment. Not funny, uh, but he's nailed it. And so I think there's a moment m where he could look up jokes and understand what they are. And then if he tries to, uh, say it doesn't work. Practice kills. And I think what you're talking about is like, you can't let the robot turn your brain to mush. Right? You got to be able to do some of the thinking. But maybe it is a great assistant to say, like, here's how you might frame it, or here's some of the other contexts that this group is going to be stressed out about or concerned about that didn't come in from the diagnostic or the investigation or the technical side, but is truly important. Um, even understanding who's in the room, who's not in the room with an audience is always. Ah, I think it's interesting to think about that because it influences things. Let's see, Wendy, about a year ago, you took over a new role, Chief Security Intelligence Officer for Palo Alto Networks. Um, what does that role and the shift that you have mean, uh, for you personally and, uh, the intelligence that you're used to getting access to for the organization? Just talk to me about that.
Speaker A: Yeah, so the role was really created for us as an organization to be able to take all of the insights we have across all of the products that we're building, the research teams that are embedded in Those, including unit 42, and to be able to really translate that into actionable insights for customers. So what does that mean? I'm, um, meeting with an endless amount of customers. Right. Nearly every day it's a different CIO or ciso and really helping, uh, for me to learn what kind of problems that they're trying to solve and then making sure that the solutions that we're building, one I can translate that into. Here's how we would recommend you do that, and here's the insights we can provide. But also learning are there areas where maybe there's gaps, where there's problems that these customers are trying to solve, where we may not have solutions for yet? So that's generally not the case. Obviously, our portfolio is pretty comprehensive at this point, but it's really been a great opportunity for me to just be in the field learning as much as possible about the challenges our customers are trying to solve.
Speaker B: Wendy, you're an official speaker at rsa, uh, this year, and you were on a panel called Inside the Hunt for China's Typhoons. That was a talk, uh, about Cutting through the hype of AI to get to the ground truth, uh, around AI and automation and how they're shaping security. Um, after running through hundreds of incidents, uh, what does the ground truth look like? And maybe what did you learn from the conversation or from the panel that you would add to that?
Speaker A: Well, the conversation was pretty dynamic. I have to say. We were all surprised. It was in first of the morning, so 8:30am Monday morning RSA talk. We thought maybe we'd have five adventurous people that joined us. And the room was packed with standing room only. And there, uh, it was spicy on stage and we got some great questions from the audience. So, you know, we started with setting the stage which was what's the difference between who are these Typhoon actors?
Speaker B: Right.
Speaker A: And in particular who's Salt Typhoon versus Volt Typhoon. And I think it's important in that conversation as well as this one to talk about just objectives and why that's still important when we look at attackers. Because certainly when you look at using AI, that remains important. Right. So you know, Volt Typhoon typically related to military pre positioning. So more of PRC attackers coming from China who are looking to embed themselves within critical infrastructure within the U.S. organizations throughout the country. And the concern is that's been going on for quite a long time. It's hard to find because they're not installing new malware that you've never heard of. They're simply leveraging the existing administrative tools that already exist in your environment and then using those for their benefit. So harder to evict and hunt in that sense.
Speaker B: And when you say in an environment, this is across the corporate network, it's an uh, OT networks, it's pervasive that way. Or is it really concentrated in some strategic areas?
Speaker A: Uh, well, critical infrastructure focus. So certainly water, power, electrical grid and um, but it's all over. So not just one specific geographical location or one specific part of a state. This is certainly pervasive throughout the U.S.
Speaker B: all right, and so you said that
Speaker A: was salt, that was volt.
Speaker B: Volt, yeah. Got me.
Speaker A: And in Salt Typhoon, typically more traditionally espionage related. So again, leveraging existing tools that are in environments so hard to detect, but for the purpose of data theft, of understanding what's going on and being able to steal in this case specific telecommunications data. So about communications going between high level or sensitive individuals, uh, existing ways to attack future telecommunications, and so obtaining intelligence about that. So two very different types of motivation here. But if we take that back to a CISO or a CIO who maybe has worked their Way up in the organization because they were a great engineer or they were a great analyst. They uh, network analysts for example. They're probably not going to be a geopolitical expert and also understand how to defend their organization against a foreign military capability. So we are really asking CISOs and CIOs to do a lot in today's day and age where cyber is so closely coupled with the geopolitical threat landscape. And that was really the next part of the discussion was going into then, okay, what are we seeing with Iran? How is that different? On it was, that was a different phase of conflict. So if you look at Volt Typhoon, that's much more strategic. It's still military pre positioning but we're talking about doing this years in advance. Salt Typhoon, still strategic but a different angle. Right. It's more data collection and understanding and some, you know, theft of data related to specific types of uh, data that you might be interested in on these conversations. Now if we look at what Iran is doing where it's much more tactical, so tactical disruption, tactical destruction, wiping, uh, and these are you know, Iran and Iran related groups out here seeing and investigating. And the reality is that a modern day CISO has to be able to protect against all of those and defend against them in addition to, oh by the way, all the cybercriminal groups that are out there that might want to steal data so that they can conduct a, you know, financially motivated attack against you.
Speaker B: Well, and maybe not part of the conversation, but we've also been seeing and reporting on activity out of North Korea and fake IT workers and theft there. Um, so if you're a ciso, you've got uh, every different flavor uh, of problem and you know, with massive funding behind it, different strategies and uh, capabilities. I do want to go back to you said it was uh, an animated conversation uh, on Monday morning. Um, I think that's a good thing that people are um, involved and have some questions. What do you think is so animating about this topic right now?
Speaker A: I think that those of us who've been in the industry for some time really want, are frustrated that these same types of attacks continue to go on and want the United States to have a coordinated defense, uh, and certainly not only United States, but across our allies, uh, and across the private sector. So we spoke a lot about how we could work together to effect change and what that looks like. Uh, I think there's many great examples of that work that's already ongoing. But no doubt it needs to continue to be operationalized much more Effectively where it becomes routine on a daily and weekly basis. And that's where a number of us are so very passionate about.
Speaker B: Ali Mellon came on talking about Code War, her new book. Uh, and in there she described the histories of the countries and she mentions the US Uh, she talks about China, Russia, Iran and some others and how our histories and our social uh, contract are what drive what we do and don't do and the cybersphere. Um, do you think that the US is social contract? That we have this idea of uh, as minimal government intervention as possible, maybe distributed systems, uh, that aren't always coordinated, uh, is one of those things that is at odds with being able to pull together that coordinated integrated response, uh, that's necessary to address some of these huge problems that are in front of us.
Speaker A: Well I think that no matter what way any country or large organization organizes their infrastructure, it's likely to be used against them by the adversary. So we start there and then apply that concept to what we're seeing today. So the fact that there are distributed systems, that much of these attacks actually occur on private networks within organizations that are far outside of the government. But then the government has the authorities to ah, affect change. Those being two separate entities certainly can work against us. But I don't think that means it's the wrong approach. It just means that we need to work together more effectively and learn how to overcome some of those barriers uh, that we may have constructed in order to achieve the outcomes at a speed that we need.
Speaker B: Well speaking uh, of speed that we need, how is AI affecting this problem either in a, uh, making it more urgent or helping things out, or maybe it's a little bit of both.
Speaker A: I think the biggest change by far is just the speed with which an attacker is able to operate. So we talk about in our report where we see cases where in 72 minutes that we've seen from initial access into an environment to data theft. We also talk about stats today where we've seen a 400 time increase year over year in terms of being able to see data exfiltration in as little as 39 seconds. That is a massive amount of speed that you can see. If you're applying a manual detection and response capability, you're going to be beat by the attacker every day. So that's the biggest change and that is I think the most pivotal reason why it's critical that we fight AI, uh, with AI and that organizations like ours who are really building world class capabilities continue to be innovative and cutting edge.
Speaker B: Yeah, I feel like going back to Your softball stories and baseball, it's kind of like playing T ball versus the bigs. That ball's coming in a whole lot faster now, and if you're not able to respond, you're going to get struck out pretty quickly. Um, the adversaries are using AI too, and not just nation states, uh, cyber criminals as well. Um, but the FBI has flagged the nation state actors in particular, and specifically China are testing AI across, uh, the full lifecycle. And you just mentioned exfil in 39 seconds. Um, an attack completed in 72 hours. I was speaking with Steve Ellevitz earlier this week and in my head it was 72 days. Uh, and he's like, no, 72 minutes. Move your time structure there. And it's just wild to me, um, that it's moving that fast. How do those changes, uh, affect defenders who are still trying to deploy tools and structure the stories to, um, the teams that help finance and fill the roles, who maybe don't understand the urgency that, uh, we're up against?
Speaker A: Well, I think that should be a big wake up call, right, in terms of the timeframes that we need. So if we're still applying more outdated models of approaches of how we're responding to attacks, then we're not gonna detect them in and we're not going to be able to respond and contain them in time. And the win is not going to be that we prevent every attack from ever occurring. It's going to be how quickly we can detect it, respond and contain it so that a compromise of an individual system doesn't become an entire enterprise wide compromise.
Speaker B: If next year you're sitting on a panel, uh, what does success look like? You mentioned the community piece. Working together. Is that the direction that you think things need to go? Are there other elements that you would add to that?
Speaker A: That's a great question. I think one of them, and I is specific to AI, and so I'm going to cover that and then I'll talk about the community piece. But specific to AI, one thing that to me looks more like success next year is if the innovation of AI doesn't so far outpace the security of AI.
Speaker B: Okay.
Speaker A: And I see that happening today because organizations, CISOs, CIOs are pushed by every angle of the business, every department, their leadership team, to drive efficiencies. And so they want to implement and innovate AI as quickly as possible, which is great, we're all for that. But what we're not for is keeping the same level of security, which then creates this Massive increased attack surface that now, a year from now we have an attack surface this big versus this big. So what, you know, what is needed for that? Uh, cybersecurity for AI is needed. So we all talk about AI for cybersecurity in terms of hey, we're creating these new capabilities and we're innovating with cybersecurity detections and we're able to take billions of attacks and get it down to one per day for manual. Like all of that's awesome. But that is AI for cybersecurity. We equally need cybersecurity for AI in terms of making sure that we keep those guardrails in place so that companies can safely innovate, can build and drive those efficiencies without exposing themselves to such a massive attack surface that's going to be unable to defend against and create inevitably, uh, more problems for them. The second piece, the community side, what does that look like? I think what that looks like in an ideal state is that we've really operationalized more of a disruption piece that we have as a community, a group of, of private partners who are really working together to share telemetry across the board with the government in a much more operationalized routine manner that enables uh, doesn't violate any legal challenges in terms of sharing data, certainly not sharing customer specific data, but also doesn't violate any government titling and authorities either. But really creates the opportunity for us to operationalize intelligence as quickly as possible so that we can make it more expensive for attackers to conduct attacks, make sure they don't reuse infrastructure, make sure that they cannot continue to use one attack and be successful against many organizations, that it's more than one to one
Speaker B: for a security leader who is in the unenviable position of uh, figuring out the difference between the typhoons and dealing with the conflict and the output from Iran or a nation state like North Korea or run of the mill cybercriminals at the same time that they're trying to figure out their AI and their automation strategy with that pressure from their business or from their industry to continue to move fast, to innovate. What's the most important thing for them to get right before they start deploying the tools that would allow them to be uh, exposed on a larger attack surface and or m massively exploited by some of these nation states, uh, that have more funding, uh, to find those weaknesses.
Speaker A: I think those challenges both require the same solution at the highest, most, simplest level, which is the right visibility into the environment. So the visibility for your team members, for your analysts to be able to detect, detect at scale very quickly with one screen. And then when you get into AI, what's being deployed across the environment, CIOs and CISOs need to equally have visibility into that environment. They need to understand visibility into shadow AI and what's being implemented in the organization that they haven't approved. Uh, same visibility into the actual prompts that are being input and ensuring that that prompt injection is not occurring, uh, within an AI system that they've got red teaming into the, uh, models and at runtime so that all of that kind of level of visibility is going to enable the innovation they need to implement moving forward.
Speaker B: Wendy, this has been really fascinating. I'm sure that a number of our listeners are curious to reach out to you. Where can people find you online and continue the conversation?
Speaker A: Uh, you can find me most often at LinkedIn. Okay, I believe it's LinkedIn.com Wendy Whitmort2
Speaker B: okay, we'll have it in the show notes. So LinkedIn is a good place to go and drop your questions for Wendy. Um, and you said you're out there talking to people a lot, so she may not get back to you instantly. Um, I really appreciate you making time for me today and for coming in and having this conversation, giving me a little bit of a snapshot of the conversation you had at rsa. We'll go ahead and link to that so people can experience, uh, the spice that you mentioned and, uh, understand what that's all about. Um, and again, uh, it's always good to have you on for our Beckett.
Speaker A: Fantastic. Thanks for your time today, David. Really enjoyed the conversation.
Speaker B: Foreign. That's it for today. If you like what you've heard, please subscribe, wherever you listen and leave us a review on Apple Podcasts or Spotify. Those reviews and your feedback really do help me understand what you want to hear about. You can reach out to me at threatvector Palo Alto networks dot com. Uh, I do read every email and, uh, it, uh, shifts the direction of the show at times. I want to thank Mike Heller, our executive producer. Original mix and music by Elliot Peltzman. Uh, we'll be back next week. Until then, stay secure, stay safe. Goodbye for now. Sam.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.