How Visa Secures Trillions Using AI Agents & Open-Source Harnesses

View Show Notes and Transcript

How does a global financial engine moving trillions annually manage cyber risk in the age of AI?In this episode, Ashish sits down with Subra Kumaraswamy, CISO of Visa. Subra discusses Visa's journey as part of Anthropic's Glasswing Project testing the Mythos model, revealing why  a majority  of Mythos-discovered vulnerabilities were non-exploitable due to robust zero-trust architecture and micro-segmentation.Subra explains why Visa open-sourced VVAH (Visa Vulnerability Agentic Harness) to help security teams scale vulnerability discovery, prioritization, and remediation across any model. He also breaks down how Visa triages 98% of Level 1 SOC incidents with AI agents, why "Mean Time to Adapt" (MTTA) is replacing legacy patch timelines, and how cross-functional AI governance enables innovation while maintaining strict production controls.

Questions asked:
‍00:00 Introduction: Securing $18 Trillion in Global Transactions
‍01:50 Subra Kumaraswamy’s 30-Year Career: Netscape, Sun, and Visa
‍04:30 Improving Visa’s Cyber Maturity Score from 3.2 to 4.9
‍07:30 Inside Project Glasswing and Testing Anthropic’s Mythos
‍09:30 Why Visa Open-Sourced VVAH (Visa Vulnerability Agentic Harness)
‍13:30 Mythos vs. Zero Trust: Why Only 0.03% of Vulns Were Exploitable
‍16:30 Defining MTTA: Mean Time to Adapt at Machine Speed
‍19:00 The Threat of Multi-Service Vulnerability Chaining
‍24:00 Prioritizing Exploits and Automating PRs with Developer Agents
‍28:30 Moving to Autonomous Defense in High-Stakes Environments
‍33:00 AI Governance: Balancing Vibe-Coding with Production Gates
‍36:00 Collapsing Silos: Unifying Endpoint, Identity, and AppSec Signals
‍39:00 Building Custom Control Planes with Agent Harnesses
‍45:30 Triaging 98% of Level 1 Incidents with AI Agents
‍48:30 Hiring for CQ (Curiosity Quotient) & Developer Mindsets
‍53:00 The "You Laugh, You Lose" Cybersecurity Joke Challenge

Subra Kumaraswamy: [00:00:00] We move seventeen, eighteen trillion dollars every year. Today, ninety-eight percent of our incidents are triaged by AI. So what used to be level one human analyst, that is now done by AI. It's open season, right? Yeah. Anybody who has access to the models can launch an attack against you.

Ashish Rajan: One zero day for ten thousand dollars.

Subra Kumaraswamy: You know, even though you're telling AI to do certain things, if it's not following instructions. Our analysis showed only point zero three percent of the vulnerabilities were exploited.

Subra Kumaraswamy: It's not if, it's when, right?

Ashish Rajan: Yeah. Building an agent harness for your security team may not be top of mind, but I had a great conversation with the CSO of Visa, Subra, and we spoke about what it is to build a security harness. They have open sourced a tool called VVAH for vulnerability assessment using agentic.

Ashish Rajan: What is top of mind from an AI security perspective? Such an interesting conversation. So much to share based on what they learned from the Mythos experience and what they're open sourcing to the world. If AI security is top of mind for you at scale, and especially if you are in a regulated space across a [00:01:00] large global footprint, this is the conversation for you.

Ashish Rajan: Definitely share this with anyone who is in a similar ecosystem or at least wants to understand why there was a agentic harness being open sourced by Visa and how you can apply that to your organization. This is the conversation. As always, if you are here for a second or third time and have been finding these episodes valuable, I would really appreciate if you take a quick second to hit the follow or subscribe button, whichever platform you listen or watch this on.

Ashish Rajan: We are on Apple, Spotify, LinkedIn, and YouTube, and I hope you enjoy this conversation. I'll, I'll see you soon. Peace. Hello, and welcome to another episode of the podcast. I've got Subra with me. Hey, man. Thanks for coming on the show.

Subra Kumaraswamy: Thank you, Ashish. Thanks for having me here. Great to be here.

Ashish Rajan: I appreciate that. And I think maybe to, uh, kick it off, if you can share a bit about yourself, your professional background as well.

Subra Kumaraswamy: Yeah. You know, been in the industry for almost thirty-plus years. You know, my foray into cyber was back when I was in Netscape.

Ashish Rajan: Mm-hmm.

Subra Kumaraswamy: Netscape Navigator. Yeah, that, you know, if you recall, kind of shows my age.

Subra Kumaraswamy: Yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: Uh, you know, that was my time where I was running the firewalls and learning the ropes from some of the gurus at the time.

Ashish Rajan: Yeah.

Subra Kumaraswamy: [00:02:00] And then, you know, from that point, I never looked back, right? You know, it was a amazing journey following the dot com days. I was part of a search engine company called Lycos, and then from there, you know, moved on to a company called Sun Microsystems- Yeah ...as you know, had the, had the slogan, "Network is the computer."

Subra Kumaraswamy: That's right. And I ran the, um, Sun SERT, the emergency response team, right? Uh, and that was my foray into the operations of 24 by seven and really living the, you know, the real first line of defense.

Ashish Rajan: Yeah, yeah.

Subra Kumaraswamy: Um, so, you know, it gave me a lot of, uh, things to think about as we think about, you know, as a CSO right now.

Subra Kumaraswamy: I rely on my front line defend- defense all the time, right? Then I spent some time, uh, from there, eBay, Intuit. I've been with, uh, Visa for the last 11 years.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Been, again, like, you know, a amazing journey. I came to Visa in 2015.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And, um, one of the things I'm really proud of Is where we are today from a cyber maturity.

Subra Kumaraswamy: Partner gives us a [00:03:00] score every year, and, uh, when I started Visa in 2015, it was 3.2 out of 5, 5 being the highest. Yeah, yeah. So fast-forward to 2026, we are, like, 4.9.

Ashish Rajan: Oh,

Subra Kumaraswamy: wow. Okay. Well done. The highest, highest in the, um, in the industry, so, you know, amazing to... You know, again, we'll talk a lot about some of the things, you know, do I still, you know, have that confidence with, uh, with that kind of score, right?

Subra Kumaraswamy: Yeah, yeah. We, we are very, um... Uh, yeah, so, uh, along, along the way, I did, um, I happened to write a book, co-author a book. What's it called? It's the... It's called, uh, Cloud Security and Privacy- Yeah ... and the Enterprise Perspective.

Ashish Rajan: Yeah.

Subra Kumaraswamy: It was really inspired by my days in S- Sun Microsystems- Yeah ... where Sun at the time was dreaming about a cloud, and, uh, o- obviously Amazon was building their own version of, uh, AWS at the time.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And, um, I realized that there's a need to educate the enterprises and the community around the cyber risks and, you know, as much as you wanna move fast with cloud-

Ashish Rajan: Yeah ... you

Subra Kumaraswamy: know, what else you gotta think about ensure that, you have a [00:04:00] very strong posture, right?

Ashish Rajan: Yeah. I mean, there's so much to unpack there as well, so, a- and appreciate all the experience you're bringing forward with this as well.

Ashish Rajan: Maybe a, a good place to start is that, is that the three-point-something score you got earlier, 'cause in the time that you've been in Visa, it's always obviously been the cloud transformation. You came from the Sun Microsystems world as well. You have gone through a cloud transformation. There's an AI transformation.

Ashish Rajan: You guys have a open source world as well. So maybe just to kind of give some people idea, what does it take to have a security program through a transformation, like a cloud or a, let's just say emerging tech as a word? Yeah, if you use that. Mm-hmm,

Subra Kumaraswamy: mm-hmm.

Ashish Rajan: What do you find in the experience you've had? What are some of the things that other CISOs and leaders who are watching this can learn from, that they can apply?

Ashish Rajan: 'Cause everyone has a security program at some level, maybe three-point-something score as well. They're kind of going, "Oh, Abin, how do you do this with a pa- a transformation?" You almost feel like, should I pause the transformation while I do this? But you clearly have done this with it, so I'm curious.

Subra Kumaraswamy: Yeah, and first of all, I was fortunate to be part of the transformation in, in different [00:05:00] companies, right?

Subra Kumaraswamy: As, uh, companies are going to the cloud, now, you know, with AI, you know, there's huge transformation happening, and especially Visa. You know, we got access to the models, GPT back when, at November

Ashish Rajan: 2022. Oh, wow.

Subra Kumaraswamy: Right? That's when GPT came out. Really early. Yeah. So we were, you know, uh, you know, my, my boss was leaning heavily on AI.

Ashish Rajan: Yeah.

Subra Kumaraswamy: I would say the number one thing is to ensure that you have a very strong sponsorship, right? To have cyber-first mindset.

Subra Kumaraswamy: You know, uh, I've been in Silicon Valley 30-plus years, and I have never seen the type of the Paranoia, pessimistic mindset to ensure always put cyber as a first, as compared to going faster with, uh, features.

Subra Kumaraswamy: And obviously you gotta, you know, you have to go make money for your own company. But the idea is that how do you bring that culture of the DNA- Mm-hmm ... you know, starting from the top? Uh, that's very critical to have the air cover for yourself.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And number two is, you know, not afraid to, uh, you know, fail, right?

Subra Kumaraswamy: Meaning like we have -- [00:06:00] I have done, uh, many different products that we built, uh, that we think we could do well. In some we didn't do well, but we some we succeeded really well, meaning like we were able to take a concept from a grassroot-

Ashish Rajan: Mm-hmm ...

Subra Kumaraswamy: all the way to production. You know, this is... Typically, most CSOs would look for a product to go buy and bolt on, right?

Subra Kumaraswamy: Yeah, yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: So we said, "Look, we need to be on a cutting edge."

Ashish Rajan: Yeah.

Subra Kumaraswamy: We need to understand, uh, the emerging threats, uh, because we see the threats much before most of the companies. And it has two benefits, right? Number one, of course, you can build a purpose-built tool-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: that is, you know, very specific to how you would, you know, your ecosystem is operating.

Subra Kumaraswamy: Number two is talent.

Ashish Rajan: Mm.

Subra Kumaraswamy: So because when you build, start engineering tools and you're developing, you know, cutting-edge tools in post-quantum crypto or in a behavioral biometrics, these are some of the technology we built, it attracts the top talent. And for me, the strategy in Visa starts with talent.

Subra Kumaraswamy: Talent is number one, so we attract the top talent throughout the world.

Ashish Rajan: [00:07:00] Yeah.

Subra Kumaraswamy: And, uh, having, uh, you know, this kind of technology that y- we can, the defenses we can build organically shows that we are, you know, here to continue to invent, continue to improve. And, you know, obviously there are technology we'll buy- Yeah

Subra Kumaraswamy: but that, that creates a lot more of excitement in the, in the group. And that's one of the reason why if you think about what happened in the last month-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: the VVA, Visa Vulnerability Agentic Harness. Yeah, yeah. Like, it was, uh, our first open source contribution in cyber and, you know, I didn't plan for a wild success, but it's been amazing to see so much adoption and feedback coming from the community.

Ashish Rajan: Yeah. I- I'm curious, what are some of the examples of, uh, adoption? And... 'Cause, uh, A, A, I think as a regulated body, coming with an open source tool itself is like a, a, in my books at least, an achievement. Having tried, having a lot of open source, even in a, a regulated environment, the amount of, uh, scrutiny and process and everything else we would have to go through.

Ashish Rajan: So kudos to you guys for getting that. Thank you. I'm curious as to what are some of the feedback you're getting? [00:08:00] What's the success look... And actually maybe even before that, what is Viva? Uh-

Subra Kumaraswamy: Yeah. So, you know, Visa, we are also a member of Glasswing-

Ashish Rajan: Mm-hmm ...

Subra Kumaraswamy: that Anthropic initiated back in April 10th. This is the company's got access to Mythos- Yeah

Subra Kumaraswamy: Mythos preview model. Yeah. Um, we were one of the 50 companies-

Ashish Rajan: Yeah,

Subra Kumaraswamy: wow ... in a so we were privileged to be part of that consortium early on. The, the whole idea of Mythos was that, you know, critical infrastructure company like Visa, you know, we, as you know, we move, you know, $17-18 trillion every year.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Um, and every day we do about billion plus transactions.

Ashish Rajan: Mm.

Subra Kumaraswamy: We are a critical infrastructure, not just for US, for the entire globe, right? That's right. Yeah. As you know. And so we got access as part of that, uh, to make sure that, you know, we get to discover vulnerabilities earlier- Yeah ... before a bad actor get access to the model.

Subra Kumaraswamy: And when we got the access to the model, you know, we were s- super excited and, you know, we had a, a core tiger team.

Ashish Rajan: Oh, right.

Subra Kumaraswamy: We put together and said, "Look, your job for the next, uh, you know, cancel [00:09:00] all your vacations." You know, all you're gonna do is you're gonna go figure out, you know, any vulnerabilities in our stack.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Uh, and, you know, build it so that we can scale much faster, right?

Ashish Rajan: Mm-hmm.

Subra Kumaraswamy: And so they c- they really, you know, again, it went through multiple iterations on a, on a daily basis, and within a week we landed in this concept of harness.

Ashish Rajan: Okay.

Subra Kumaraswamy: The harness is basically how we guide the model-

...

Subra Kumaraswamy: With the intent, with the context of Visa, all the things that makes it easier to guide the model and be able to effectively hunt for vulnerabilities in the code and config.

Subra Kumaraswamy: And so that harness evolved so nicely for us. Yeah. And along the way, right, and obviously we, the, all of this is inspired by our access to Mythos, but we also realized that we could use other models, right? So we developed this harness in a way that it is model agnostic-

Ashish Rajan: Okay ...

Subra Kumaraswamy: and multi-model. 'Cause this harness is a nine step, you know, from the point of discovery to f- reporting that vulnerabilities, and then we added two more steps.

Ashish Rajan: Yeah. Yeah. [00:10:00]

Subra Kumaraswamy: Remediation and validation. But, uh, to the f- the first nine steps, there are multiple models you can use, right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: And the reason we did that was we realized that 99.9% of our customers, our partners, and most companies on the planet don't have access to Mythos. So we said, "Look, how do they do it," right?

Subra Kumaraswamy: Yeah. So we, we wanna make sure we create something that can potentially help anybody who wants to discover vulnerabilities without access to Mythos, right? Yeah,

Ashish Rajan: yeah,

Subra Kumaraswamy: yeah. So that was the genesis of the Mythos, I mean, of this, uh, V- VAH. And, uh, now, you know, w- um, and again, we didn't plan to open source, right?

Subra Kumaraswamy: It was designed for Visa. Uh, then g- given the fact that a lot of our, um, my, um, partners, CSOs are asking, "Hey, how do... How can we learn from Visa?"

Ashish Rajan: Yeah. "

Subra Kumaraswamy: What are the insights that you got that we can get a head start?"

Ashish Rajan: Yeah.

Subra Kumaraswamy: And, uh, so we published a whitepaper on that. And along with that we said, "Look, we're gonna open source this."

Ashish Rajan: Wow.

Subra Kumaraswamy: So we completely made it agnostic to Visa. Yeah. So, you know, it's... A- anyone can download. And, [00:11:00] uh, and, uh, in the last many weeks, we got feedback, including from, uh, some of the top thinkers from NVIDIA-

...

Subra Kumaraswamy: You know, who said, "Hey, this is a really good way for defenders To get ahead.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Right?

Subra Kumaraswamy: It's really for us to get, uh, you know, ahead of the bad actors. So that's where we are, right? So, you know, it's... And we, by the way, we are, we are, we're just gonna make announcement where this VVAH has a new feat- bunch of new features.

Ashish Rajan: Oh, wow.

Subra Kumaraswamy: And it's coming up, uh, in the next, uh, couple of days. Yeah.

Ashish Rajan: Yeah.

Ashish Rajan: Wow.

Subra Kumaraswamy: Uh, and, uh, th- again, you know, our goal is to help community to adapt with new models- Yeah ... like, like OpenWeight. Yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: So the, you know, I'm so excited to see, we are continuing to enhance and, uh, provide that value back to the community.

Ashish Rajan: That's awesome. I think 'cause this is, I- I was gonna kind of addresses the question that I was gonna get you, 'cause a lot of times you would have, say, open source being released but not maintained over time because it's an open source project.

Ashish Rajan: Obviously, you guys have more things to look at at the, uh, the risk that you're working with. [00:12:00] You have... So can the community expect this, 'cause this would be a ongoing managed open source repository from you guys?

Subra Kumaraswamy: Absolutely. Yeah. I mean, you know, not only we are contributing, right? We are also seeing quite a bit of forks.

Subra Kumaraswamy: So comp- so a lot of companies are taking the code and forking it.

Ashish Rajan: Yeah.

Subra Kumaraswamy: I've also got -- I've been reached out by a few vendors-

...

Subra Kumaraswamy: In, uh, appsec space-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: uh, who are super excited to take w- this and add to their product line-

Ashish Rajan: Oh, wow ...

Subra Kumaraswamy: in a way that, you know, helps create more value, right? Yeah. Yeah. You know, one plus one equal to three.

Ashish Rajan: That's right. Yeah.

Subra Kumaraswamy: So we believe that, again, we've, we're not developing just for sake of open source, right? We're using it inside Visa. Yeah.

Ashish Rajan: Yeah. Yeah.

Subra Kumaraswamy: And you know, we are only in the first innings, right, of this nine innings if you think about a baseball. So we believe that there's a lot more gas, we're...

Subra Kumaraswamy: And we're also super happy to see many other companies have jumped in, and they're off- they're, you know, thinking along the same lines and offering a hardness.

Ashish Rajan: Yeah. Yeah.

Subra Kumaraswamy: Yeah. Uh, so it's good compari- healthy competition, right?

Ashish Rajan: Yeah. Yeah. If it... I mean, [00:13:00] so i- it's a good thing because you guys are looking at this as something that, A, is obviously, uh, attracts talent that realize, oh, you guys are already trying to be ahead of the curve, open sourcing it.

Ashish Rajan: In terms of, uh, say people who are listening or watching this and they're going, "Yeah, super, but I don't have a technical team," what kind of things that I should I have on my side as someone who wants to utilize this? Do I need a technical engineering team to get this, or can I be a small body that is potentially can take advantage of this?

Ashish Rajan: Like w- what do you see as a range of The size of security teams or the size of companies that can get to use and take advantage

Subra Kumaraswamy: Yeah. Uh, great question, Ashish. I think the two things I would advise companies who are looking to, you know, stay ahead and defend against AI threats specifically, number one is not to lose sight of the foundation.

Ashish Rajan: Mm.

Subra Kumaraswamy: Right? The basics. So one of the things I didn't share yet with you was, okay, we discovered all these vulnerabilities with Mythos, but when we did the analysis you know, we said, like, "How many of these vulnerabilities are truly exploitable?" Right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: [00:14:00] So, you know, if you think about a kill chain- Yeah

Subra Kumaraswamy: right, how many of these can e-eventually result in a boom, right?

Ashish Rajan: Yeah,

Subra Kumaraswamy: yeah. And, uh, we, you know, when we did the funnel- Yeah ... from Mythos discovering the first level, you know, we are applying our context to understand really is it a, is it a critical or is it a medium, right? Mm-hmm. Because every company may have different way to normalize it.

Ashish Rajan: That's right. Yeah.

Subra Kumaraswamy: And then we designed a red agent-

Ashish Rajan: Mm-hmm ...

Subra Kumaraswamy: that took all the vulnerabilities that came from Mythos and said, "Look, now can this be exploited effectively?" And our analysis showed only 0.03% of the vulnerabilities were exploitable. The reason being that, like I said, all the investments we have made over the last many years-

Ashish Rajan: Oh, right.

Ashish Rajan: Okay ...

Subra Kumaraswamy: on this zero trust architecture-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: layers of defense, right? Yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: So that effectively disrupted the kill chain.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And as, as an example, right, having a strong discipline on micro-segmentation- Mm ... segmentation, micro-segmentation, [00:15:00] multi-factor authentication-

Ashish Rajan: Mm-hmm ...

Subra Kumaraswamy: for if you're, especially for con-consumer facing applications, strong mutual authentication with TLS.

Ashish Rajan: And-

Subra Kumaraswamy: Mm-hmm. So every one of these controls that sits outside the code-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: effectively disrupted the kill chain. You know, if I didn't have the, the, that strong architecture and the strong discipline-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: we would probably be at 12% of exploitable.

Ashish Rajan: Right.

Subra Kumaraswamy: So again, uh, every company will have a different mileage-

Ashish Rajan: Yeah

Subra Kumaraswamy: based on where they are in the journey. So for small to midsize companies, VVH, you'll get result within few hours.

'

Subra Kumaraswamy: Cause, you know, you can... Pretty much you can download it. There's no dependency as long as you have access to some model.

Ashish Rajan: Yeah, yeah. Even

Subra Kumaraswamy: if it's

Ashish Rajan: an open source

Subra Kumaraswamy: one. Even if it's open weight model, right?

Subra Kumaraswamy: Yeah. Uh, you can, you leverage that. And then, you know, the key area that I would advise them to think about is how do you really prioritize it, right? You have to understand your most critical applications-

Ashish Rajan: Mm-hmm ...

Subra Kumaraswamy: whether it is customer facing- Yeah ... commercial application, handling more sensitive data. You know, [00:16:00] where, you know, your crown jewels are.

Ashish Rajan: Yeah,

Subra Kumaraswamy: yeah. Um, so you have to understand. And then from there you prioritize, you know, the exploitable The f- you know, all hands on deck kind of sit- situation, right? Uh, the-- And then followed by what I call is hygiene.

Ashish Rajan: Yeah.

Subra Kumaraswamy: So, you know, you-- if you have a root canal to be done, do that first -

Ashish Rajan: Yeah,

Subra Kumaraswamy: yeah, yeah

Subra Kumaraswamy: right, uh, uh, before you're brushing your teeth, right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: Uh, so same, uh, you're gonna see this, uh, funnel happening, and I think, you know, it's great to take the VVH, try it out, and obviously I'll be happy to get feedback. Yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: The more, uh, critical part is how fast you remediate, right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: And this is where, you know, we thought about a new way to measure your efficacy.

Ashish Rajan: Okay.

Subra Kumaraswamy: And, uh, we came up with this, um, metric called M-MTTA.

Ashish Rajan: Okay.

Subra Kumaraswamy: Mean time to adapt.

Ashish Rajan: Oh, okay. Right.

Subra Kumaraswamy: Okay. Okay? It's basically from the time you discover a vulnerability to the time you roll out a patch- Mm-hmm ... and validate.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Right? That patch in, in, in fact, closes the attack loop, [00:17:00] right? So VVH will tell you everything from, hey, here's-- within a few hours, you're gonna see vulnerabilities, then it's gonna help you to pick up those vulnerabilities and create a patch.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And you can also apply validation to ensure that that attack path is closed, right?

Ashish Rajan: Oh.

Subra Kumaraswamy: So that end-to-end, it, 'cause, uh, mean time to discovering is going down to zero.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Now we need to understand, hey, how fast is your patching? Are you able to-- Are you agile and you can roll out a patch with all the regression testing, ensuring it does not-- not only it's remediating the issue- Mm-hmm

Subra Kumaraswamy: it is also not disrupting the application, right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: So, you know, um, it may have, uh, side effects, uh, that may have impact. And that's the key part, is to ensure that you know exactly what is your MTTA. Mm-hmm,

Subra Kumaraswamy: and then you can fine-tune and say, "Hey, I need to focus more on remediation because that's where I see more friction."

Ashish Rajan: Which is kind of a reality for a lot of people, 'cause I imagine, like, most organizations have that 48-hour period for SEV 3 or one week, one-- I mean, SEV 3, SEV 4 was working at. SEV, SEV 1 [00:18:00] is 24 hours, 48 hours, and SEV 2 tends to be a week, usually the response time. Why is there a need to, I guess, shorten that window, like the MTTA that you mentioned?

Ashish Rajan: Why do you think it's, uh, it's probably more required now than before AI? 'Cause obviously a lot of people are talking about, "Hey, cloud is coming quickly," feels like AI is coming quickly. I mean, I mean, I have-- AI is coming very quickly, but why the focus on MTTA?

Subra Kumaraswamy: Yeah. I mean, again, if you look at the mean time to exploit-

Subra Kumaraswamy: That is going down to literally bend of this air, le- less than one hour. So from the time exploit, uh, I mean, a vulnerability is discovered-

-

Subra Kumaraswamy: To the time it's gonna be exploited is gonna be in minutes, right? Oh, yeah, yeah. In, in, in, in a year. And if you compare that with eight years ago, that used to be a year and a half, right?

Subra Kumaraswamy: Yeah, yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: So if you come from a 18 months exploit to a minutes exploit, so literally you are, you are to operate at machine speed.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Right? You can no longer operate at human speed. So, so if you think [00:19:00] about, Ashish, if you think about how the bad actors were, uh, creating the TTP-

Ashish Rajan: Mm-hmm

Subra Kumaraswamy: Was really reverse engineering a lot of these patches, right?

Subra Kumaraswamy: That's

Ashish Rajan: right. Yeah, yeah.

Subra Kumaraswamy: So Microsoft comes with a patch, you know, they, they reverse engineer the binary. Yeah. And now with the access to model like Mythos, you can reverse engineer in no time. You can not only reverse engineer, you can apply all the other dependency map and everything and say, "Look, I can now effectively create a...

Subra Kumaraswamy: I can chain the vulnerabilities."

Ashish Rajan: Yeah.

Subra Kumaraswamy: So chaining of vulnerabilities is very unique to Mythos-like models, right?

Ashish Rajan: Oh, okay. So it can ch- mul- like the long-standing, sorry, the long-running agents and all that, they can do that. It can tack on multiple stages of vulnerabilities.

Subra Kumaraswamy: Exactly. And, you know, so I can take, if I, if I've taken a application, let's say, it has tens of microservices.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And, most of the attack surface management will focus on OS top 10, right? That's right. You know, you are going and looking at cross-site scripting- Yeah ... or SQL injection- SQL injection. Yeah ... type of attacks, right? The business logic testing-

Ashish Rajan: [00:20:00] Mm-hmm ...

Subra Kumaraswamy: uh, where, you know, most of the time the hackers go after, most often is discovered through, during pen testing.

Ashish Rajan: That's right. Yeah. Right? Or-

Subra Kumaraswamy: Once

Ashish Rajan: a year. Yeah. Once halfway

Subra Kumaraswamy: a year. Yeah. Yeah, yeah. Yeah. And if you fail that- ... hopefully bug bounty, you know, if you have a bug bounty program- That's right, yeah ... you know, they, they're gonna find this, and hopefully you can remedy it before a bad actor finds it, right? Yeah.

Subra Kumaraswamy: With Mythos, you can get that level of efficacy, a bug bounty level of efficacy, by just running the model against the code.

Ashish Rajan: And the- Even the business logic ones ...

Subra Kumaraswamy: e- even the business logic ones. So basically- Ah ... it's able to go down based on what the application's intent is. If your application is a transaction processing system, or say, a loan disbursement system, right?

Subra Kumaraswamy: Yeah, yeah. And you provide that intent-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: of the application, it provide the context of what the application does. It can effectively go down into the config and code and connect the dots end to end.

Ashish Rajan: That's scary.

Subra Kumaraswamy: Yeah.

Ashish Rajan: Well, yeah,

Subra Kumaraswamy: yeah. And those type of sophisticated discovery happened with human, right?

Subra Kumaraswamy: Yeah. Skilled, you know, somebody skilled in the craft like a Jedi, right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: Knows how to, [00:21:00] uh, how to, you know, some of them are zero-days sold in the black market.

Subra Kumaraswamy: Yeah. Now you get access to that type of efficacy, the fidelity-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: with a model, just with a model, right? Yeah, yeah. So, so going back to why should you do it now, right?

Subra Kumaraswamy: And again, this is coming from my friend, uh, in Anthropic. He was saying that in 18 months, most of the open weight models will be as good as Mythos.

Ashish Rajan: Yeah.

Subra Kumaraswamy: So-

Ashish Rajan: The six-month window. Yeah. Yeah, yeah. You're right.

Subra Kumaraswamy: Yeah. So you, you're gonna see a continuously an exponential increase in the reasoning-

Subra Kumaraswamy: In the, you know, open weight model. And, uh, you know, which means it's open season, right? Yeah, yeah. Any, anybody who has access to the models can launch an attack against you. So it's more important to under... You know, be able to patch and, as you get it. And again, you know, like, like you said, if I look at, uh, how I patch, I, you know, I, I go after SEV 1, maybe I have to s- you know I, I have only finite resources, right?

Subra Kumaraswamy: Yeah, yeah. And budget

Ashish Rajan: as well. I'm

Subra Kumaraswamy: gonna go... Yeah, exactly, right? Mm. But now I have to look at, hey, can I take two SEV 2-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: one SEV 3, and connect those three and [00:22:00] create a chain So now I have-- I can no longer hide behind CVSS scoring.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Right? I now have to think about collectively the vulnerabilities in the application.

Ashish Rajan: Yeah.

Subra Kumaraswamy: All the way, full stack, right? Code that you write, the open source that you depend on, the kernel as in Red Hat or Microsoft, all of them have vulnerabilities, right? Now, we have to throw all of them at a model, and it'll say, "Look, I can now go connect these three things effectively and get a, you know, foothold into your ecosystem."

Subra Kumaraswamy: So that's, uh, that's a power, right? Yeah, yeah. So we, we never had this type of capabilities.

Subra Kumaraswamy: Yeah. Even, previous to AI, we had deterministic tools. Yeah. Uh, you know, the-- you had the static code analysis, dynamic code analysis and all of that, and then you had pen testing the human in the loop. But now you can effectively connect the dots with a model.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And there's the element of, um, economics-

Ashish Rajan: Mm-hmm ...

Subra Kumaraswamy: because Mythos type of models are expensive.

Ashish Rajan: Yeah.

Subra Kumaraswamy: [00:23:00] And then the hardness allows you to run this discovery in a more economically friendly way.

Ashish Rajan: More

Subra Kumaraswamy: cost

Ashish Rajan: effective.

Subra Kumaraswamy: More, yeah, for token spends and- Yeah ... right. So that's also... And because people now cannot just go and run this tool, you know, infinitely, right?

Ashish Rajan: Yeah,

Subra Kumaraswamy: yeah. You're gonna, you're gonna get a, a bill like, uh, you know, your kids- ... going and, uh, using cell phones. At the end, at the end of the month, you get a- Yeah ... sticker shock of all the, the bill that you get.

Ashish Rajan: Yeah, all the international calls they made as well. They're like, "Oh." Yeah. 'Cause I think you hit, uh, something interesting, right?

Ashish Rajan: Because I think, I don't know where I was reading this, but Mythos discovery of that twenty-seven-year-old vulnerability, I think the cost of that was about ten thousand dollars to find that vulnerability. And it was like, which organization in their right mind would think, "I'm gonna spend ten thousand dollars to find zero days across-" "well, not even one..." Sorry, not even a, a set of zero days. One zero day for ten thousand dollars. Now, obviously, a large organization where the risk conversation may be much different, but majority organization, that is too much money for any kind of zero day, no matter how you advertise it. But I, [00:24:00] I'm glad you guys have built this model to be able to switch around between an open weight model versus a, a cheaper model, or maybe have an enterprise version to a model as well.

Ashish Rajan: To kind of bring it back to the remediation piece, and yes, it's important, how far can I go with the VVAH today? So you said you can do recon. And so you-- but you do, you do recon, you find all these, say, 20,000 vulnerable systems- Mm. -I'm gonna give an example. Um, so 20,000 vulnerabilities. Now you've kind of, okay, I need to add a layer on top for what is high or medium for me in this.

Ashish Rajan: Let's just say it reduces to 5,000. And I'm assuming, can VVH help with that?

Subra Kumaraswamy: Yeah. So VVH will give you a prioritization based on your context.

Ashish Rajan: Oh, so you can provide your own context?

Subra Kumaraswamy: Yeah. Like say- Right ... if it's an example, PCI.

Ashish Rajan: Yeah, yeah.

Subra Kumaraswamy: So if your application is in PCI scope-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: right, it is handling payment data and it handles PI information, right?

Subra Kumaraswamy: So it, you can actually create a level of prioritization- Mm-hmm ... coming out of VVH, and then, you know, you can adjust the scoring based on exploitability.

Ashish Rajan: Yeah.

Subra Kumaraswamy: [00:25:00] So we actually, the way we did was we took the output of, uh, uh, VVH, like you said, the vulnerabilities that came out of, uh- Mythos ... Mythos.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Then we said, what is P1, P2, P3, P4?

Ashish Rajan: Based on the context you have provided.

Subra Kumaraswamy: Exactly. Yeah. And in that, P1 means I can exploit without authentication.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Like, it's open c- open on the internet. Yeah. P2 is with authentication, can you exploit? Mm-hmm,

Subra Kumaraswamy: P3 is reachable, but not exploitable.

Ashish Rajan: Yeah.

Subra Kumaraswamy: P4 is best practice.

Ashish Rajan: Yeah. Yeah.

Subra Kumaraswamy: Right? So we said this is truly the, you know, attack surface we need to go mitigate as a first phase.

Ashish Rajan: Yeah.

Subra Kumaraswamy: We still have to worry about the hygiene, right? Mm. Yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: And that can be done with a little more, um, you know, longer cadence.

Ashish Rajan: Yeah.

Subra Kumaraswamy: But the idea is to have a good view of how, one, the application

Ashish Rajan: criticality- ...

Subra Kumaraswamy: uh, like a PCI application or something very sensitive c- commercial, uh, applications.

Subra Kumaraswamy: Then you marry that with the context to give you a priority.

Ashish Rajan: Oh, okay. And VVH helps with all of that.

Subra Kumaraswamy: Yep.

Ashish Rajan: And I guess, you've mentioned RED agent as [00:26:00] well?

Subra Kumaraswamy: Well, we didn't, uh, we didn't publish a RED agent yet. Oh,

Ashish Rajan: okay.

Subra Kumaraswamy: Okay. The-- What we did after the first version was we added remediation.

Ashish Rajan: Okay.

Subra Kumaraswamy: Right?

Subra Kumaraswamy: Basically, uh, so the way we worked in Visa, so we took all the vulnerabilities, we t-threw into Jira.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And, uh, obviously we have to rely on all the developers who wrote the code.

Ashish Rajan: Yeah, yeah.

Subra Kumaraswamy: And we also told them, "You know, it's, it's your job number one."

Ashish Rajan: Yeah. "

Subra Kumaraswamy: Cancel all your other-

Ashish Rajan: Vacations. ...

Subra Kumaraswamy: all the plans of releasing features."

Ashish Rajan: Yeah, yeah. "

Subra Kumaraswamy: All you're gonna do is fix, fix bugs."

Subra Kumaraswamy: Yeah. You know, number one priority, 24 by seven. So now they ha- you know, and developers are lazy, right? Yeah. I mean, they, they are s- they want to do something that's faster, too. So with their, with their, with their help, we developed an agent, developer agent, which picks the vulnerability from Jira, creates a patch automatically-

Ashish Rajan: Oh

Subra Kumaraswamy: the agent.

Subra Kumaraswamy: Yeah. Does a PR merge.

Ashish Rajan: Oh, wow. Okay.

Subra Kumaraswamy: And the human has to accept it. Obv- obviously, we have the- The reviewer would

Ashish Rajan: accept it.

Subra Kumaraswamy: Yeah. Yeah. The loop, but, you know, 90% of the work is done-

Ashish Rajan: Yeah,

Subra Kumaraswamy: yeah, yeah ... by, by the agent. [00:27:00] And then, you know, they're-- we, uh, they push the code to the production. Before that, we do a validation-

Subra Kumaraswamy: To ensure whatever patch that was issued by, you know, or by the developer really has closed the attack path.

Subra Kumaraswamy: So the remediation or development agent and the validation agent is really critical to reduce the meantime to adapt, right?

Ashish Rajan: Mm-hmm.

Subra Kumaraswamy: Now, again, many, you know, uh, enterprises have practices like regression testing.

Subra Kumaraswamy: All of that creates additional delays.

Ashish Rajan: Yeah,

Subra Kumaraswamy: yeah. So you have to know where you move fast and where you cannot move fast.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And then, but, you know, once you have that principle established, you can go 99% of the time in a fast track.

Ashish Rajan: Do you find that, uh, uh, I think I'm glad you mentioned this also because that almost makes it accessible for many organizations, even at a smaller scale.

Ashish Rajan: You don't have to have a, a talented red teamer, a talented security architect or, well, security tester, I guess. Majority of people know the business logic challenges [00:28:00] they have in most applications, and if you have an understanding of it, and you can provide that as a context, they can use VVH tomorrow and start building on top of that as well.

Ashish Rajan: So I love that as a concept as well. One thing that is top of mind for a lot of people is obviously we're at this AI for Black Hat conference week at the moment, and A lot of leaders at the moment have this challenge of they have been sold AI security with browser endpoint security, all these, like the, to your point about the hygiene part.

Ashish Rajan: Uh, in all the work that you guys have done with Mythos and how you approach AI security program, quote unquote, the transformation, let's just say, uh, I'm sure it came with cultural challenges. I'm sure it came with challenges for how do we get everyone on board. And I guess to what you said, you guys had cybersecurity as the first thing, but not many people may have that.

Ashish Rajan: Any tips for people who are leaders who probably want to go down this path, but clearly don't have... They're trying to sell the idea of, "Hey, cybersecurity first, and why Mythos is..." The minutes actually make a difference. Is there anything in the conversations you've had with other people that have come across that has been, that can [00:29:00] be used to have a conversation with a CT or CIO or executives to go, "Hey, guys, this is why it's important.

Ashish Rajan: This is no longer just a hypothetical of me just flagging that this is a high risk. This thing is real."

Subra Kumaraswamy: Yeah. I mean, you know, this case in point, right? If you just look at what, what happened in the last two weeks, we had a Hugging, a autonomous attack against Hugging Face.

Ashish Rajan: Yeah, yeah.

Subra Kumaraswamy: Uh, even though it wasn't intended, right?

Subra Kumaraswamy: Yeah, yeah. I mean, unintended consequence of, uh, you know, giving the model a challenge. Yeah, yeah. A CTF challenge. And same thing happened with Anthropic, right

Ashish Rajan: yeah.

Subra Kumaraswamy: It's not if, it's when, right? Yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: Uh, and it's also an existential threat for companies.

Subra Kumaraswamy: If, I mean, if you don't... Just imagine that if cybersecurity, you know, the hygiene, the posture, if that becomes the weakest link, you no longer have the trust of the customers, right? Yeah. Yeah, yeah. I mean, at Visa, we do business with four and a billion, you know, cardholders worldwide. Mm-hmm. And trust is a cornerstone, right?

Subra Kumaraswamy: They know that Visa has their back. And, you know, [00:30:00] we take that very seriously. Yes. It's a, it's a responsibility, right? So it's the same, you know, every business, uh, you know, now should be thinking about the threat of going out of business.

Subra Kumaraswamy: It's not just like, hey, I need to, you know, it's a technical debt anymore, right?

Subra Kumaraswamy: Yeah. 'Cause, you know, it used to be like, hey, if you don't, uh, I can, you know, punt the, you know, can down the road-

Ashish Rajan: Yeah, yeah ...

Subra Kumaraswamy: and I can fix this later on.

Ashish Rajan: Yeah, yeah.

Subra Kumaraswamy: But now it's, uh, it is, you know, if you don't do it, you know, you're gonna see the bad actors leveraging AI, and you have to have the mindset of fighting AI with AI.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And you have to start investing on machine speed defense versus waiting for, you know, some, you know, uh, you know, some magic bullet to happen, right? So my suggestion would be that it's, a business in the line of, um, sus- sustaining and, you know, be able to survive the new kind of attacks.

Subra Kumaraswamy: And so you have to be thinking about the basics foundation. You also need to think about how are you gonna automate the defenses, right? And so my, [00:31:00] uh, approach has been how do I get to more autonomous defense-

...

Subra Kumaraswamy: Where we can eventually the, the first line of defense is AI.

Ashish Rajan: Okay.

Subra Kumaraswamy: Right?

Subra Kumaraswamy: And we still have to ensure that there is human in the loop For various type of, um, escalations.

Ashish Rajan: Yeah.

Subra Kumaraswamy: But you just cannot afford to have someone sitting behind a keyboard and mo- and monitor and be able to say, "Okay, you know, go quarantine something." Yes. Right? Or, you know, "Go block an IP address." Yeah,

Ashish Rajan: yeah.

Ashish Rajan: I- I'm curious, how are you... Because you've come from, uh, the Sun Microsystem world, the cloud world, how do you kind of mind map the AI security ecosystem and what secure... And by, by, by that what I mean is there's obviously people looking at coding agents with the Claude Codes of the world and everything, then there is the code work, which is just your application that runs autonomously and, uh...

Ashish Rajan: Or, like, like, to again, to what you said, given a goal, just goes and does it. Then there is the SaaS providers, the third parties which are using your, uh, AI capability. Now, they all have AI capability as well. Then you [00:32:00] have the worlds where now in a lot of organizations, especially the forward-thinking one as well, where non-developers are being asked to write code as well.

Ashish Rajan: Mm. They just there's a cultural shift, there's a technology shift. How do you see the role of security change in this? And the teams that we used to have before AI, does that still apply in this kind of world? And if there's a change, how do you foresee that change to be, I guess?

Subra Kumaraswamy: So, so, so, you know, right now you have to enable the business, and again, like I said, it's, uh, it's not just a technological transformation-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: it's also business transformation for a lot of companies, right?

Subra Kumaraswamy: Yeah. So at this point, uh, enabling business means, one, understanding the risk. Obviously, you have to make sure- You create awareness- Yeah ... with the management, with the board, and be able to articulate, you know, what does that new, uh, way of, uh, enabling business look like. You have to understand where the developers are going.

Subra Kumaraswamy: You remember for a while, developers were using heavily open source?

Ashish Rajan: Yeah.

Subra Kumaraswamy: And obviously, there was a [00:33:00] whole open source hardening, products that came out and, um, ensuring that anything that is going into your supply chain is hardened.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Same thing is happening with AI supply chain, right?

Subra Kumaraswamy: So you have, your product managers are now developers.

Ashish Rajan: Mm-hmm.

Subra Kumaraswamy: Right? And everybody's going to be a developer and a- Yeah, eventually ... and a, and a builder.

Ashish Rajan: Yeah.

Subra Kumaraswamy: But how you would do that, you know, how you would effectively enable that is where the art comes into play, right? Mm-hmm. There is a science aspect of ensuring you have the right guardrails and, right, be able to e-ensure that, uh, the sensitive data is not used for training.

Subra Kumaraswamy: A lot of that has to be done- Yeah ... with the right level of governance.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And in Visa, what we have done is we have a ni- very, very strong AI governance-

...

Subra Kumaraswamy: Where I am partnering with the chief privacy officer, the chief data governance officer, the chief AI officer-

...

Subra Kumaraswamy: Chief legal officer. So we all join ha- join together and ha- you know, in our hands to say, "Look, we need to come together.

Subra Kumaraswamy: It's not just cyber, right? Because, you know, the same concerns are coming from legal."

Subra Kumaraswamy: [00:34:00] Yeah. So and how do you really look at the risk? You know, where do we can take risk, where we cannot-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: and be able to say, okay, this type of vibe coding-

...

Subra Kumaraswamy: Can be, uh, ring-fenced-

Ashish Rajan: Yeah, okay ...

Subra Kumaraswamy: in a way that it doesn't leak into the, the serious part of the business, right?

Ashish Rajan: Yeah. '

Subra Kumaraswamy: Cause, you know, we, we took an approach of thousand flowers- let the thousand flowers bloom.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And, you know, but at the same point, I, I'm not gonna give the vibe code, uh, you know, be able to move to production- ... right? At the- Yeah, yeah ... at the, at the speed of AI.

Ashish Rajan: Yeah.

Subra Kumaraswamy: We're gonna ensure that it follows a due process- Yeah

Subra Kumaraswamy: to, you know, we've, you know, again, the process of how we harden itself is changing significantly. We are shifting even more left-

Ashish Rajan: Mm-hmm ...

Subra Kumaraswamy: with AI, you know, doing the SAST. So having a, you know, a view of where the risks are- And then be able to say, you know, which part of the business, has that, uh, momentum and where do you want to put the guardrails.

Subra Kumaraswamy: So at Visa, we developed our own guardrail. So every, every [00:35:00] AI interactions from employees and e- every application has to go through a guardrail.

Ashish Rajan: Mm-hmm.

Subra Kumaraswamy: And we monitor every traffic going in and out of Visa.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Uh, so we can block, you know, we have ways to, you know, prompt block a prompt injection or data that is very sensitive- Yeah

Subra Kumaraswamy: that is going out of Visa, right? So having a, a strong architecture helps, you know, zero trust architecture, and then educating, of course, it really requires-- It takes a village to- Mm-hmm ... you know, keep a company secure. Yeah,

Ashish Rajan: yeah. '

Subra Kumaraswamy: Cause as, as a CISO and a cyber team, you only have finite resources.

Ashish Rajan: Yeah.

Subra Kumaraswamy: So helping, working with your partners, uh, very early and say, "Look, if you are gonna go, and build these vibe coding a- applications, this comes with these risks and, it... But if you want to get to a production quality-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: it has to go through the proper, you know, gates and automation that we put in place," right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: I- I just cannot take a vibe code- Yeah, yeah ... and throw that into production.

Ashish Rajan: Yeah, a hundred percent. I, I think also in terms of the way security teams [00:36:00] are designed in a way, like the way we traditionally we have had the appsec, the cloudsec The SOC teams, the GRC teams, the third party privacy, all that.

Ashish Rajan: Do you see that would change as well, as the more we get into AI, the more AI transforms?

Subra Kumaraswamy: Yeah, excellent question. In fact, that is one of the thinking I, you know, we, I'm going through. Typically, there are a lot of silos, right? Yeah. If you look at cyber programs, you know, everyone is looking at from their lens.

Subra Kumaraswamy: That's

Ashish Rajan: right, yeah.

Subra Kumaraswamy: Right, I'm hardening the code from AppSec or, you know... And if you look at the SOC, they're much more centered around infrastructure security rather than knowing the co- you know, the code level issues, right? Yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: So with the AI, one of the biggest advantage we have is this cross domain visibility.

Subra Kumaraswamy: Yeah. So, so think about a typical lateral movement.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Right? I- if you're gonna get, um, you know, uh, if you're gonna do a social engineering of a help desk employee and get access to the endpoint-

...

Subra Kumaraswamy: And then from there, you're able to laterally move by escalating privilege-

...

Subra Kumaraswamy: So identity comes into play.

Ashish Rajan: That's

Subra Kumaraswamy: right, yeah. So is, is [00:37:00] that user, does it require admin privilege or not, right? Yeah, yeah. So there is a level of, you know, endpoint security that needs to come into place. You need, you need to have identity, least privilege, all of that in place.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Then as you go out to the, to your network, do you have authentication in place?

Ashish Rajan: Mm-hmm.

Subra Kumaraswamy: Right? So that's typically a, a network security team, right? Yeah. So you, you, you know, you have endpoint security, you have your network security, then eventually to reach an application, you need to know the APIs and y- y- you know, does the API have security in place? Yeah. You know, are you enforcing, uh, mutual TLS?

Subra Kumaraswamy: Yeah. Are you enforcing OAuth? So if I give all of these signals to AI, it'll effectively look and say, "Oh, look, that looks like a anomaly here."

Ashish Rajan: Yeah.

Subra Kumaraswamy: It is not a normal transaction for someone to come from this laptop to this, uh, you know, bastion host to this application.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And now, you know, I can quickly detect.

Subra Kumaraswamy: I can, you know... So the, the cross domain signals-

Ashish Rajan: Mm-hmm ...

Subra Kumaraswamy: is gonna be very critical for... So you can take the [00:38:00] individual deterministic signals-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: coming from, say, a, a CrowdStrike or d- or a Defender, or from any other endpoint moi- any other network level monitoring- Yeah ... and you can provide that to a reasoning engine like, you know, the model.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And you'll be able to get, uh, you know, immediate, um, you know, actionable, you know, depending upon the efficacy of the models. And so th- this is where you're gonna see the domains collapsing, right? Mm. You can no longer have separate function living on their own charter.

Ashish Rajan: Yeah.

Subra Kumaraswamy: It has to come together much faster.

Ashish Rajan: Yeah. And I guess to what you said earlier about probably the, the opportunities now with harnesses being developed, you actually can do that. Uh, and I'm sure there'll be a shift in how the, the product ecosystem, the vendor ecosystem would evolve to as well. One, one thing that- It is, I've been harping about and, uh, I'm curious to hear your thoughts on this as well.

Ashish Rajan: No matter what the vendor solution comes back with, all of us who are working for organizations like yourself and others, we all need to have our own harnesses [00:39:00] irrespective. A- and obviously they can leverage the one that V- Visa has created, but use that to kind of build your own ecosystem of what your, what the context is, what the high-risk resources are, whether you would, uh, this is a red agent, blue agent, however you see it Uh, whoever is in that, not a vendor side, but on the practitioner side, they have to think about, think about a model where they would have an agent harness of some sort eventually.

Subra Kumaraswamy: Correct.

Ashish Rajan: Right now, relying on a vendor that, hey, my vendor would make my... Eh, I don't know if it's the right strategy. Like, I don't know h- if you agree with me on

Subra Kumaraswamy: this. Uh, to-totally. You hit the nail on the head, right? Because every vendor is looking at a point solution, right? Yeah, yeah. You know, you're deploying.

Subra Kumaraswamy: Harness is, you know, one, it allows you to guide the model with the right context, right? Yeah, yeah. And you, only you know what the context is. That's right. 'Cause then I, you know, you know, from a payment side, I can exactly tell you which applications are the most critical or where we have the most sensitive information, right?

Subra Kumaraswamy: Yeah. What it's handling. So ha- and having a harness will help you [00:40:00] to, one, plug and play different models- Yeah ... that comes along. Yeah. Because you may find open weight models that may be better at, uh, you know, different aspects of the reasoning in the, you know, attack surface management.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And then number two is, as you evolve, uh, expand your harness I'll give you one example.

Subra Kumaraswamy: When you run the discovery and looking for vulnerabilities in the code, you can also now fine-tune the harness and say, "Now find all the crypto- crypto algorithms that needs to be uplifted for PQC." Quantum. Yeah,

Ashish Rajan: yeah, yeah, yeah. Okay,

Subra Kumaraswamy: yeah. For, for post-quantum crypto.

Ashish Rajan: That's right,

Subra Kumaraswamy: yeah. Right? So I can... It's like killing two birds with one stone, right?

Subra Kumaraswamy: I can now leverage the same harness-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: to not only look for vulnerabilities, but look for hardening my cryptography.

Ashish Rajan: Yeah.

Subra Kumaraswamy: The third, I can now say, "Look, go look for resiliency flaws." Is my code logging the right data for my SOC?

Ashish Rajan: Yeah.

Subra Kumaraswamy: Right? Because ultimately you need to give signals to say there's something bad happening.

Subra Kumaraswamy: That's

Ashish Rajan: right.

Subra Kumaraswamy: And, you know, and again, most of the, uh, code may not have the right level [00:41:00] of logging-

Ashish Rajan: That's right. Yeah ...

Subra Kumaraswamy: the right attributes, right? Yeah, yeah. You know, and even exception handling, the error handling. So again, we can... The model can tell you quickly and say- Yeah ... "Hey, this code needs to be, uh, you know, there's opportunity to harden the code to improve the resiliency."

Subra Kumaraswamy: So I- basically you need more telemetry, more observability, right? So the harness can be tweaked to expand from d- just discovering vulnerability to managing your, you know, resiliency, managing other technical debt that you have. That's right.

Ashish Rajan: Yeah. Yeah. And I guess to your point, it almost becomes like a Swiss knife at this point in time.

Subra Kumaraswamy: Exactly. Yeah,

Ashish Rajan: yeah. That's

Subra Kumaraswamy: the right way to say that,

Ashish Rajan: right? Yeah, 'cause almost like... And I think what surprises me is that most people are not waking up to the idea. I'm, I'm so glad you guys are open sourcing your harness as well, and other people are trying to talk about it, because ultimately there's only...

Ashish Rajan: The vendor ecosystem can create things that is going to make money at scale. They can't create an individual context for that's one, let's just say an insurance company which has sensitive data and [00:42:00] requirements. Yeah, they can try and provide the information, but it's not in benefit. It's not gonna make them the next unicorn.

Ashish Rajan: So f- they have a very different objective, but you as an organization have an imperative decision to make where, how do I enable AI safely? And if to what you were saying earlier, if Mythos is going to be there everywhere, the, the window is shorter. By the time I, I wait for my harness to catch up, my, my vendor harness to catch up, I've already been like few hours in.

Subra Kumaraswamy: Exactly.

Ashish Rajan: Yeah. So like- Yeah ... this is not the way you want the- Yeah ... the thing to plan out for yourself. Yeah. So I'm, I'm so glad you agree on this. Sorry, you were saying? Yeah.

Subra Kumaraswamy: No, I just want to say that, expanding on your thought, right? Yeah. The way I would envision the future-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: is that a control plane, right?

Subra Kumaraswamy: Mm. So a control plane that is orchestrated through hardness.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And you're gonna have tools behind the control plane.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And that's gonna be, some of them are deterministic.

Subra Kumaraswamy: Yeah. Like an ex- example is anti-malware, right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: It's gonna look at signature and say, there is a IOC collision.

Subra Kumaraswamy: Very clear, deterministic, right?

Subra Kumaraswamy: And you're gonna have multiple of these tools in different [00:43:00] layers, right? You may have a deterministic tool for IAM-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: um, that looks at privileges, right? Very much like a rules-based.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Now, when you take all the signals And be able to say, look, I, across this, can you reason-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: what is the, you know, the flow-

Ashish Rajan: Yeah

Subra Kumaraswamy: you know, that, that goes from an, an, a typical compute path. So this hardness will allow you to f- take the right... I can change the deter- deter- deterministic tool tomorrow with something else, right?

Ashish Rajan: Yeah, that's right.

Subra Kumaraswamy: But I can actually add all of this with a reasoning engine.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And now I can say, "Look, I see there is a issue that needs to be mitigated."

Ashish Rajan: Yeah.

Subra Kumaraswamy: And now I can issue a- another command-

Ashish Rajan: Mm ...

Subra Kumaraswamy: and say, block that or isolate that machine.

Ashish Rajan: Yeah.

Ashish Rajan: Yeah.

Subra Kumaraswamy: This is the autonomous operation that we are envisioning. Yeah. You know, it's 'cause you ne- need to go from signal to orchestration to reasoning-

...

Subra Kumaraswamy: To enforcement, and enforcement is where you are, you know, either mitigating something or isolating something, right?

Subra Kumaraswamy: So an [00:44:00] example could be, hey, I see attack happening account takeover happening on a particular application.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And I, I want to immediately stop the bleeding, right? Yeah, yeah. I can say, look, this is... AI will say, this looks like

Ashish Rajan: ATO. Yeah.

Subra Kumaraswamy: Now I'm gonna, you know, push something and block these IP addresses or bad actors- Yeah

Subra Kumaraswamy: or identity that is compromised. Yeah,

Ashish Rajan: yeah.

Subra Kumaraswamy: And then you can, go figure out how to, you know, fix the code.

Ashish Rajan: Yeah. But stop the bleeding first.

Subra Kumaraswamy: Yeah. So like, you know, can I orchestrate a policy on the WAF-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: application firewall, and because a lot of times code change takes time, right?

Ashish Rajan: That's right.

Ashish Rajan: Yeah, yeah.

Subra Kumaraswamy: So this having a hardness with a control plane will allow you to quickly respond to threats-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: without waiting for a code or a config to be fixed.

Ashish Rajan: Yeah. And I, I guess to hundred per- we're, we're thinking so much alike on this 'cause I, I think the idea is not that we're replacing the EDRs of the world, the MDMs of the world.

Ashish Rajan: We're just u- we're still using them for, like, you don't wanna build an MDM-

Subra Kumaraswamy: Correct ...

Ashish Rajan: or you don't wanna build an EDR solution, but you wanna be able to take advantage of a deterministic thing that is doing the threat intel, has the [00:45:00] information, but have some logging as well. Another area which has been top of mind for me is the fact that, uh, we're talking about SIEM quite a bit- in terms of what's the value of a SIEM in a world where all of us are building, say, a control plane, which is a gen- quote-unquote, agentic, which talks from an API perspective. And would engineering be the first people to do this, or would security be the first? 'Cause I was having a great conversation with someone about the fact that they found that there was a lot of overlap in the SIEM usage as well as the log collection that the finance team does or someone else does.

Ashish Rajan: At some point, all of us are collecting logs of different shapes and forms, and if the AI has to go down that path, is, is there some thoughts on the how does the SOC ecosystem may evolve as well?

Subra Kumaraswamy: Yeah, yeah. So I think, you know, again, uh, going back to the autonomous operation-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: today, at Visa, 98% of our incidents are triaged by

Ashish Rajan: AI.

Ashish Rajan: Mm-hmm.

Subra Kumaraswamy: So what used to be a, a w- level one human- Yeah ... analyst That is now done by [00:46:00] AI.

Subra Kumaraswamy: And, and then AI is able to say, you know, and again, the, the confidence rate will depend on the models- Of

Ashish Rajan: course ...

Subra Kumaraswamy: right? And how, how deterministic it is, the outcome is. But we are very, very, uh, optimistic that it's, you know, it's getting better and better.

Subra Kumaraswamy: So now L1 is done by agents-

Ashish Rajan: Mm-hmm ...

Subra Kumaraswamy: and triaging and be able to, you know, say, "Hey, this looks like a true positive-"

Ashish Rajan: Yeah ... "

Subra Kumaraswamy: or a benign positive," right? And it can have, just to validate, A, let the human run it, and then provide the feedback loop back to AI- Mm ... so it learns, "Hey, this, next time I, you know, I understand this may not be a, a true positive.

Subra Kumaraswamy: Th- this could be a false positive," right? Yeah. So ha- having that system in place is very critical. Yeah. Having a AI-based triaging and be able to, you know... A- and then l- the L2 is where, you know, humans are. And my vision is to really move a lot of these folks into advanced threat m- threat hunting-

Ashish Rajan: Mm-hmm

Subra Kumaraswamy: where, you know, the L2 and L3 are writing agents.

Ashish Rajan: Oh, wow. Okay.

Subra Kumaraswamy: I mean, you know, for now, [00:47:00] SIEM was purely, you know, SIEM was doing correlation, and it was saying, "Look, there's a playbook. Go do this," right? Yeah, yeah. You, you have an alert that comes out, um, whether through a MDR or through a SIEM.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And it's only, it only has one signal, right? Yeah. You know, from Defender or CrowdStrike. But now it synthesizes information across multiple sy- uh, deterministic tools and multiple log, uh, sources, and now we can s- say, "Hey, this looks like an attack on a outcome," right? Yeah, yeah. Outcome being a account takeover Or, you know, uh, a business logic compromise.

Ashish Rajan: Yeah.

Subra Kumaraswamy: So that's where the, the, the SOC has to move away from the traditional SIEM.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And SIEM can be okay to have a, as a system of record.

Ashish Rajan: Yeah, yeah.

Subra Kumaraswamy: But really you want a, a reasoning engine that takes all this different, uh, s- you know, input, and provides guidance to the human eventually investigating.

Ashish Rajan: Yeah.

Subra Kumaraswamy: "Hey, look, here is the reason why I investigated, and here is why this looks like a real, [00:48:00] you know, initial access vector-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: or, you know, a potential exploit," right?

Ashish Rajan: Hmm. I love this. What do you think about the actual team members? 'Cause I imagine a lot of people, there's a whole job fear thing going on as well with this- Hmm

Ashish Rajan: ecosystem as well. Uh, but obviously you're, you're saying you're hiring more talent, which is even more amazing to hear. What do you see as, uh, leaders who are basically hiring or trying to grow their, I guess, their security teams in an AI world? What are you seeing or what are you looking for in the kind of talent people should looking to hire?

Ashish Rajan: And people who are already in a job, what should they be, quote-unquote, "upskilling" in? Mm-hmm. If that makes sense. 'Cause obviously not many people may be at the same level where you guys are, but now there's an open source BBH, there's access to information and skills that you guys have y- developed, which they can use to upskill as well.

Ashish Rajan: So I'm curious, now when you look at hiring, uh, in the teams that you do, what kind of skill set is, uh, is the mindset for the skill set changing? Is it-

Subra Kumaraswamy: Yeah. Certainly, right? I think the number one, you know, as you know, [00:49:00] people have been talking about IQ-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: EQ. And now we are looking at CQ Which is a curiosity quotient

Ashish Rajan: Oh, right, okay.

Ashish Rajan: Yeah, yeah, yeah.

Subra Kumaraswamy: Okay, so the critical thinking-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: I think as, uh, you know, we always say that, uh, think like a hacker, right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: And, you know, there was a- thinking about this joke of, you know, every CSO wants AI- ... to think like a hacker-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: but they just don't want it to act like one.

Ashish Rajan: Yeah. Yeah, that's a good one. Yeah, yeah.

Subra Kumaraswamy: Right. So, you know, so if you're thinking like a hacker- Yeah ... do you- are you curious about, uh, you know, how do you... It's like breaking the locks and, you know, uh, going deeper and, and understanding, you know, the mechanics, the root cause.

Ashish Rajan: Yeah.

Subra Kumaraswamy: The fi- we, we say we had to ask the five why- Mm-hmm

Subra Kumaraswamy: to go down to the root cause, right? Every time there's a problem. So I think the... Because AI is gonna give you a lot of information, right? Yeah. It's gonna, um, you know, some of them are facts, some of them are not.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And you have to have that critical thinking to challenge the status quo, challenge, you know, what has been done until, you know, [00:50:00] what has been established as a prac- as a normal practice.

Ashish Rajan: Yeah.

Subra Kumaraswamy: I'm also looking for developer mindset, right? We are only hiring these, uh, only, you know, even if e- you know, I'm not saying even, but for a non-developer role, right? Yeah. We have quite a bit of non-developer in the compliance, governance, in the, uh, third-party risk management- Mm-hmm ... auditing, right? All of these are, you don't have to have, but I still believe that you need to have a developer mindset.

Subra Kumaraswamy: Because as you know, developers like to automate everything, right? Yeah, yeah, yeah. And one part is your critical thinking. Second part is that are you, do you have a m- automation mindset? You don't have to be a hardcore developer.

Ashish Rajan: Yeah. I

Subra Kumaraswamy: mean, developer role will require development, but for non-developer roles in threat intelligence, all of these requires that domain expertise, right?

Ashish Rajan: That's right. Yeah.

Subra Kumaraswamy: So I, I look at that. The third area is the domain expertise.

Subra Kumaraswamy: So, you know, uh, obviously someone coming out of college-

Ashish Rajan: May not have that ...

Subra Kumaraswamy: may not have it. Yeah, yeah. But they may have the CQ, and they probably have a good developer background or automation mindset.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And we say, "Look, we're gonna train you- Yeah

Subra Kumaraswamy: "on the, on the domain."

Ashish Rajan: Okay.

Subra Kumaraswamy: Right? I can put you next to [00:51:00] IAM person who has 20 years of experience architecting, single sign-on, multi-factor, FIDO, what have you, right?

Ashish Rajan: Yeah, yeah.

Subra Kumaraswamy: Or work with a application firewall engineer-

Ashish Rajan: Yeah ...

Subra Kumaraswamy: who knows how the whole, uh, you know, attacks happen with the la- layer seven attacks and rate limiting attacks, all of...

Subra Kumaraswamy: You know, so that's the w- the wisdom, right? Yeah, yeah. That the, the architects have developed. So I think that's the where, you know, I'm going is like how companies imagining a two people company are gonna create billion dollar enterprise, right?

Ashish Rajan: Yeah.

Subra Kumaraswamy: Same thing here. You know, two to four people in a particular domain can create wonders with the help of AI.

Subra Kumaraswamy: So for anybody who's looking to be- to, you know, make a career out of cyber, first of all- The surface is expanding rapidly.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Apart from applications and all that, you're gonna have AI attack surface. So knowing, you know, just think about what happened last two weeks again, right? Yeah. There's so much focus on how [00:52:00] do you contain AI from going rogue.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Or, you know, there's a whole... We still haven't scratched the surface on learning about how do you contain AI within the guardrails. What are the-- How do you prevent unintended consequences, right? Yeah. I mean, you know, even though you're, you're telling AI to do a certain thing, it, you know, it's not following instructions.

Subra Kumaraswamy: So I think there is a whole bunch of new jobs will emerge-

...

Subra Kumaraswamy: Where you have to understand the models, uh, in adversarial aspects of the model, and, uh, be able to upskill yourself to, you know, see how you can protect Applications and users from these type of, uh, you know, decisions that could, that could eventually, uh, be a, a big blunder, right?

Ashish Rajan: Yeah. No. Awesome. Yeah. Thank you for sharing that. I mean, that's most of the questions I had. I don't know if you were told about the, the joke thing, or have you used a joke? So b- basically, what I'm doing is you laugh, you lose the challenge, and if you have a joke in mind I have mine. Essentially, the way we're doing this is that I ask a joke, you have five seconds to [00:53:00] react.

Ashish Rajan: If you laugh, you lose. If I laugh, I lose. But I have a couple of jokes. Do you have one, or we have more than one?

Subra Kumaraswamy: Oh, I have one. Yeah.

Ashish Rajan: All right. Okay, cool. All right. I'll start with my joke first, and, uh, hopefully this is funny enough. Do you know about the shiny hunters?

Subra Kumaraswamy: Uh, yeah. Of course.

Ashish Rajan: Yeah. So do you know why they can't sh- catch shiny hunters?

Subra Kumaraswamy: Mm. Is it because, uh, of reflection?

Ashish Rajan: Um, no, because they ran somewhere.

Subra Kumaraswamy: Ah.

Ashish Rajan: Ah,

Subra Kumaraswamy: you

Ashish Rajan: see what I did there. Okay. Late reaction, huh? Yeah. Late re- Okay, cool. All right. That was good. All right. What, what else? What's your joke?

Subra Kumaraswamy: I, I only gave you one joke, which is about, um, you know, why CISOs, um, uh, how they want to AI to think like a hacker.

Ashish Rajan: But don't hack like one.

Subra Kumaraswamy: Yeah. Yeah, yeah. The other one I wanted to, um, think about hiring an AI employee.

Ashish Rajan: Okay.

Subra Kumaraswamy: And you say, "Look, what can it do for you?"

Subra Kumaraswamy: And you say, "You know, it c- it can work 24/7."

Subra Kumaraswamy: It has, uh, you know, no vacations.

Ashish Rajan: Yeah.

Subra Kumaraswamy: And sometime it's gonna make up a fact [00:54:00] that with high confidence.

Ashish Rajan: Yeah.

Subra Kumaraswamy: Right? And why would that fit into a company? Because it's like a, a, you know, any other corporate culture. You know, AI employee, uh, I'm just saying-

Ashish Rajan: It would, it would fit perfectly well.

Subra Kumaraswamy: Perfectly

Ashish Rajan: well. Yeah. Yeah, yeah, yeah, yeah. I can see that. I can see that. Oh, I, I loved your other joke as well, by the way, the think like a hacker, but don't hack like one.

Ashish Rajan: I love that joke as well. I mean, you did great... i, I love both of them, but that's for that, that's what we have time for. So where can people learn more about VVH and maybe connect with you as well to talk more about the things that you guys are doing and maybe more open source tools? Sounds like there are more coming up, so-

Subra Kumaraswamy: Yeah, yeah.

Subra Kumaraswamy: Um- We, you know, happy to come back some point and, you know- Yeah.

Ashish Rajan: Well, I'd love

Subra Kumaraswamy: to- ... talk about more innovations and, you know, all the things we are cooking up in our labs.

Ashish Rajan: Yeah, for sure. And, uh, so is VVH just on GitHub?

Subra Kumaraswamy: Yeah, it's on GitHub. Yeah. Okay. I'll put- So if you go to visa.com- Yeah ... uh, sorry, github.g- github.com/visa-

Ashish Rajan: Yeah

Subra Kumaraswamy: you'll see VVH as the number one- Mm ... you know, on the, on the- Pinned. Okay, all right ... on the lead- Star. Okay ... on the leadership board.

Ashish Rajan: Yeah, I'll put that notes as well. Uh, thank you so much for coming on the show. Really

Subra Kumaraswamy: appreciate [00:55:00] it. Thank you for having me. Yeah, it was a great conversation.

Ashish Rajan: Thank you.

Subra Kumaraswamy: Thanks

Ashish Rajan: everyone for tuning in.

Ashish Rajan: Thank you for watching or listening to that episode of AI Security Podcast. This was brought to you by TechRiot.io. If you wanna hear or watch more episodes of AI Security, check that out on aisecuritypodcast.com. And in case you are interested in learning more about cloud security, you should check out our sister podcast called Cloud Security Podcast, which is available on cloudsecuritypodcast.tv.

Ashish Rajan: Thank you for tuning in, and I'll see you in the next episode. Peace.

‍

No items found.
More Videos