
Sophos CEO Joe Levy and Director of Government Pa…
Loading summary
A
Sophos CEO and head of Threat Intelligence joined us in the studio. Let's talk about it on this episode of Safe Mode. Welcome to Safe Mode. I'm Greg Otto, Editor in chief at cyberscoop. Every week we break down the most pressing security issues in technology, providing you the knowledge and the tools to stay ahead of the latest threats, while also taking you behind the scenes of the biggest stories in cybersecurity. An attack is coming.
B
It's about keeping us safe. He's just a disgruntled hacker.
C
She's a super hacker.
A
Stay alert, stay safe, stay saf. This is Safe Mode. Welcome to this week's episode of Safe Mode. I am your host, Greg Otto. Joining us for our interview segment is SoFo CEO Joe Levy and Director of Government Partnerships Alex Rose. Really interesting conversation about what they're seeing in the cybersecurity landscape. They were in D.C. talking with some government executives about the national cybersecurity strategy. And we talked to them about their conversations that they were having. But first, in another conversation, talking with Tim Starks, reporter for cyberscoop. And Tim, you know, our readership and our listenership know that we cover a lot of the bread and butter in cybersecurity vulnerabilities, cybersecurity policy, what's going on with all the threats. But we had a really interesting technologically focused case heard in front of the Supreme Court this week that you covered for us. So talk to me about the ramifications of Chatri versus the United States.
C
Yeah, so I, I was interested in this, you know, because I like covering surveillance. I like covering the parts of cybersecurity, like you said, kind of adjacent to cybersecurity. But I think, I think it was cybersecurity because it involves the, the integrity of the data on your phone, who's, who's, who's eavesdropping on it, who's obtaining it, and that's what Chatri was about. With the oral arguments in the Supreme Court this week. The case involves a bank robbery where a fellow was arrested in part with the aid of a so called geofence warrant, where the law enforcement authorities were able to gather the location data of a number of people within a geographical range over a set period of time to help find out who was there for the bank robbery. And so this is all kinds of ramifications, Fourth Amendment especially, of course, what is a general warrant. Right. That was the, if you think of what the founders, one of the things that they were upset about with the kings of England was these kinds of big open ended warrants where it wasn't necessarily about we're going after somebody. And so from the privacy side of things, people were concerned that these kinds of warrants allowed the surveillance of innocent people who had nothing to do with the situation with the bank robbery. And this was a test case to see how far maybe the Supreme Court would be willing to embrace or reject these geofence warrants or narrow them or do something to contemplate the fourth Amendment ramifications. There's, there's all sorts of other things. Like the third party doctrine became a big deal here. It was a, it's a really fascinating case. It was really fascinating to hear the way the, the justices broke down in terms of who questioned whom in what ways. Because you know, you, you maybe would have had a preconceived notion about what the liberal justices might have asked about versus what the conservative justices might have asked about. It wasn't that way.
A
Yeah, it was really interesting to read about what came out of the oral arguments because so much with these cases is binary. Like it's either okay, we're going to throw this out or no, this is now applicable law. And it did seem like a lot of the justices were really trying to find like a narrow ruling for the way that they, this is going to be processed in the future with, with these geofence warrants. Because it, the metaphor as I have read up on it, is that think about it in terms of like lockers basically, where are we going to allow police when they issue these warrants to search through all of these lockers that may be used by individual people, but they aren't owned themselves? And that's really, that the best equivalent for what I've heard is happening here in the technological space because that's the way our, our phones operate is that, you know, they have all this data and we store this data, but we store this data whether it's on, you know, machines owned by Microsoft or Google or Apple or, or what have you. So that there's a lot of moving parts here that I think it was really interesting to see how each of the justices thought through that process.
C
Yeah, the locker metaphor. They kept coming back to virtual locker. They kept saying, but they were. I think there's not been a lot of cases that the Supreme Court has taken up on technology issues like this. They've not taken up a lot of fourth amendment cases overall. But especially lately, I think you have to go back to 2018 to find the last major one. And I think that from the standpoint of the legal principles at stake. They were trying to find the physical equivalent to our cyber world and our technological world. And the locker one was a big one for them because they were thinking about instances of you have a storage facility and there's a bunch of storage lockers. The police believe that there's a Glock in one of them. Obviously I've been using the word Glock because they literally use the word Glock. And at what point do you allow surveillance of that entire facility to just because you think there might be one gun there? The other thing is that I agree with you that they seem to be trying to find a narrow reading of this. And, and that's my personal opinion. After we wrote our story, I was looking at some of the other coverage and don't do that, don't read other
A
people's read us first, but then you can, you can be well read in other places.
C
Fine. But a lot of the other publications were seeking to try to come up with like, what they thought the court was going to, to, to rule. Some people said it seems like they don't like GFS warrants, seems like they're out. Other people were saying it looks like they're inclined to keep geofence war. I don't. My personal opinion again is, is that it's hard to read those things. But Oren Kerr, the Stanford law professor who's really smart on Supreme Court issues, had had the take that he thought they were going to be inclined to keep them, narrow them geographically or narrow them for a shorter period of time. I mean, one of the things that came up in the, in that case was, you know, I think this was something like a 17.5 acre geo like area that they searched, if I remember correctly.
A
Oh, wow, okay. So that's pretty big compared to what is actually applicable to geofence technology potentially.
C
I think, you know, they were, I think they were thinking about people coming, going, right. But if you're thinking about who was in the bank, you know, this is one of the things that, that the government gave a little on. If you want to narrow it down to something like who's in the bank, maybe, maybe we can do that more easily. If, I mean, if I'm guessing it's, that's probably the way it goes. I think the question that becomes, does this have ramifications for other kinds of cases? Because we've talked about it before that, that Google isn't the case, that this
A
is probably right before, before it got to the Supreme Court, Google had changed the way that it stored location data in that it was not storing it in its servers, it was actually storing it on device. So therefore, when a warrant is issued, the warrant has to be issued, you know, toward the person's personal device. And Google says, whoa, whoa, whoa. Well, we don't have that information. Which we've seen that even outside this case. That's generally the way that a lot of these search and seizures when it comes to data, whether it's even something totally motive different as like section 702, where we're still talking about data being pulled from servers that are owned by the big technology companies for a totally different reason. But it really just goes back to what the companies are doing in terms of trying to push privacy out of their own. Yeah, we don't want anything to do with this. Go, go, go talk to. Go talk to the owners of the devices, which is really interesting. And gets back to that digital locker metaphor that we were talking about earlier.
C
Yeah. And I think one of the things that maybe privacy folks were hoping to get out of this court ruling, which I think we're, you know, a few months away from it, would be something like, let's get a sense of what. What is an account, what is a search of an account, and what is protected. What requires a warrant, what requires a very particularized. They love that phrase, but just specific, you know, one person, a warrant for this person versus this person. Because, you know, I think the court was very interested in how this related to things like email and other kinds of records that you have that might be stored in the cloud by these companies. And there's a chance that people will be disappointed because they may not get anything definitive as to the extent of these kinds of warrants. It might be something very narrow.
A
Interesting, Tim, fascinating story. Appreciate you listening in. And we will definitely have you back on for an update when we get a ruling to see what the future
C
looks like for this look for the summer, I think June, July.
A
Thank you. And now to our interview with SoFo CEO Joe Levy and Director of Government Partnerships, Alex Rose. Really interesting conversation. I was excited when I got an email that these two were going to be in town. I said, hey, jump on the podcast and let's talk about all the things that you guys are working on. Some really interesting insights into what they're hearing from the government. They were in town and talked to Sean Carecross about the national cybersecurity strategy and their role in it. Then also how they are really talking about the full totality of protecting their Customer base. Look, Sophos does a lot of enterprise work, too, but a good portion of of their customer base is small and medium businesses. And they are really under the gun right now when it comes to threats and the adversaries going after them. So we dove into that and how that fits into the national cybersecurity strategy and all the things that they are seeing when it comes to adversary behavior. Check it out. All right. In joining us for a special conversation on this week's Safe Mode, to my right is Alex Rose, the Director of Governor Partnerships for Sophos, and Joe Levy, the CEO of Sophos. Really appreciate you guys dropping by. I know you guys are doing like a US Tour, so to speak. So I really appreciate you both having a DC stop at our offices. So thank you for joining us.
D
Our pleasure. Glad we could.
A
So, talk to me about what your conversations have been like as you have been in D.C. who have you been meeting with and what have those conversations sounded like, especially with the federal government.
D
Yeah. So we started off with some meetings with cisa, and we've been part of the Secure by Design initiative since its inception. And I think we're one of the best supporters. CISA tells us that all the time, and we're proud of that fact. And we just continue to think about how could we, number one, continue to set a good example with our engagement in the program? How do we begin to uplevel this and actually get more traction from the initiative itself? One of my personal pet projects within the whole Secure by Design framework is its counterpart, Secure by Demand. And just thinking about how we can start activating market forces so that we can see not just the supply side coming from the good act or software vendors that are out there today, particularly represented by the cybersecurity community, of course, but also how do we get more procurement offices and more buyers actually taking this a little more seriously and beginning to demand this kind of investment from the software space itself. Because if you think about when Jen Easterly was running cisa, she made what I think is one of the most important points, which is that the cybersecurity industry itself thrives because of software defects. And if we didn't have quite as many software defects, we wouldn't have quite as much of a need for cybersecurity as we do today. So just thinking about how we can better activate market forces to actually advance the state of security and software in general.
A
So you used an interesting word there. You went from secure by design to secure by demand. And it fits into something I was wondering is, has the urgency changed at all from the federal government when you speak to them in terms of their cybersecurity priorities over the past 18 months? Because it just feels like we're at a really interesting inflection point right now with all of the talk about what AI is doing. And we are at war right now with an adversary that we know is one of our biggest adversaries in the cybersecurity space. So I'm wondering whether the conversations that you've had, whether you've seen a ramp up in urgency when it comes to what needs to be done and the strategies that need to be enacted.
D
Oh, goodness, yes. And we didn't even need for AI to really amplify the sense of urgency that we have around this. We had already started seeing an escalation from threat groups that are out there, and it was just, I think, underscored by the rate at which we're going to start seeing the discovery of vulnerabilities, the development of exploits. I think Mythos is symbolically very, very important, but it's really nothing new. This is something that we have been dealing with for a very, very long time. Defenders have been on the back foot. We've felt that the adversary has had the advantage. A lot of this just comes down to general immaturity that exists within, unfortunately, vast majority of networks out there that don't have enormous budgets to be able to deal with the problem. And now, most recently, we've had these just startling announcements from some of the frontier labs about the capabilities that these emergent models have without requiring these elaborate harnesses. That is really going to lower the barrier of entry for many of the attackers who are going to begin to leverage AI to really accelerate the rate at which they're going to be able to take advantages of software defects. So, yeah, it's serious.
B
Yeah, I think absolutely. We, you know, whether it's administration to administration, quarter to quarter, year over year, the exact focus areas and priorities might shift. But from our perspective, cybersecurity partnerships, all of that continues to be a priority and a strategic priority at that. And so obviously, we have things coming out with Mythos and others that are driving some of the conversations today. But the partnerships that have been built over the years continue and endure. You'll have new players that come in and out, but I think the foundational partnerships, we still rely on and engage with them, and that's why we're here.
A
So, being that you are director of government partnerships, I can think of you people better to answer this next question, what does a good public private partnership look like at this point in time and not just like window dressing? Cause I feel like we've been talking about public private partnerships for a decade now. So I'm wondering what really does it look like from like the actual mechanisms and from a practical standpoint, what does a good public private partnership look like?
B
So I think there's a few layers to that. One will be like if, if things were to go south tomorrow, whether it be in the industry or whatever, some major forcing event, it is a, at a minimum, I know where, where to call, who's going to jump in and help, that there are convening functions that will allow that to happen. That we in the private sector are going to partner with others in the private sector and we know that we're going to be joined by government partners. Those foundational partnerships are there. I do know something happens tomorrow. I know who to call. We know, we know the phone will get picked up. That's really important. That's one thing. The other one is we always focus on how do we get out of the conversation. Like we want to come and meet and we want to, you know, have a good relationship, but we want get to get beyond what does good look like and actually execute on what good is. And so that is, you know, we're sitting down with FBI, we're part of their leadership in cyber program, which brings together law enforcement and intelligence, but it also brings together industry and really talking about how do we partner from an operational perspective. We're bringing intelligence to the table. That's helping them execute on operations and then seeing the real world impact that comes out the other end and doing that over and over and over and doing that with other partners. And then the last piece, I would say it is about showing up at the table in an honest fashion. And that goes for us, it goes for our government partners. It is us saying when we don't have insight on something and them understanding that, that doesn't mean we're not a valuable partner. That doesn't mean you don't call us again in the future. It just means we don't have insight on that particular thing. And I think that's been a foundational piece that we've built over the years. You build up relationships and trust. Right. But that just because one government partner isn't strong in a specific area at any given time or we don't have the insight that they might need, doesn't mean we're not there day in and day out. And so again, to reiterate, it's like, who are you going to call in the case of emergency? Do we have those foundational structures that we're all honest at the table and wanting to move out of just conversation into that operational impact? And that looks different.
A
It sounds like that really fits into what this administration, particularly the National Cyber Director, wants to do when it comes to the national cybersecurity strategy, especially with this, I would say I don't know how new it is. I want to say new, maybe new is not the right word for it, but the active disruption that is a part of the national cybersecurity strategy. Last month at rsa, we heard a lot about this from industry partners. And I'm wondering if you have heard that come back with the conversation that you have at the federal government where we do want you to help us go after these adversaries at a level that we haven't before. And it sounds like you do, but you do it selectively when you have something to contribute. Absolutely. Let's go do it together. And if not, call us again and we'll help you when we can.
B
Yeah, absolutely. I mean, this is a space that as Joe can talk to that from a Sophos perspective we've been leaning in on for several years now. I mean, we have some of the foundational cases that represent what this work looks like. And from my seat, I really think it's important that however we're going forward operationally, that, that we are doing that in collaboration, understanding the strategy we're trying to implement forward. It's not about companies going it alone. I don't think that that's where our big wins come from, but it is in that collective effort and bringing each of your piece to the table.
D
Yeah, we did meet with Sean, Karen Cross on this and we spoke at length about giving adversary behavior the first pillar. I think this is one of the most important things that we can get better at doing in the collaboration between the public and the private sector. And this, this is not necessarily hacking back, like people automatically jump to that conclusion that, that what, that's what that means. There are variations of that that are going to be a factor in this, of course. And as Alex was pointing out, we, we had a tangle with China over our disclosures that we made with the Pacific Rim campaign where we, we defended forward in that multi year engagement that we had with them. I think that's a good example of not just what is possible, but I would go so far as to say what the obligations of Software vendors ought to look like meaning that when your base is under attack, when your infrastructure is under attack, when the software that you're putting into your customers environments is under active exploit development by an attacker, the software vendor should have an obligation, number one, to participate in threat intel sharing with all of the agencies worldwide. And that's exactly what we did. But, but to, to take an active role in the defense of the customer. And that could mean something as simple as having auto update capabilities in your software that is on by default. Like make it easy for the software to do the right thing. Have, have safe and secure defaults out of the box and whatever it is that you're shipping into your customer's environment so that the customer doesn't have to take any active steps, they don't have to intervene in some way in order to protect themselves. The protection is native to the behavior of the software. I think that's a really good example of a standard that should be adopted a little more broadly because all too often it's inertia that becomes the greatest enemy to security. It's the failure to do something. So instead of making it incumbent upon the customer to have to do a thing in order for them to be secure, make that the default behavior of the design of the software itself. So that, that, that's an example of how the software vendor community could do a better job just by thinking more thoroughly about like what, what does it mean to be safe by default? Which is another safe, safe buyer secure by that we talk about there. There are other variations of this of course. Like is it possible to just raise the barrier for attackers to the point where maybe they begin to think about their life choices and they say to themselves maybe cybercrime is not the most lucrative thing for me to be doing with my skills. Maybe I can actually apply my skills in a more constructive way. Those are other examples of shaping adversary behavior. So there's a very broad spectrum of these things that we can do. And I think that it is going to take a partnership between public and private sector to achieve back.
A
What more is the government asking of you or maybe talking about in terms of things that you could give them to help out with in order to raise the bar for adversary behavior, Is it better telemetry, is it different, other non technical ways in order to raise that bar and, and deter that behavior? I like there's just so much that goes into this and I'm wondering how the government approaches, approaches industry to really attack it from all sides other than just the hey, could you guys patch better or develop better code, please?
D
Well, we can certainly develop better code, all of us, and it is quite exciting the capabilities that we have with AI now to be able to refactor code bases from older languages to memory safe languages. So there's. For all the pessimism that accompanies the capabilities of the new frontier models, there I think is an equal or perhaps even greater amount of optimism that we should be looking at. Like what does this mean for the defender? What does it mean, mean for the wholesale manufacturing a more secure code? So those are certainly dimensions of this, the sharing component of it. I think we do a really good job talking about this and I think everybody is like, okay, we get it. Threat intel sharing is important. The reason why we still need to see more activation from the software industry is because there is no one single vendor that is going to have a comprehensive view of everything that's going on. This, this is going to take like a whole of industry approach in order for us to surmount the, what is effectively a blind man and the elephant problem. Because we, we, we don't have any one vendor, it doesn't matter how big the vendor is, they don't have a completely comprehensive view. And, and many vendors, they have a bigger footprint in certain geographies or certain segments of the market. What one of the key capabilities of Sophos is the fact that while we have a large number of enterprise customers, we have a much larger number of small to medium enterprise customers. SME, SMB, over 500,000 SME customers out of our total base of about 600,000 worldwide customers. And that gives us visibility into segments of the market that vast swaths of the cybersecurity industry generally don't have access to. And because of that, we're unique in that respect, but we're not unique in the respect that we do have this sort of unique perspective that maybe the rest of the industry doesn't have. And this is why it's so important that all the vendors in the entire community are participating so that we can get that more complete view.
A
Right. I was going to ask you about that because I do know that Sophos does have a wide customer base, especially when it comes to company size or organization size. That when you do talk to the government, how does that corporation size, especially in the small and medium, factor into. Because so much of what we talk about and so much of policy is driven by large enterprises or is just driven by critical infrastructure, which is obviously, you know, there's a different set of risk when it goes into that too. But it's so interesting to hear if the totality of the economy or what's out there on the Internet does get factored into these conversations. When the government is asking what more needs to be done with cybersecurity.
B
And I think that that's part of our job is to raise that up when we see it missing. Because you're right, often we start the conversations around what are the large enterprises doing, what are the others in the tech or cyberspace doing. And even, especially in this AI conversation and you lose focus on the vast majority of the economy is driven by the small medium business. So one that we see as our job to make sure we, we continue to bring it up and make sure that it's at the forefront. So that way, whether you're putting out guidance and advice for organizations and what they can do that we're giving insanity check of, is this something that is actually practical, that something that they can implement? And I know we, we've talked a bit about Operation Winter Shield with FBI and one of the things we're the practical guidelines that you're giving people and bite sized things that they can often say, you know, I can't do all of this today, but I can go a little bit by a little bit each and every year. And so making sure that we continue to drive that focus. And then one other angle I'll give of this is as you look and think about the threat landscape and how threat actors are operating, they impact businesses of all sizes in all verticals and all geographies. And so this is not just your E crime ransomware operators, these are your state sponsored threat actors. I think that it's easy to forget that small and medium businesses might be small in size, but their impact in many ways can be really outsized for what they do. And they don't have the CISO giving them expert advice and guiding them. And so, you know, not only is it our role to figure out how we support those organizations but, but it's also to advocate in front of our government partners, with our government partners about what we're learning in that space, why it might look different and how to best enable them to protect themselves.
A
So after these conversations that you have in Washington, how do you work that back into the business? Like when you go back to Sophos headquarters on Monday, how do you fold that back into what you are delivering? Is it retooling to fit policy or is it something that gets baked into a product? Or how do you further those Partnerships that you can bear the fruits of those conversations you're having on the policy side. But everybody, whether it's public, private sector, is getting the benefits of what is coming out of those high level conversations.
D
So first of all, it's cultural. There needs to be an understanding pervasively through the company that these sorts of partnerships global are important to us. And we do participate in a global level with, with the US Government, with government in the UK where we're headquartered. But we do this globally. We work with the certs and you know, the equivalence of CISAs and the NCSEs and GHcqs across the entire planet that I think is important as something that has to be set as tone within the organization. Probably more importantly, it's continuing to think about this segment of the market that we rather uniquely serve. And I fundamentally believe that the vast majority of the market is underserved by the cybersecurity industry because the cybersecurity industry does go after, let's call it the Global 2000. And you've got in the United States, for example, the Small Business Administration shares the statistic that 99.9% of all businesses in the United States are technically small businesses. And those are generally not the businesses that the cybersecurity industry tends to serve, or at least not serve well. And you were talking about critical infrastructure. So 16 segments of critical infrastructure, vast majority of them are in the private sector and very large number of those are small businesses. If you look at the defense industrial base, estimated 300,000 organizations and vast majority of those are private sector small business. So it's interesting when we think of it in terms of the exposures that we're most concerned about, if you actually do the Venn diagram, the majority of exposure that we're concerned about is the SMB space. But yet that is the segment of the market that is historically neglected by the cybersecurity industry. So how do we fix that that's so fundamental to our mission? It's something that I think differentiates sophos in the cybersecurity space because we have, number one, the interest in serving that group, but number two, the demonstrated capability of being able to do that. At scale of our 600,000 global customers, 39,000 of those are MDR customers, managed detection and response, meaning that we're providing 24, 7, 365 security operations services to them. And we're doing that at a larger scale than anyone else in the industry is doing it. That was our first act. Our next act, I think is even More ambitious. And that is when you step back and you ask the question, why is it the cybersecurity industry is over 40 years old now, it grows at a double digit CAGR year over year. And despite the fact that we're spending hundreds of billions of dollars on the problem, the problem doesn't seem to be getting better. The problem seems to be getting worse. And now we've got this looming AI thing that's about to happen to us. And I think the answer to that question is because the vast majority of organizations in the world don't have a ciso. And we were curious, so we did some research and collaboration with Cybersecurity Ventures on this. There are approximately 359 million organizations in operation in the world today. There are approximately 35,000 CISOs. So it's, it's a gap.
A
It's a gap.
D
It's a 1 in 10,000 problem. That's exactly right. And then the question was, could we, could we leverage the demonstrated at scale capabilities that we have with our NDR service to be able to address cybersecurity leadership for all these organizations? And we believe the answer is absolutely yes. So a little later this year we're going to be launching something that we're calling CISO Advantage. And it's designed to do just that. Allow us to provide CISO leadership capabilities in a virtual fractionalized way, working with our global set of partners and leveraging the capabilities of agentic AI to provide that kind of North Star leadership to organizations so that they have a way of saying, we know how to be better tomorrow than we were yesterday. I think that's going to put it
A
down to things very, very interesting. So when it comes to CISOs and what they do have to care about, it's obviously the adversaries. And I'm wondering what you guys are seeing as far as adversary behavior. And really, let's look at it. The landscape over the next 612 months. What are we seeing and what's changing on the adversary side of things?
B
Yeah, so I think that one, the landscape, there's a lot of new threat actors that pop up day in and day out. Some of the core things that we focus on though are the ways that threat actors are getting right, because fundamentally that's what you can, then you can think about and protect yourself against. And so identity is a key way people are tapping into threat. That, that's not necessarily new, but the, the uptick in how we are seeing that play out in our incident response cases and beyond. You know, it's one of those things that goes along with nearly three quarters of all the breaches that we see and so continued there. The ransomware ecosystem as we know continues to thrive. And as we look at how these threat actors, whether they are state sponsored or the criminal money making types, how are they going to use AI in this space and continue, you know, they're like many organizations figuring out how it might help them and often it's for gaining efficiencies. Right now it is about how can they operate a little bit quicker at what they're doing. And that's a space that we keep eyes on. But even at that, even with the ways they're employing it today, it doesn't necessarily change how they're getting it. And so it's really fundamental. You go back to this, why we talk about patching, this is why we talk about mfa. You know, that's why we talk about having monitoring in place. Not just the detection, but the monitoring of what you're doing environment. And so in that criminal landscape, we, we see a shuffle of ransomware operators day in and day out, new groups emerging here or there, to be quite honest, behind the scenes, it's often the same players.
A
I was going to say they might not be so new, it's just a new name on top of it.
B
Right. And you know, they're, they're like many retailers, really well resourced industries. We talk about the ransomware ecosystem for a reason. It's because it is an ecosystem where it's built for resilience. Something happens one place, they want to shift to another, they fall out with one partner, they want to go to another. Right. And so making sure that, that folks understand that ransomware is still a threat and how to protect against that. And then of course, things like business email, compromise and all of that, that continues. And then on the state sponsored side, it is looking at whether it's China or North Korean IT workers or what we've seen or not seen with Iran. Right. It's continuing to look at that might be impacted. And again, I'll say that some of the techniques will evolve day to day. The IOCs or the infrastructure that they're using might evolve, but often from a practical standpoint point, the way they get in, you can get in with credentials, you want to get in with credentials.
A
Right.
B
If you know, and from there you, you escalate as needed by taking that path of least resistance to get in. And really just the increase in activity day in, day out, you know, I think we saw a bit of A dip in ransomware last year, and that's not the case of what we're seeing now. And so persistent threats persist.
A
So the identity part, I want to focus on that because I think we're at a really interesting inflection point, especially Joe, with what you were saying with the focus on secure by demand. One of the big selling points of AI, at least in the future, is that we see agents and developers using AI to root out all of the issues in code and actually get to a point where maybe we do get to secure by design. And I've been talking to some other experts about this and you know, they're looking three steps ahead and go, okay, let's say that we do get to a point where we won't get to a hundred percent secure by design, but maybe we get to like 98% where if there is a flaw, we can patch it really, really quick and the, the woes of, of patching go away. Identity then is going to become so much more of a focus from the adversary because you don't need a vulnerability to break in. And Alex, you were just saying that identity is already a big part of the IR incidents that you're seeing. So I'm wondering if you have been having conversations with your customers where it really is a focus on identity because of, Even though what I'm just saying might be hypothetical, it's, it's clear that AI is getting, going to get to a point where it pushes the threat so much more focused on identity, even more so than it is right now.
D
Let's imagine a utopia where we end up with software that has no defects in it at some point in the future. Might take a minute to get there, but let's just imagine we do. Hopefully in that time we also see wide scale adoption of ISH resistant MFA across the board. Because if there's one thing that organizations could do today, they don't already have it in place. Probably implementing fish resistant mfa. That's one of the most important things that they can do that's really going to make an operational difference for them. The reality is there, there are just a lot of legacy applications out there that don't support it. They require wrappers like zero Trust, network access, that sort of thing. So it's, it's not, it's not trivial to do right or organizations need to do this in a mindful way. There's capital investment associated with that, there's infrastructure, there's skill sets that are required. But if there is one thing they can do, it would Be that short of that. The other thing that I'd say about AI, and again continuing to imagine the utopia of it's going to fix all software defects. If you just think about the surface area of software that's out there and the rate at which software is now being developed because of AI coding assistance, we are going to see an exponential explosive growth in the amount of software that's out there. So unfortunately that software is probably not going to be defect free when it comes out. So I think in the near future what we're going to see is a very rapid increase of the surface area software. That software will probably have its fair share of defects in it and that's going to provide a bigger attack surface for adversaries to be able to go after. So for those organizations who are just discovering AI coding and they're very excited about the capabilities and they're thinking about I'm going to go replace my SaaS vendor that does XYZ for me. Be completely mindful of the fact that while the AI code is generally secure, is not always secure, and just think about what it means in terms of your attack surface and what you're going to be putting on the Internet.
A
So speaking of attack surface too, I'm wondering, do you have any opinions or any thoughts of this like growing set of threats that I see, especially with what I believe to be AI powered is a lot of open source software that a lot of people, even technology inclined people do not think about. But we've seen reports lately where adversaries are using AI to find and go after vulnerabilities in open source software. Uh, how do you talk to your customers about that and especially those that are using mdr where MDR I know is such a product where you are talking to customers that may not have, you know, like the global 2000s and they're getting technologists that understand all of different ways the supply chain can impact their company. When you have mdr, somebody else can worry about it for you but alert you when something goes wrong. How do you do that in the scope of an MDR when it's, you know, something like what we're seeing with GitHub repositories or something like rclone or what we're seeing in the JavaScript community? It is just a fascinating time that I don't think we, we've, I don't remember ever seeing it like this before. I don't know about you veterans of the cybersecurity space.
D
There's always been a concern about open source Security and I think the poster child for this has always been open ssl. Like ever since hardbleed and you know, shell shock and there, there, there have been like variations of like really wide scale like industry disruptive open source Linux like that, that has always existed. The, the rate at which the defects are going to be discovered is probably going to increase. We're already seeing early indications of that right now. And when you think about it in terms of instances of a piece of software like open SSL probably exists on let's estimate, 5 billion devices, whether it's your mobile phone or your television or whatever it is, if it has, it has an IPStack and it supports TLS, pretty good chance it's running open SSL. So there's a lot of that out there. But, but then you get more foundational on like the makings of the Internet itself and you've got like i9, you've got NTP, you've got FRR routing, like there, there's, there's a lot of like may maybe order of tens of billions of instances of certain open source projects out there. As the defects are getting discovered, they're getting reported to the project maintainers. We're already dealing with AI slop submissions. We're hearing instances of certain organizations turning off their bounties because it's becoming overwhelming to them that that's like an unintentional denial of service attack that we're seeing against OSS over.
A
Interesting. I haven't thought of it that way, but I do make a good point.
D
Yeah, we're going to need to figure out a way to deal with that. And you know, if it's like three people who are doing voluntary maintenance on a project that has millions of instances out there, we're going to have to come up with a more scalable way to help those guys out. And I think that is going to be a collaboration between public and private sector and many other organizations out there who are leveraging open source software. I believe that we have an obligation to be part of the solution there.
B
Great.
A
Alex, Joe, really appreciate you stopping by. You ever stop by again, we'll have to come in and talk about all of the changes that, that we're seeing because I feel like you could stop next week and we'll probably have an entirely different conversation. But I would love to have that if you're ever in town again. So appreciate you dropping by and joining the podcast.
D
Pleasure. Thank you.
A
Thanks for listening to Safe Mode, a weekly podcast on cybersecurity and digital privacy Brought to you by cyberscoop. If you enjoyed this episode, please leave a rating and a review and share it with your friends, your co workers, your sizzos, your sysadmins, your mom, your dad. Anybody that wants to know more about cyber security. To find out more information or to contact me, please look for all of our social media handles or visit cyberscoop.com thanks for listening. Check us out next week. Sam.
Date: April 30, 2026
Host: Greg Otto (Editor in Chief, Cyberscoop)
Guests:
This episode explores how government and industry can collaborate to make cybercrime more costly and less appealing for threat actors. It features two main segments: a breakdown of the Supreme Court case Chatri v. United States and an in-depth interview with Sophos CEO Joe Levy and Director of Government Partnerships Alex Rose. The conversation covers evolving adversary behavior, public-private partnerships, policies like "Secure by Design," and practical challenges in protecting both large enterprises and small-to-medium businesses.
(00:47–09:47)
(11:19–42:26)
(13:42–15:32)
(15:32–18:56)
(19:32–22:28)
(23:01–25:03)
(25:03–28:13)
(32:08–35:33)
(35:33–39:06)
(39:06–42:26)
This episode offers a nuanced, multifaceted discussion suitable for anyone interested in not just the "what" and "why" of cybersecurity threats, but also the "how" of meaningful progress through partnership and innovation.