Video: Discover the Sophos AI-Native Cybersecurity Defense System | Duration: 2708s | Summary: Discover the Sophos AI-Native Cybersecurity Defense System | Chapters: Welcome and Introduction (86.66s), Three AI Security Buckets (133.075s), AI-Based Threats (197.27s), Detection Opportunities (328.69998s), Pivotal AI Moment (401.235s), Process Reinvention (501.21s), SOC Platform Evolution (613.73s), Integrated Security Systems (698.9s), Sophos Fusion Launch (809.5s), Synchronized Security Infrastructure (898.34s), Customer Partner Benefits (998.015s), AI Native Mindset (1087.295s), AI Native Philosophy (1143.48s), Transparency and Trust (1263.2201s), AI Partnerships & Transparency (1303.175s), Join Our Vision (1402.3799s)
Transcript for "Discover the Sophos AI-Native Cybersecurity Defense System": Welcome. Thanks for joining us for a very special Sophos event. I'm Joe Levy, CEO of Sophos, and I am incredibly excited for what you will hear today. Earlier this month, we launched Sophos Fusion, the Sophos AI native cybersecurity defense system. Today, we're going to share why now, what it is, and how Sophos Fusion protects our customers in the AI era. I'm here with Raja Patel, president of products and marketing at Sophos, and Fernando Montenegro, vice president and practice lead at the Futurum Group. Thanks, Joe. And Fernando, welcome. The first question is for you. You know, AI adoption is through the roof. What impact do you believe it has on cybersecurity? Thank you. Thank you for for having me here. It's a phenomenal question, and it's one that we get a lot. The way we like to frame it is thinking about AI and security in three different buckets, if you will. Bucket number one is security for AI. How do you deploy security controls that the organization may need to protect the AI deployments that they are having on lines of business, etcetera. The other one is AI for security. Where can an organization apply AI to the defense capabilities themselves? Right? Whether it be within security operations, whether that be application security, data security, I mean, everywhere. Right? So security for AI, AI for security are the two most common ones. The third one is super relevant. It's security from AI. And that is how should an organization think about what changes in their defenses, in their threat posture when the adversaries start deploying AI capabilities. Awesome. Joe, over to you. Can you give us a couple of recent examples of AI based threats that have been seen in the world? Yeah. I I think probably the most memorable is probably Echoleak from about a year ago. This one was a variation of classic prompt injection, which was leveraging the RAG capabilities, retrieval augmented generation capabilities of Microsoft Copilot. And the scenario here was, an attacker sent an email to a victim, and that email had embeddings in it, which sat in the email box, didn't require any kind of interaction from the user. So this was a zero click scenario effectively, where when the user then did some sort of a search that would hit that rad content, it would pull forward the embedding from the attacker. It basically tricked Copilot into then setting up a link, which then automatically rendered in Teams. And the user didn't have to click anything at all, just basically did a search that hit this context. And it then reached out to a server that the attacker controlled, and it was able to demonstrate exfiltration of sensitive information. So pretty complicated scenario. But I think everyone who's worked with AI thinks about, like, what are primary concerns that we have about how is AI going to be exploited. Prompt injection is always at the top of the list, and here is one that was weaponized through from concept to actual impact on victim. The interesting thing about this is that there are multiple opportunities to spot and stop this sort of thing while it's happening. First opportunity is email is the vector itself. Like, if there's a good email security product that's actually doing the inspection, it would have had a very good chance to catch it on the inbound path before it actually landed in the user's inbox or before Copilot itself had the opportunity to access it through its rag mechanisms. Number two, as the attack itself started running through its sequence of events, there are Microsoft events themselves that are firing that you could pick up through management APIs, graph security API, and all of these could trigger real time detections of this unfortunate exploitation that was happening within the Microsoft environment. The third opportunity that you would have here is on the outbound attempt where Teams is unfortunately being tricked to reach out to the attacker controlled server, exfiltrate that information. You could stop that through various sorts of DNS protection, web filtering protection. Basically, your your network security apparatus begins to kick in here and has another chance to stop it. And then if it actually makes it through all these gates, then, of course, you've got managed detection response where all the event data is coming into the system. System is correlating all of this together from the discrete piece of context that we just walked through. And then you could have a human or you can have an agent actually respond to the threat if none of the previous controls had the opportunity to do it. So on the one hand, super scary sophisticated attack. On the other hand, plenty of opportunities to stop this kind of thing. You know, it's, as you walk through those steps, you know, you start looking at cybersecurity products and categories that have existed for a long time, and you will just walk through an example where you just made it a necessity for systems to have to talk to each other. Right? You know, it's a very pivotal moment in the market right now, and it's not just for technology providers or cybersecurity providers. It's just about for the human race and everybody else. Like, the adoption of AI is faster than any other technology that we've ever seen in our history. How would you define this moment? I I think you used a pretty good word there, pivotal. It really is. People often ask the question, what would you compare this to? Would you compare it to the Internet? Would you compare it to the web? I compare it to the Industrial Revolution. It's it's probably May may maybe you have something even bigger scale than that. Maybe one I think it's bigger scale, but but keep going. I I think it's unique. Like, analysts hate to use the word unique. I I'll use the word unique here. I think that that it is a pivotal moment. The reason why I think this is so significant is because I I think that we're at the early stages of a massive rewiring of society and civilization. I think it's going to be that big of an impact. We're in the very, very early stages of it today, and we can already see the way that it's impacting our lives. But I think within the next five years, it's going to completely transform the way that businesses run, the way that households are run. It's going to require complete and total process reinvention for just about everything that we do in a professional context, and I think in a personal context as well. People always compare it to cloud. Right? I think it's different because even cloud for it's wonderful. It it it brought us a lot. Cloud was confined to IT. AI is not. Right? It's the first technology in my lifetime that has this broad appeal to business outside of IT. And and I loved how you just framed, the process, and this should be the golden age of business process engineering. We should be re like, everyone should be looking at their processes right now and say, where does AI fit? Where does it not fit? And so on. On that point of process reinvention, I I think it's it's so important that we don't just look to recreate the existing processes that we have today with an AI. That that will make things maybe a little faster than they are today, but it won't necessarily make things better than they are today. I think it's probably one of the most common mistakes that organizations make as they begin their AI journey where they just look at the set of process that they have and say, we're just gonna reproduce these with AI. This this is a back to the drawing board moment where organizations need to ask themselves, do these processes need to exist? If so, in what form do they need to exist? How can we actually make these more effective, more efficient? And and this is it's it's just a major housecleaning opportunity for any organization through all functions of their business. We, of course, as you pointed out, tend to think of it in an IT context. We think about it as people who are writing code, people who are running security operation centers. We we look at it through the lens of cybersecurity. Joe, you describe the notion that you can't just take old processes and move them over. You gotta reinvent processes. And then there's the third layer, right, which is the humans that are defenders, The roles that we play are gonna constantly evolve as well. Of particular importance in cybersecurity, it does require a complete and total reinvention of the way the SOC works. You can't just continue with the same functions that you had last year when you're building an agentic sock or you're adopting an agentic sock. And we we've already done what career mappings look like from this point forward. We, we did a talk at the RSA security conference earlier this year on this very, very topic, and, that that session is available, for anyone who's interested in, hearing what we have to share on that. The the other really interesting point of this is that it really does demand that there is an evolution to the platforms that we're building to run our security operations. We always think of platforms as having a data lake and then a layer of analytics, layer of threat intelligence on top of that. The the tendency again is to just reproduce the processes that we had before, but this is really a moment for the cybersecurity industry to fix an architectural flaw. And that architectural flaw was best characterized by John Lambert from Microsoft who said defenders think in lists, attackers think in graphs. This is an opportunity for us to reimplement the way that these systems work so that the platform isn't just collection of lists anymore. The platform is actually operating the way that it needs to. It's operating like a graph. We are at this stage of deep geopolitical ramifications of massive impact to business operations of anything to do with cybersecurity. And we need to evolve that practice to think more like an integrated system. And I think that what goes in there, you need to have the right reaches into the business. You need to have the right to your point, redesigned processes on top of it. Right? The components are there. The the, you need controls, whether it's it's it's your own or or or others. You need you need that that orchestration. You absolutely need centralized data and intelligence in some capacity. Right? I think that the the the autonomy of the of the system is important as well. There are things that should really be autonomous. Right? For the not only because of the speed of the the potential attacker, but just because there is no need for a human to look into that. There has to be significant improvement in learning. Right? One of the one of the most, successful machine learning techniques is, like, reinforcement learning. Right? That kind of feedback loop. How do how does the system evolve from, okay, this may have worked, this may not have worked, how do we learn towards that? So I think that that is a phenomenal direction where industry itself is going. It's an evolution of just thinking about technology alone. It's thinking knowledge alone. It's thinking along a a broader system. Systems usually have four characteristics. They have performance. They have availability. They have, resiliency, and they have scalability. Right? You have to think about this in a broader sense. Joe, can you tell us how Sophos is securing organizations for the AI era? I am delighted to share Sophos Fusion, the Sophos AI native cybersecurity defense system. AI accelerated threats don't see your defenses the way you do. They see the gaps. That's where they thrive. The answer is not a platform. It's not a stack. Sophos built something smarter, a cyber defense system. Every control point, every service, every data source, every analyst connected, responding as one. A single open architecture, pulling your entire environment into one coordinated defense, always learning, always adapting. Every threat stopped, every edge case solved across more than 625,000 organizations raises protection for all. Agentic AI at speed, human accountability in command. The gaps are gone. The Sophos AI native cybersecurity defense system. Sophos Fusion, securing the AI era. Fernando, you described, you know, the what what the definition of a system are. And, you know, as a part of this, launch, that's exactly what we've built. You know, the Sophos AI native defense system or Sophos Fusion is really the evolution of a platform to assist them. You still need the control points. Right? And we need the control points to be really strong because you can't have defenders taking care of everything that comes through the door. Right? So without a strong set of control points, defenders are never gonna be able to keep up. But at the same time, it's gotta be native and third party. Right? Because the technology evolution and changes in technology happen so fast. Customers want choice, and so native and and and third party have to be a part of that control point infrastructure. You need your data in a common place, and you need every element of that system to have access so that whatever one element sees, everything else sees. And that's both for contextual data and also for response actions. Right? So every element of the system is as smart as any other element. The second element for us is synchronized. Right? Meaning, if we are able to see a detection on one part of the ecosystem, but yet you wanna be able to take an action on the other side, that has to happen in real time. The third you also touched on. Right? Genentech, autonomy is gonna continue to grow. However, you can't just let it on wildfire. You're gonna have to have humans being able to set the the the boundary conditions, and those boundary conditions will change over time. And the last one is learning reinforcement. The intelligence, and and that intelligence is anytime you see a threat in one part of the world, you're able to apply the fixes and learnings so that everybody that's within that system ecosystem benefits from it. At Sophos, that's 625,000 organizations, and it goes right back to the four framings that you did, scale, performance, resilience, and availability. Joe, what does this mean for Sophos customers? Every Sophos product is part of the Sophos Fusion system. For Sophos customers, the good news is they don't need to do anything. If they're using Sophos Central today, they're going to get the Sophos Fusion system tomorrow. This is an automatic upgrade delivering more value to them without them having to do anything manual, nothing to uninstall or reinstall, no changes, same familiar operating experience and environment for them with all the added value that we just covered. So for those of our customers who are starting with a single product, a single control point, they'll get the benefit of that technology within the system. And then as they add more products, they get a cumulative benefit as the knowledge and the intelligence compounds through the system. What does this mean for Sophos partners? Sophos partners don't need to do anything to gain the benefit of the Sophos Fusion system. If they're using Sophos Central today, they get Sophos Fusion automatically, and it confers all the benefits that we just talked about. There's one in particular that our partners, I think, are gonna be really excited about, and that's the availability of Sophos CSO Advantage. This is built on top of the Sophos Fusion system, and it allows our partners to go out and become the human interface that provides cybersecurity leadership to the customers using the CISO Advantage capability within the Sophos Fusion system. Fernando, question for you. What does AI native really mean, and why is it important? Being AI native requires several things. It requires, for example, the flexibility of experimenting. You have to have a research mindset. You have to be able to try little experiments. Some things will work. Some things will not work. That's totally fine. Right? But you have to have that mindset. Also, very important, you have to have a deep understanding of the technology itself. I've seen, Sophos present on AI for a very long time. Right? You've been at this for a long time, so you've seen that evolution. So I think that AI to to go back to your question, AI native is about that flexibility of exploration, the deep expertise in AI itself and in your processes, and then where do you apply them? Do you apply them to human centric processes? Do you apply them to completely new machine driven processes? But it's about that flexibility and experimentation. I agree with you. First of all, I I think, AI native requires a few things. One, it it must incorporate into its very design the ability for humans to provide feedback to the operations that the AI is performing for them. And, there there are many platforms that are out there today that don't incorporate that kind of feedback capability, and that's where you lose out on what perhaps the greatest benefit of AI enablement really provides, and that is an accumulation of value over time. The system must actually it it must get better through use, and that only happens through intentional design of that kind of feedback into the workflows and the processes that you're building in the very system itself. And that's been foundational to the philosophy of how we've been building for, you know, a decade now. The other part of it is that I I think it requires that you can't just be strictly a consumer of AI. You can't just use the stuff that Frontier Labs are producing. You also have to be a producer of AI. You you actually must give something back to the community. You you must be the provider of datasets, and we've done that in the past with Swirl 20,000,000. It was one of the very, very first datasets available in the industry to be able to train, AI detectors on portable executable files. And this is going back many, many years ago when when that was considered a novelty. I remember. We're talking 2017, 2018 time frame. Yes. A 100%. That's right. And, it it also requires, a generosity with these kinds of disclosures, and it requires transparency. There's still a lot of hand waving going on out there and a lot of unsubstantiated and invalidated claims, and we tend to be just the opposite of that. We we try to provide as much of the behind the scenes work as we possibly can because we think that that's foundational to credibility. We think that's foundational to trust. I would take that one step further. I think that that kind of transparency is, essential to trust and at the vendor level. And I think that that kind of transparency is where the industry should be going as an industry. And I'm not saying we're not there yet in terms of fiber, but I think that part of what we should be seeing from organizations is thinking about the systems they they deploy in a way that is transparent. You know, two tenants of culture at Sophos, transparency and trust. Would you mind commenting on the programs and how we're working with the Frontier Labs themselves using transparency and trust? Yeah. Happy to provide an update on that. We've been working with, OpenAI for many, many years. They they were one of our very first partners as we began, making very significant advancements in the capabilities and availability of AI across our products and our platforms. We've also, more recently started working with Anthropic. Internally, we're using Microsoft across our entire environment. We've we've used a number of other coding assistance to help out our r and d organization. So there's number of vendors that we work quite closely with, on the Frontier side. We're already part of, the OpenAI Daybreak program. Prior to that, we were part of TAC Trusted Access for Cyber, and, we were also recently brought into the anthropic Glasswing program. So we're working with all of the industry leaders in AI right now, and we're also a primary producer of AI models ourselves. You know, we've got a trust center, and we put everything up there for people to be able to go read, see for themselves. It's transparent, and it's available. And we just published twelve months of production data of our Agentix SOC, and fifty two percent of cases are now handled completely by AI with response times down to eighty nine seconds. Back in the days, this was thirty eight minutes or forty two minutes, and it's not acceptable anymore. But one of the things that you'll have a commitment from us is we will keep those stats updated because what's there today, will evolve tomorrow. And what we learn, we want everybody else to learn as well. AI advances have brought cybersecurity to a crossroads. The direction we collectively take will materially impact how businesses succeed in the next decade. At Sophos, our vision is a world where the most trusted cybersecurity is also the most accessible. Sophos Fusion, the Sophos AI Native Cybersecurity Defense System, is how that vision becomes a reality. This is our path, our choice at the crossroads. We invite you to join us.