AI Operators
Contact
All episodes

AI Attacks at Machine Speed. Zero Trust Is Not a Slogan.

livestream1:01:2812 Aug 2026

Tony Kirkham joins Dave Pengelley, Richard Webbe and Matt Slager to examine AI-driven cybersecurity, zero trust, observability, identity controls and the enduring value of network fundamentals.

DP
Dave Pengelley
RW
Richard Webbe
MS
Matt Slager
YouTube
Show notes

Episode notes

AI is changing cybersecurity on both sides of the fence. As tools become better at understanding code, finding weaknesses and automating technical work, defenders need to build security architecture that assumes threats move at machine speed.

Tony Kirkham joins Dave Pengelley, Richard Webbe and Matt Slager for a practical discussion about cybersecurity foundations that do not go away: isolation, segmentation, authentication, visibility and technical literacy. They unpack why zero trust is more than a phrase, why observability should focus on behaviour rather than an endless list of individual exploits, and why a business case for security is really a case for operating with assurance.

The panel also explores the opportunity in combining AI fluency with established cyber skills, the risk behind weak identity controls, and the potential for AI to make decades of undocumented legacy systems understandable again.

In this episode

  • AI-assisted vulnerability discovery and attacks at machine speed
  • The cybersecurity fundamentals that still matter
  • Isolation, segmentation and practical zero trust
  • Why observability needs to detect behaviour, not just known exploits
  • Authentication, passphrases and stronger identity controls
  • A practical risk-versus-assurance conversation for business leaders
  • Combining cyber fundamentals with AI fluency
  • Using AI to understand legacy code, rules and documentation gaps
Transcript
[00:00] Dave Pengelley: No more of those uh those dodgy stories. [00:03] Richard Webbe: I promise. [00:04] Dave Pengelley: Well, you never tell a dodgy story, I'm sure, Richard. [00:07] Richard Webbe: Never [00:08] Dave Pengelley: Um [00:08] Richard Webbe: in my [00:08] Dave Pengelley: if you [00:08] Richard Webbe: life. [00:09] Dave Pengelley: want to see a collection of Richard's dodgy stories, they will be soon available on [00:12] Richard Webbe: Oh [00:12] Dave Pengelley: on Amazon. [00:13] Richard Webbe: yeah. [00:13] Dave Pengelley: I'm just fixing up some of the publishing details, and then you can read a whole book of Richard's dodgy stories [00:19] Richard Webbe: You [00:19] Dave Pengelley: that [00:19] Richard Webbe: are [00:19] Dave Pengelley: aren't [00:19] Richard Webbe: fabulous. [00:20] Dave Pengelley: so dodgy, but they're [00:20] Richard Webbe: Yeah, [00:21] Dave Pengelley: very [00:21] Richard Webbe: well [00:21] Dave Pengelley: informative. [00:22] Richard Webbe: I'm very excited that we've got Tony Kirkham here today, who uh has witnessed some of those stories. Uh and we go back, I reckon three [00:31] Tony Kirkham: It it does, yes. It goes back, [00:33] Richard Webbe: Yeah. [00:33] Tony Kirkham: it goes back um goes back to the early sh uh early 90 years, 90s. [00:37] Richard Webbe: Yeah, yeah. Well, Tony, I'll let you introduce yourself in a sec, but Tony knows just about everything about the IT industry from every perspective, always has a great opinion. We're always discussing where the world's going and how it's going. Um, give us a little bit about your background, Tony. I won't I won't do that. [00:53] Tony Kirkham: Okay, so a little bit of background. Um I I'm new to new to the um I'm new to this podcast, so I'm just sort of getting a um you know feel for what's um you know what go goes on here. But um yeah, yeah, I I've been around the um been around the um um, you know, I guess the engineering and then the IT scene for um a lot of years now. Um so spent a lot of time in networking, um, spent quite a number of years with Cisco, um, so um a number of different roles there. Um spent a few years with Palo Alto Networks, um, you know, opened the um the Queensland office for them. Um as a fair while ago now. Following that, I started my own consultancy company, which is called Neon Knight Consulting. And, you know, it's it's pretty that was predominantly in the cybersecurity space, uh, where I've you know done yeah consulting work for for for a lot of people, um, you know, um large enterprises, a lot of telcos um have a bit of a niche specialty in in telco. But like everybody, um, you know, this AI thing has come along, which has got the um, you know, Potential to impact a lot of industries and change the way things can be done. There's some fantastic tooling there, which is going to have some fairly profound impact on things. So there's a lot in it to wrap your head around. So that's pretty much what I do. [02:17] Richard Webbe: Thanks, Tony. And um over to you, Matt. Thanks for joining us. [02:22] Matt: Hi, [02:22] Richard Webbe: Sorry, over [02:22] Matt: uh [02:22] Richard Webbe: to you, Dave. And then Matt. [02:25] Matt: name's Matt, uh it's nice to meet you. [02:29] Matt: Thanks for Yeah. [02:30] Richard Webbe: I've got no internet. I'm [02:31] Dave Pengelley: This [02:31] Richard Webbe: trying [02:31] Dave Pengelley: is [02:32] Richard Webbe: to do this on a [02:32] Dave Pengelley: this [02:32] Richard Webbe: phone hanging from my computer screen. Take over, Dave, [02:36] Dave Pengelley: as [02:36] Richard Webbe: and just tell [02:37] Dave Pengelley: all [02:37] Richard Webbe: me. [02:37] Dave Pengelley: as always, this show is a well oiled machine. [02:42] Dave Pengelley: Um but no, it's great, great having you, Tony. Uh uh mean uh friend of Richard's is a friend of the show's friend of ours. So it's good to have you here and bring your technical history and knowledge and insights into the space, especially around the cybersecurity thing, which I know Matt is definitely keen on how do we guard our lockdown, ensure that models are Doing nefarious things. Um, before we kick off with the bumper, I there's actually a YouTube post I saw, not YouTube, LinkedIn post I saw, which is really relevant to some of the cybersecurity stuff. And Tony, on the pre-show, um, you mentioned the hugging face thing and how the AI got out, and all these frontier AIs are supposedly breaking out of their cages and doing nefarious things. But I saw this uh insight into it, which I think you'll enjoy. [04:09] Richard Webbe: I [04:09] Matt: Sorry. [04:09] Richard Webbe: think that is a perfect description. As you know, I put a LinkedIn uh article this week. I think I posted it last night or the night before, about criminal AI and exactly that example where Entropic had an agent break out and cause trouble. What are your thoughts on all that stuff, Tony? [04:27] Tony Kirkham: Um to to be honest, I I haven't Really sort of I haven't really been through that Hunging Face incident in [04:35] Tony Kirkham: a lot of detail. But it's obviously happened. The stuff's obviously intelligent enough that it's able to, you know, have have knowledge of what can be exploited and understand how to actually go ahead and do it and some sort of a motivation behind it to actually find a path out of some of these, out of so some of these isolated networks. So I I think the really I think the real scary part and what sort of where where I play is you know just what people have got to do to sort of protect themselves from some of these um these attacks. That's sort of probably been more the more relevant thing, um, you know, thing to me that we're starting to see more and more these these attacks are really moving at machine speed now. You know, so trying to the the concept of having operators in the loop and trying to pick these things up manually or just you know checking log messages and things. like that. I think it's really going to drive the um the the need for a lot more sort of proactive defense on uh on on networks and um [05:40] Tony Kirkham: and and and also just going back to the foundation of just having a fundamentally strong you know defensive architecture um in in the first place I think that's just going to become more and more important now and and and that's been something that's been the case for a long time now that just as we move through um time and start to see some of these things um you know arrive uh it's just more and more of a consideration these days. But I think there's going to be more of this to come. You know, we're seeing a lot of sort a lot of stuff in the um you know the hacking in the offensive circles of where people are you know starting to you know construct these um the these um you know ai-based tools for you know for offensive purposes you know so so I think just just more and more we've got to be um you know very mindful of that and um you know start um you know constructing security architecture. And and um um, you know, those sort of postures on that basis. [06:34] Richard Webbe: What I find utterly Hollywood and very interesting about the whole scenario, how we're worried about malicious actors in the environment using AI to bombard and attack, it's the non-malicious ones that are making the headlines. There's just by their natural law, they are breaking in wherever they want to go. It's it's it's it's archaic. [06:55] Dave Pengelley: I mean, so it's like like you posted in that uh that image, uh Richard, and we talked about the garden. Scenario last week. It's that goal-driven models, right? You give it a goal without scope, and it's highly goal-oriented, and will find a way to appease its master and and fulfill the goal uh unless you've told it what it can't do. Matt, you're you're big on the guardrails. [07:19] Matt: I've got so many questions. I've [07:20] Dave Pengelley: I [07:20] Matt: got so [07:20] Dave Pengelley: know, [07:20] Matt: many links [07:21] Dave Pengelley: I know [07:21] Matt: to [07:21] Dave Pengelley: you [07:21] Matt: go [07:21] Dave Pengelley: do. [07:21] Matt: down. I'm just I'm holding them back. [07:24] Dave Pengelley: All right, well, let's let's let's do this and then you can go go nuts. [07:26] Richard Webbe: Yeah. [07:28] Dave Pengelley: Matt. [07:43] Matt: All right, I took a taking a big breath. Um, so first of all, Tony, I I I love like your origin, like where you've come, where you've been, where you've seen, you know, the stuff that you've seen, the changes that you've probably seen as well. And the first thing that I'm the most fascinated by Is your history of networking and security? Like, imagine you're a junior these days, you know, someone in their teens or 20s that wants to get into this space or a similar industry to what you've done. How do they do it now? Because like I feel like the way that you would have done it and the way that you probably would have taught this maybe five years ago is completely different to how you would do it now. But before you go through that. You said something before that I find so resonant is that, you know, these things now that are coming through are just making the fundamental principles so much more evident. [08:43] Tony Kirkham: That's that's very um that's very true. So so there's a few things in there. Um so so let's just um uh let's just try to um just break them break them all apart. So if you're a if you're a new person coming into the industry, you know, and I've I've been mentoring a couple of people who have come out of university into their first jobs and things like that. And I I I suppose just as a side comment, you know, I had a couple of um couple of you know very top tier um uh top-tier people um who have come um yeah who have come through who are looking for first jobs. It's been way harder to find them, um, you know, opportunities than I thought it was going to be. I I thought we would have had them into um, you know, into into places very quickly. Way more difficult, whether that's a sign of the economy or a sign of you know where you know the technology landscape is these days, I'm not not really sure. But in in terms of how how how you would do it, I think you've just got to really step back to the fundamental, you know, principles. You know, just I I used to tell you know my my guys you you've got to fundamentally understand how networks get broken into. And and I know things have changed, but there's a lot of things that certainly haven't. So you've got to you've got to understand just how a lot of these attacks have worked have have worked. You've got to understand what vulnerabilities are, how they're caused, [10:20] Tony Kirkham: and things like that. And then you've got to understand, you know, what are some of the um you know the fundamental um you know offensive tools that are used. You know, like, you know, just stepping right back to the the the basics, how do you do port scans, how do you do vulnerability scans, things, things like that. Um, you you know, what what what AI is really doing is it's it's it's learning a lot of these techniques. You know, it it's learning how you can go and uh attack something, it's learning what the vulnerabilities are. But the other thing that it can do, um, and and this was the the thing that came out of that um uh recent um uh anthropic model. Sorry, the name just escapes me. It was able to go through code bases and find um you know vulnerabilities which had never been discovered before and able to very quickly put exploits in place. So [11:14] Richard Webbe: Yeah. [11:14] Tony Kirkham: now that you've got automated um you know methods that can go through the these code bases and put the attack tools together very quickly on tools on on um you know systems where it didn't know these vulnerabilities existed. So one One of the cases in point there was like VLC. VLC is a [11:37] Tony Kirkham: very widely used media player. But sitting underneath it is some libraries called FFmpeg, which are some very low-level libraries that were written in that were written in C [11:51] Tony Kirkham: probably a lot of years ago, and they've evolved. And they're used as the foundation of like so many streaming platforms and things like that. this particular model very quickly went through and found some severe vulnerabilities in those libraries which made basically um all of these streaming platforms were basically found to be vulnerable um you know within a short period of time and there was no fix available for it you know so so there's some of the you know the the the things that have been happening that have been moving this um you know this scene along. Now I I've probably digressed there a little bit. So coming back too yeah so so a lot of it is understanding understanding those sort of fundamentals in you know in cybersecurity you know understanding things like how you protect data at rest how you protect data in you know in transit you know what are secure protocols how do you use them how do you secure systems things like that all of those things are still you know very um you know relevant today and it it's really just a matter of I I think working through and learning that and understanding it. Um yeah you know and and and I'd even probably Step back to some of the books that were put out probably even 25, 30 years ago now. [13:12] Tony Kirkham: There was one by Bellavin and Cheswick, which was put out probably in the late 90s, which which would these days would be very dated, but the foundations and the principles of it are still as relevant as ever. You know, so you've just got to keep that in mind. But you know, just sort of reading those. sort of books and understanding the um those um you know fundamental principles and [13:34] Matt: Yeah. [13:34] Tony Kirkham: then just be able to think um you know how do they apply in in a world of you know 30 years later because because one of the things that I found you know just in my time in the industry is old things become new again you know it's it's um it's amazing I think you know my um my my day when I my days when I joined um you know Cisco in the first place one of the things I never ever wanted to ever touch again was a dial up modem. Well guess what? When the internet started up um you know those things were used for internet access and um you know and they'll dull back again and I [14:10] Dave Pengelley: Yeah. [14:10] Tony Kirkham: that's a very dated example now. [14:12] Dave Pengelley: But [14:13] Tony Kirkham: But [14:13] Dave Pengelley: but [14:13] Tony Kirkham: there [14:13] Dave Pengelley: I mean [14:13] Tony Kirkham: there [14:13] Dave Pengelley: I [14:13] Tony Kirkham: there are a lot of examples of just where some of the things that have happened in the past just re-emerge in a new form. [14:19] Dave Pengelley: to your point about primitives and and and the primary principles though, think things like you know, subnet controls and isolation and so on, th those sorts of core networking principles, if you're trying to sandbox and isolate computers, machines, agents, and stuff. Those are foundational principles. And if you know how to set up your subnets and your routing to isolate traffic, then that's a critical principle that still applies from 30, 40 years on. RPB4 hasn't changed. [14:46] Tony Kirkham: Exactly. So the the the um the the principles of isolation and segmentation and things like that is still still a very uh very big one. Um there was a um a few years ago there was the whole zero trust architecture thing because became a um you know a a big deal. Um that was um you know that was a very important um you know concept in in in cybersecurity but the whole concept of you know of trust and you know defining what that um that that sort of thing actually means. [15:17] Dave Pengelley: Matt Matt pulled me up last week because I mentioned having um tokens in in a.env file in plain text for my agents. And um since then I've now set up one password and I'm running secure vaults. giving my agents access to a secret vault instead. So thank you, Matt. Um just all those little things, those things that you can get away with at first, but as these things mature and become more complicated and there's more risk and more surfaces, you've got to lock those down. [15:44] Tony Kirkham: Yeah. [15:44] Dave Pengelley: And arguably you probably couldn't couldn't [15:45] Tony Kirkham: Yeah. [15:45] Dave Pengelley: have got away with it up front, but I did and now I'm fixing it. [15:49] Richard Webbe: Thank you. [15:49] Matt: Can [15:49] Tony Kirkham: Yeah, [15:49] Matt: you imagine [15:50] Tony Kirkham: the the [15:50] Matt: the how [15:51] Tony Kirkham: so I I I'll just touch on one other I'll just touch up on on one other thing there. The the other thing and um that you just mentioned, Dave, was compared. Complexity. One of the things is also the management of complexity that a lot of people don't really grasp. That, you know, when you're putting a lot of systems together, you can very quickly get into a situation that gets so complex it becomes unmanageable. So that's very [16:18] Matt: Technical. [16:19] Tony Kirkham: that that's that's very important to understand. And that's also one of the things that AI tooling is very, very good at is that if you get, you know, systems that are just so complex that a human can't understand them anymore. They're very good at pulling that apart and breaking it all down to basic logic. So [16:34] Matt: Yeah, the reverse is true too. Whether I can keep making the system more complex that the human just doesn't understand it anymore. You [16:41] Tony Kirkham: yeah, [16:42] Matt: mentioned [16:42] Tony Kirkham: and absolutely. [16:42] Matt: um, you mentioned before, like learning those fundamentals. Like one thing that we talk about all the time is like technical literacy. You know, like there's a certain level of literacy that people need to brush up on every time there's some sort of change. And whether you've studied the old fundamentals. Or whether it's going to apply to you sometime in the future, it all is based on this like literacy. So and it's awareness of these things. So, like you said, like how do networks get broken into in the first place? I speak in analogies all the time. And the first thing that I think about is locksmiths. You know, you think about a locksmith as someone that's very safe and trusted. You know, call the locksmith. He will help us out with our locks, you know, because we care about our security and our privacy. I feel like the locksmith is The offensive person in this. He's got the offensive tools. And you know, like the locksmith is the hacker. So you need to have people that know these offensive tools in order to defend against them in the first place or to tune them right, if you will. [17:44] Dave Pengelley: The old the [17:45] Matt: So [17:45] Dave Pengelley: old red teams and black hats and all that kind of stuff. [17:48] Matt: like we're with the people that you spoke about before that you mentored and they're they're struggling to get jobs. Is that junior roles or is that you know senior roles? Like you're talking about like SOC analyst kind of roles? Or yeah, how does this work nowadays? Is it the same sort of landscape? [18:04] Tony Kirkham: It's really junior roles, just in my per in my particular case. [18:13] Tony Kirkham: So that's what I've hit in that um in that in that space. But one of the pieces of advice that I've been providing to them is like one of one of the guys very keen to go into the um into the into the cyber world. And and I said, I think what you've got to start thinking about is not just learning the cyber world, but you're going to need to learn the AI technology as well. Because the thing that I see that that particular generation is going to have that they can bring to the table that's fairly unique is that they can have a different way of thinking about things. That if they've grown up using this technology and can apply that new technology to the older problems, that can be a very valuable skill. And I I think from a personal thing where where I got probably um a lot of my breaks back in the um in the early days is where where I'd been able to develop some technical skill that somebody wanted and was prepared to pay money for. So [19:16] Tony Kirkham: so you you know you you can have industries you know get very commoditized and and and things like that. [19:24] Tony Kirkham: So you know being in a commoditized, trying to go break into a commoditized industry is very difficult. But if you can have it have have some sort of a more commoditized industry and you've got a new technology knowledge that you can bring to the table as well, that's the thing that I think can be a very valuable skill for [19:42] Dave Pengelley: It [19:42] Tony Kirkham: people. [19:43] Dave Pengelley: it seem [19:43] Tony Kirkham: And [19:43] Dave Pengelley: seemed to me that twenty, twenty five years ago you'd go get your C C and A and you'd just walk into any job. Like you'd have a dozen jobs waiting for you once you got your C C and A or and other certifications. Like is that less true now? Because you know, I can ask Claude to go and write write the routing table for me and I don't need to have quite as much knowledge and and all that sort of stuff's a little bit simpler in the AR world? Or is it just the markets moved? [20:07] Tony Kirkham: I think that's very true. I think that the market the market has moved and you can use these tools to do a lot of stuff for you, but it doesn't always get it right. [20:17] Dave Pengelley: Hmm. [20:18] Matt: And you [20:18] Dave Pengelley: Yes. [20:18] Matt: don't know unless you know those fundamentals. [20:20] Tony Kirkham: And [20:20] Dave Pengelley: You don't [20:21] Tony Kirkham: you [20:21] Dave Pengelley: know [20:21] Tony Kirkham: don't [20:21] Dave Pengelley: what you don't [20:21] Tony Kirkham: know, [20:22] Dave Pengelley: know. [20:22] Tony Kirkham: yeah, [20:22] Dave Pengelley: It's the [20:22] Tony Kirkham: you [20:22] Dave Pengelley: Dunning [20:23] Tony Kirkham: you don't [20:23] Dave Pengelley: Kruger [20:23] Tony Kirkham: you [20:23] Dave Pengelley: stuff. [20:24] Tony Kirkham: you you don't know um you know unless you've got enough you know background to be able to um to just say, no, look, what what this is just giving me here is rubbish. That's clearly a wrong answer. [20:37] Tony Kirkham: But it's also not just it a lot of the models these days are pretty good and pretty good at coming up with the right answer, but it's being able to use them to, you know, ask the right question. [20:49] Matt: Yeah, speak [20:50] Tony Kirkham: And [20:50] Matt: a language. [20:50] Tony Kirkham: that's um yeah and and that's really that that's really that sort of discernment is the um the the the Problem that I don't think believe has been solved. [21:03] Richard Webbe: And and and getting back to Matt's point about how much stress these young kids are getting into the market. I mean, I remember, you know, even when you and I working together in the old days, Tony, um, you could suck it and see, try and test. And nowadays you don't have time or or the ability to do that. You make a mistake and you can lose the whole business because there's an AI actor out there that's automated and moving at light speed. And so in the past, oh Look, someone's trying to get in through our firewall, let's just change the subnet mask on that. And you don't have time to do that anymore. So like you said, they've got to know AI and they've got to understand the people that are attacking them have AI. And if they're not equal to the tasks, there's going to be a lot of trouble, isn't he? [21:47] Tony Kirkham: Yeah. [21:48] Matt: I've experienced this myself. Like I I've actually got real life sort of experience on this exact thing that we're talking about. Cause like I back in the day, like let's say 10 years ago, I actually started down the CCN. A root got the CCE and D, and I started going down the next sort of path of study, getting ready to do like NP, and you know, it was like future pacing. And then I realized that the same concept, like I couldn't really find any place I wanted to work. And the content was great, but at the time I had a better offer, a different rabbit hole to go down. So I stopped it and I just went down a different path. Now my little brother, I've got two younger brothers. The older one, he's 25, you know, mid-20s, and he actually went to uni doing cybersecurity. Didn't finish it. He deferred, did a bunch of world travel. He contacted me recently and he said, Hey, look, I've just come back from overseas. I'm unemployed. Uh, I want to learn what you do. You know, is there any way that you can teach me what you do? Like, and I was like, Okay, do you still want to go down cybersecurity path? Because if you've got that, which is knowledge that I don't have, like I didn't go through those courses, but I can show you this, and all of a sudden you meld those. things together, we've got magic. And yeah, he's he's slowly started to to clue on and understand what this actually can do and where it can go. And just like Richard's bucket analogy from last week, you know, that water flowing into those cracks that the human just didn't notice. You know, I want to be able to teach him how to do that. [23:21] Richard Webbe: I think that's that's that's magic, Matt. I put in my career and looking at helping other people, and I'm sure Tony and Dave have seen this, if you get a unique skill. Over here that's not so unique anymore, and you get another, but you bring them together, you create a magic, you create a new color that no one's prepared for, and stuff like that. [23:39] Matt: One [23:39] Richard Webbe: I [23:39] Matt: of the [23:39] Richard Webbe: I [23:39] Matt: engineers [23:39] Richard Webbe: remember [23:40] Matt: I follow says something like that where you you don't speak in ores, you speak in ands. [23:45] Richard Webbe: that's it, that's it. And and you know, um the the funny thing is that when I was thinking about electric cars coming to the market, another metaphor for you, buddy. Um, I used to think, oh, what's the problem with electric cars? I thought A lot more pedestrians are going to die because the cars are a lot quieter and we use mostly our ears when we cross the road, not our eyes, but people don't realize a lot more people will be hit by electric cars. And it and I started to think now, of course, I having looked at that a bit more, 90% of the noise from a car, aside from a noisy V8, actually comes from the wheels. So it hasn't been cat yeah, tires and that. So and friction has been as catastrophic as I thought. But when AI grew up a few years ago, the first thing I thought thought of cybersecurity, you know, you've got all these people with these big security knocks and they're going to be useless against someone who's running a really high speed algorithm off a bunch of actors and agents and they're just going to find in a few seconds one way in when there's not one. [24:45] Matt: And and observe the like the actual monitoring of that, like the observability of that, like how you know that somebody's in your system or that one of those things is actually, you know, in there doing stuff, because they potentially could use different protocols that you haven't. set up observer observability for. I find that fascinating. And especially the old style of you know CVE releases, you know, okay, we've got this thing, it's been patched, make sure you update to this version. You know, now they can just detect when there's code changes before the CVE gets released, find out what the code change was, find out if that was a security vulnerability, and then just go attack it before they've even announced it. Like [25:24] Richard Webbe: And then [25:25] Matt: it's [25:25] Richard Webbe: we step [25:25] Matt: crazy. [25:25] Richard Webbe: we step straight into the world of unintended consequences. Be a person looking for unintended consequences, as Tony was saying, is a different set of skills to being a triage for a security invasion. [25:40] Matt: Absolutely. [25:41] Tony Kirkham: Yeah, so so I I've spent a I've spent a fair bit of time on this whole um you know observability thing and um yeah one of the one of the technologies that I'm a you know I'm uh a big fan of within the security space is the whole concept of network detection and response. The ability to be able to like what of wire and you know monitor all this traffic you know which is a very high speed and just within that start to pull out um particular malicious behaviors because um you know all of the various exploits and the um the you know the the more more atomic sort of techniques they change very quickly you know so so trying to stay on top of those and trying to stay on top of all the protocol changes is you know just almost a fool's errand but the actual behaviors and a lot of the techniques that the um malicious actors are using and and this is all stuff that's going to be learned by um you know ai um yeah you know in AI attacks as well is those behaviors and they change very very slowly you know so so if you can use that sort of um you know by throwing a lot of computational power at um those sort of things to pull those behaviors out you you can very you know quickly detect uh you know you can turn a lot of noise into a um you know into a signal act. on that sort of stuff. You know, so that's one, that's that's one you know particular technology there. Now where where was I um where where was I going where was I going with that? You know, within the whole within the whole observability piece. But that that's one of the other key um you know uh you know principles within within cybersecurity. It's the whole technique of like visualization of being able to detect these attacks and being able to correlate um you know seemingly unrelated events into you know something that's that that's meaningful. And um you know we're we're seeing with a lot of this, you know, a lot of the the the computational power that's available, we're able to do a lot of that sort of stuff there, which is, you know, tools that were astronomically expensive five, you know, 10 10 years ago. But the um probably where I where I actually was going where I was going with that is one of the biggest problems I found with getting a lot of those um technology is deployed is it's not a technology problem. It's it's actually a business investment problem. That you know, although the price point has, you know, potentially moved, you know, lower the speeds have also increased as well. One of the um the the biggest issues that that that I've found with a lot of these technologies is being able to make the business case for the investment of it. [28:24] Matt: Yeah. [28:24] Tony Kirkham: And that's been um you know one one of the one of the things I've you know would just come across time and time again just in consulting work is is that it you're you're able to find a um find solutions to a lot of these problems that particularly a lot of the chief information security officers and people like that um you know they've got they've got hundreds of potential um you know projects in the pipeline and they've really only got you know a handful of them that they can make the investment in and um you know both from a military point of view and From an execution point of view to deploy that sort of stuff. So that's a that's a big deal as well. Whereas, you know, more and more I'm seeing, you know, the business case for these things is, you know, is is probably more important than the actual technology solutions themselves. [29:17] Matt: Do you see it similar to like selling insurance? You know, you don't need insurance until you need it. [29:23] Tony Kirkham: Yeah, I so I I'm I'm um I probably more like to think about it in in terms of assurance. So I I'm I'm certainly certainly you've got certainly you've got um you know a risk that something bad you know can happen and you know you you certainly you you you certainly need insurance in place to be able to um you know protect you financially from those sort of scenarios but in a lot of these sort of things I prefer people to think about it from an assurance point of view that you um you like like what is what is it worth to your business to know that um you know you can be you know operating in a in a fairly safe region that you can eliminate a lot of the risks and be able to um you know and and um you know be able to be confident that um that that you could you can operate your business you know safely and securely without having to worry about this stuff. [30:30] Richard Webbe: Operate disrupted before it was gone. And we have a whole enough you've ever seen those lists, right? And so, you know, people don't think like that. They just think, oh, you know, we've got a hack, or someone took an email or something, did something like that. And I was in network observability for a number of years, as you know, Tony a few years ago. And I will say it is one of the hardest things to do a business case for. There's SOC compliance rules out there that government departments must do it and everyone do it, but no one does it. [30:58] Dave Pengelley: It's it's it's the old story of Like, what is the cost of the risk if it goes badly? And you hear you think about this like when you hear about product recalls, it's like, yeah, the lawsuits for 10 people dying uh is probably less than the cost of recalling the entire product suite. Like, and so we'll just take the risk that if we get sued a few times, it's still going to cost us less money than doing the full product recall. Now, I'd it's it's that mindset, I think, where it's like, what is the cost of it going bad versus the cost of us in in investing in the assurance? Like, sure, we could put all these systems in place, but then we'll never even know whether we're actually getting our money's worth out of them because if nothing breaks, then well that that's the good outcome. But then it goes, well, why are we spending all this money if nothing ever breaks? Well you spent all the money so nothing would ever break because if it did break the consequence would be this big. [31:44] Matt: It's kind of like health, like personal health. You know, why am I taking these vitamins? Why am I exercising? I'm not sick, you know, I don't need to get better. Like it's the same kind of concept. It's funny when you say that out loud, Dave, like that whole, you know, it's part of our budget to handle lawsuits. And you know, cataclysmic issues in the company. Um, we we've we've accounted for it. It's it's re it's ready [32:06] Dave Pengelley: And [32:06] Matt: to write [32:07] Dave Pengelley: and you [32:07] Matt: off. [32:07] Dave Pengelley: you you hear those horror stories around you know the tires and stuff like that, tire recalls and things where I'm sure those maths have been done and those conversations have been had and exposed over years. I didn't make that up, but um, I don't want to name any brands because then I'll get I'll I'll name the wrong tire company. But [32:22] Richard Webbe: Thank [32:22] Dave Pengelley: you know, [32:22] Richard Webbe: you. [32:22] Dave Pengelley: you you hear those conversations happen with with vehicles and cars and those sort of big heavy things where that's a huge recall cost versus Just paying for the consequences. [32:32] Richard Webbe: And [32:32] Dave Pengelley: Um, and [32:32] Richard Webbe: and [32:32] Dave Pengelley: in [32:32] Richard Webbe: I think [32:32] Dave Pengelley: in [32:33] Richard Webbe: sorry, go on, Matt, Dave. [32:34] Dave Pengelley: yeah, I was just just from rounding that out and going, and so when it comes to your cybersecurity, AI security, app security, like what is the potential like worst case scenario? And is that actually worse than do nothing? Like [32:49] Richard Webbe: Yeah, I uh in network observability, I would go and speak to like we sold to defense, to large corporates, banks, everyone. And I had one business manager line me up. And literally the same thing. So why are we wasting all this money on this stuff? Don't we have firewalls and things like that? And I said, Well, there's a new world coming for you, and it's coming for you. And I said, Let me give you an example. You're running a nightclub and you've got bouncers at the door standing there, just guessing whether someone's bad or not, but they actually don't catch them until they're inside, shooting, stabbing, drinking, fighting, punching, or whatever. I said, network observability, if powered by AI, is like having X-ray vision, and you've got a list. Of all the criminals, and as they walk through, you can see they're a criminal and you don't even let them in the front door. And it's a really, you know, it's a it's a step change if used properly. But of course, the step change that's really happening, as as Tony was alluding to and you're asking about, is the actors out there that are malicious, they're ready, they're lined up and going. And they're going, I reckon we're going to find out in a few years how much damage they've done because we won't even know about [33:54] Dave Pengelley: I mean, [33:54] Richard Webbe: it. [33:55] Dave Pengelley: that's as I like to say, locks only stop honest people. [33:58] Richard Webbe: Sorry? [33:58] Matt: Yeah, true. [34:00] Dave Pengelley: Lock so when they stop honest people. [34:01] Richard Webbe: That is very good. You've got the best sayings, Dave. Here's a classic example of delay security impact. I was sitting at my office desk a couple of years ago, and all of a sudden my phone buzzed, and my taxi in Mexico City was arriving at my hotel in two minutes. Problem was, I was sitting in Hampton, Victoria. [34:25] Richard Webbe: So I'd have to be careful as I say it was Uber. I don't mind outing them on that. So I looked at my phone and went, oh, that's no good. So I went in and I just immediately saw it and immediately cancelled it. But it seems you've been charged $1.50 for cancelling it. Now, you know what? I wouldn't have normally given a hoot, right? But I thought, no, I'm an IT. That's really pissed me off because it's wrong and it's all geospatial. So they should have known that my phone was here and not over there, right? So I spent the next hour trying to get onto someone and eventually got onto someone at Uber. I think I went around the back door by looking up someone on LinkedIn, cross referencing. Someone that knew, and I got a phone number. And I got the head of, I think I think it was the head of security of the call center in Australia, and they started going to me like this Have you given your password to anyone? Who's had a hold [35:11] Matt: Yeah. [35:11] Richard Webbe: of it? Yeah, it's all my fault. Now what happened? Flash forward, I could be getting it wrong, but I'm pretty sure six or twelve months later, the CIO for Uber ended up in jail because something like five million accounts were stolen, and he didn't report it to anyone. He tried to hide it. He ended up in jail. And I was one of them. And it's just, you know what I mean? But it didn't even come to light for another six months to a year. And it was nothing I don't. So how many million more of me people had been sort of thwarted and Uber got a free dollar fifty out of us? [35:44] Matt: So did you were you actually charged for that that [35:49] Richard Webbe: Yes. [35:49] Matt: Mexico Uber? [35:50] Richard Webbe: And I never got the dollar fifty back. [35:52] Matt: That's crazy. Like I've had I've had people they must misspell my email when they're typing in their email on accounts. So get I've I've gotten receipts for pizzas in Miami before, you know, from Domino's. But you know, I've never been charged. I've just been given the receipt. I'm like, thanks, no worries. [36:11] Matt: Yeah. Can I can I go down another technical pathway? I've [36:15] Richard Webbe: Please, [36:15] Matt: got one more [36:16] Richard Webbe: please. [36:16] Tony Kirkham: Well, [36:16] Matt: question. [36:16] Richard Webbe: We're hanging on the edge of our seats. Go, buddy. [36:18] Matt: I just feel a bit, yeah, feel a bit selfish hogging uh Tony's [36:22] Richard Webbe: No, [36:22] Matt: ears [36:22] Richard Webbe: go, [36:22] Matt: here. [36:23] Tony Kirkham: it's all [36:23] Richard Webbe: go. [36:23] Tony Kirkham: good. [36:25] Matt: So I did a little bit of research leading up to this when when Dave let me know that we're having a special guest. And I noticed that you wrote about zero trust as a phrase that people often misuse. What do you mean like that? And what does it mean for somebody to use it properly? [36:46] Tony Kirkham: That's that's a good question. Think about how to think about [36:49] Matt: Yeah, [36:49] Tony Kirkham: how to how [36:50] Matt: sorry. [36:50] Tony Kirkham: how to answer that. So so the old um um the old y saying I think when it first came onto the market, and it's been around a long time now this came out. The original concepts of this were born in the late 90s, if I remember it, um remember it um properly. But there used to be a saying trust but verify, which if you translate it means um do a lot of trusting and no verifying. Um so so it it's really it's really a matter of um you know making sure that you've got strong mechanisms in place before you consider you know some entity to. be to be trusted. You know, so so that could be something like, say if you took it from like an authentication point of view. You know, so if you're if you're if you're you're you're logging into a system, you can have a username and a password, pretty weak these days, easily crackable. Then you can move to things like passphrases, a lot stronger. You can move to you know some sort of multi-you know two-factor, multi-factor authentication, you know, hardware tokens and things like that are very strong. So you've got somebody who's gone and authenticated themselves, you know, say with a username, password and an and a um, you know, a an a um a UB key or something like that, um, you know, then you can probably have a very high confidence level that they're um you know actually a trusted entity and they say who um you know say who they are. That that's probably you know one of the key you know examples that I can um you know that I can I can think of. [38:26] Matt: That's a [38:27] Tony Kirkham: But [38:27] Matt: really good [38:27] Tony Kirkham: but [38:27] Matt: one. [38:27] Tony Kirkham: I could I can see that whole concept of trust is going to become you know more and more important, you know, in um you know in AI systems. Uh but I I could I couldn't actually off the top of the top of my head give you a good example of [38:40] Matt: That's [38:41] Tony Kirkham: um you know [38:41] Matt: fine. [38:41] Tony Kirkham: of [38:41] Matt: Like [38:41] Tony Kirkham: what that [38:42] Matt: something [38:42] Tony Kirkham: might be [38:42] Matt: that [38:42] Tony Kirkham: at this [38:43] Matt: like [38:43] Tony Kirkham: point. [38:43] Matt: Dave and I talk about this all the time. We always bring up the fact that like people talk about AI in production where like it's an AI system. Um, but it's not always the most important analogy or the most important situation. Like you can have a system that exists, and like we've just been talking about like The AI is inspecting or trying to penetrate that system that exists. It doesn't have to be an AI system. It could be that you've used AI to build a system and therefore you're trying to build this thing with concepts of zero trust involved. Like me this morning, I've got another real life thing. I literally had two client fires this morning I had to put out. One of them was the message in Teams, we can't see our dashboards. You know, I'm like, oh great, something's down. I go through my series of zero trust stuff and try and figure out where all the 200s are is there any 400s, any 500s? And then turns out it was on their end entirely. They had some sort of network-related issue and it wouldn't fetch the domain. It was just timing out. So like that was interesting. So my my version there of like production assurance was nice because I could say, well, look, guys, it's got to be something on your end. Like everything's fine. Um the second message was, oh, the team can't log in. You know, this is a different client, entirely different system, something else that's like a full stack app that I've put together. So I'm fully responsible. And this particular one was the Google redirect, wasn't working when they were trying to sign in. So, and this was nuts. This was just like a header, like a payload in the authentication redirect. It was literally a header that had changed. So that to do with the reverse proxy. And I had to just strip that header and then everything was fine. Like nothing that I could have known. So like I didn't have that observability for that thing. So yeah, crazy. Like that sort of authentication situation is so prevalent now, especially with people just being able to. Spin up an app with their coding agent of choice? What like, is it true? This is like something that I keep coming across. The concept of an email and a password plus multi-factor authentication, plus a YubiKey, like a hardware token, you know, when people just go and they use like a uh an OAuth sign-up process through Google or Microsoft or whatever those plugin options may be. Are those as terrible as people? don't want to accept, you know, having like a Google login for your application. Is that as insecure as as many would assume? [41:11] Tony Kirkham: Um [41:13] Tony Kirkham: good question. I've I've I've I I think it depends on like what what's the application? What are we doing with it? Um, you know, are we trying are we is it i is an application which has got real sensitivity behind it, you know, like um, you know. Storing people's credit card numbers and personally identifiable information and and that sort of thing. You know, or or is it a less important application? So I I I think you've got to really understand what the app is and what you're protecting and um, you know, make sure that you've got something that's uh you know, that aligns with that sort of um, you know, that's the the sort of objective and the sort of you know risk or consequences that could be involved in it, um, in it in it going wrong. Um, um, yeah, I I think people People are getting th people are getting tighter and tighter all the time. I've had a couple of emails from Microsoft just saying that they're basically um, you know, moving everybody to passphrases, want to move everybody to passphrases now. [42:10] Dave Pengelley: Yeah, [42:10] Tony Kirkham: And they're, [42:11] Dave Pengelley: they're [42:11] Matt: Yeah. [42:11] Dave Pengelley: getting [42:11] Tony Kirkham: you [42:11] Dave Pengelley: off the [42:11] Tony Kirkham: know, [42:11] Dave Pengelley: SMS [42:12] Tony Kirkham: yeah, [42:12] Dave Pengelley: and and and [42:12] Tony Kirkham: getting off [42:13] Dave Pengelley: notifications. [42:13] Tony Kirkham: SMS because there's no one um, you know, problems in known problems in that. Um, [42:18] Matt: Yeah, [42:18] Tony Kirkham: you know, that [42:18] Matt: SMS [42:18] Tony Kirkham: they're just becoming [42:19] Matt: RTPs. [42:19] Tony Kirkham: weaker and weaker all the time. [42:21] Dave Pengelley: Yeah. [42:21] Tony Kirkham: Um [42:21] Dave Pengelley: Yeah. I I I got caught out on all this um this this whole zero trust thing with some Bitcoin stuff last week with the cold card hack. So Um it's not super AI focused, but uh just on the concept of this trust and security thing. So a lot of people get these hardware wallets to generate their seed phrases for generating air gapped wallets. So this seed phrases never been on the internet. No one, it's not a software [42:44] Richard Webbe: I [42:44] Dave Pengelley: wallet, [42:44] Richard Webbe: think [42:44] Dave Pengelley: it's never [42:44] Richard Webbe: that's [42:44] Dave Pengelley: been on [42:45] Richard Webbe: a [42:45] Dave Pengelley: a [42:45] Richard Webbe: good one. [42:45] Dave Pengelley: computer. Like it should be an isolated set of 24 words that is that has that entropy and randomness that it's really hard to duplicate and crack. But one of the um Cold Card had an issue in their firmware where they were basically rolling. The keywords with a load of dice, and someone worked out w which dice was loaded, and so it reduced the entropy, and they were able to guess wallet seed phrases [43:09] Richard Webbe: Shivers, [43:10] Dave Pengelley: with much greater accuracy. And so hundreds of millions [43:12] Richard Webbe: I a good one. that's think [43:12] Dave Pengelley: of dollars of Bitcoin has been um rated and and moved from people's wallets because they generated their seed phrases using the supposedly air gapped hardware device. There was yeah, there was um yeah, yeah. So I may I mean I was I I I've got like, you know, a tiny amount of Bitcoin just because I was dabbling, um, nothing of consequence really. But uh but I had one of these [43:37] Richard Webbe: All [43:37] Dave Pengelley: wallets [43:37] Richard Webbe: right, [43:37] Dave Pengelley: and so I was like, [43:38] Richard Webbe: so [43:38] Dave Pengelley: crap. And so I went in and fortunately it was still there, but just the the stress of trying to work out how to move things with money from one thing to another to keep it secure and do all these sorts of things, like that and it got me thinking, I put a post up on LinkedIn. All of these decisions around whether it's cybersecurity, AI, Bitcoin, crypto. There's money attached to them. And as soon as there's money and, you know, potentially not trivial amounts of money when it comes to setting up some of your infrastructure right, people get cagey and stressed and they don't know what they don't know. And and who do you talk to and and where do you get advice from? And obviously it's guys like you, Tony. Like that's where people need to go, but then they hesitate and the temptation is do nothing. And like I was like at that point, like trying to work out all my Bitcoin wallet stuff, and I'd sort of start working out and go, Oh, I don't I don't want to get it wrong. So I'd go make a cup of coffee and then I'd come back and go, I've got to get this done. Oh no, this is too stressful. I'm gonna go sit in the sun for a bit. I'd be like, I just I kept coming and going, coming and going because I'm like, I was just overwhelmed by it. And do nothing was the easiest stress response. And I think there's lots of businesses across all of these things that we talk about on this show, AI, security, etc., where they're doing nothing because it's overwhelming and too hard. Are you seeing much of that in in your conversations, Tony? [44:55] Tony Kirkham: That's that's a very common thing. Um that that it just it it just gets so complicated that yeah that that that people are not in a position to do anything. So like maybe let me give you an example. In a lot of the um yeah a lot of the organizations that I I've dealt with, they're running, you know, big enterprises. They're they're running applications that have to run 247 by 365. [45:22] Tony Kirkham: Yeah, yeah. And and it's it's a if you're trying to if you're trying to like update, you know, just even doing things like trying to update firewall rules and tighten things up and do all of that. It's like trying trying to change the um you know the engine on a plane in flight. [45:37] Matt: Yes. [45:38] Tony Kirkham: And and and and when whenever I've you know had to do work on some of these um you know sort of sort of environments it it can it can be really um like I I'd have to say beyond stressful uh that [45:53] Richard Webbe: Yeah. [45:53] Tony Kirkham: where where things can things can go um things could go wrong. There was one that I was uh there was one that I was working on one night we were doing a project for I I won't say the client name, but but let me just say it was it did something that was basically critical infrastructure. You know, potentially, you know, it wasn't life and death if the um you know if the system was taken down, but if it was left down for probably more than 24, 48 hours, [46:18] Dave Pengelley: It's [46:18] Tony Kirkham: then there would have been like real consequences to it. [46:22] Dave Pengelley: not not like the ultra customers not being able to ring triple O or anything. [46:25] Tony Kirkham: Yeah, yeah. [46:26] Dave Pengelley: That wouldn't happen, [46:27] Tony Kirkham: Not not [46:27] Dave Pengelley: would [46:28] Tony Kirkham: quite [46:28] Dave Pengelley: it? [46:28] Tony Kirkham: not quite not quite that extensive. but you know but still a um you know but but still you know had a had a degree of criticality associated with it. And we were doing a um we were doing a firewall project on this and we're replacing some of the um you know some uh previous vendors uh equipment with with a with a new one and just in in the process of uh of doing it uh somebody had had basically left a landmine behind um in the in the previous design and you know we checked this as thoroughly as we could But in the process of upgrading one of the data centers, we ended up taking both of them down, the whole infrastructure down in the um in the process. And you know, this was this was a this was a sun this was a Sunday night. But and we we were able to back out and and and things like that. But that's just an example again. It was it [47:18] Richard Webbe: Tony, [47:19] Tony Kirkham: was complex [47:19] Richard Webbe: Tony, can I ask [47:20] Tony Kirkham: and [47:20] Richard Webbe: when you say they left a landmine, was it an an accidental one or a malicious one? [47:26] Tony Kirkham: it was just a poor network design that was just [47:28] Richard Webbe: Right. [47:28] Tony Kirkham: an accident waiting to happen. [47:29] Richard Webbe: Yeah. [47:30] Tony Kirkham: So [47:30] Richard Webbe: Okay. [47:30] Tony Kirkham: again, it was just a it was just a poor decision, poor design decision that somebody had made when this was deployed five years earlier earlier. They put it in place and were probably never seen again. [47:40] Dave Pengelley: It rem reminds me of this comic that I saw this week. [47:46] Dave Pengelley: Which which has got generated off a real story where they they were going through their budget line items and they saw their payment for this server, and no one, no one in the business knew what their server was, so they shut it down. And then, you know, the next day the finance team couldn't. Close out the books because this one server was acting as a middleware between two of their back end systems and no one knew it just ran for years and years. And the only thing they found in the code was like this one comment saying, Don't touch ask Dave. Like they didn't leave any documentation around what it was. Um, but you [48:16] Richard Webbe: I [48:17] Dave Pengelley: know, it's [48:17] Richard Webbe: think that [48:17] Dave Pengelley: it's [48:17] Richard Webbe: I think that does relate to a certain piece of technology in Telstra that caused the outage that was left alone and never upgraded and been there for years. [48:28] Dave Pengelley: yeah, that that the whole technical debt and legacy Of old applications is a real risk as well. [48:34] Matt: I [48:34] Tony Kirkham: Yes, [48:35] Matt: think [48:35] Tony Kirkham: and [48:35] Matt: it's [48:35] Tony Kirkham: I believe [48:35] Matt: hilarious. [48:36] Tony Kirkham: I I [48:37] Matt: You go, [48:37] Tony Kirkham: Yeah, [48:37] Matt: Tony. [48:38] Tony Kirkham: yeah, [48:38] Matt: Go ahead. [48:38] Tony Kirkham: and I I I've seen examples of that where you know systems are just you know, there's critical systems are running on some, you know, server that's stuck under somebody's desk in the office and then they leave. [48:49] Dave Pengelley: Yeah. Yeah, and like [48:50] Tony Kirkham: So [48:50] Dave Pengelley: I've I've I've worked in systems in small businesses and written access databases, and you do your best to try and do some handover documentation, but you know there's no one in the business that's going to pick that up and Run with that after you leave. And it's just going to exist as it exists for as long as they they use it until for whatever reason it breaks, in which case they're just gonna have to work out a new solution because they're never gonna be able to pick up and carry on and rebuild what you built as it was. [49:15] Richard Webbe: So [49:15] Tony Kirkham: So [49:15] Richard Webbe: let me [49:15] Tony Kirkham: so [49:15] Richard Webbe: ask the [49:15] Tony Kirkham: if we [49:16] Richard Webbe: team, [49:16] Tony Kirkham: if we [49:16] Richard Webbe: let me [49:16] Tony Kirkham: bring [49:16] Richard Webbe: ask the [49:16] Tony Kirkham: this [49:17] Richard Webbe: team, how many AI type agents are there that you could use today and pass across a system that automatically creates documentation and exposes gaps? [49:28] Tony Kirkham: do going that. to up, we're [49:30] Tony Kirkham: that was exactly what I was just about to jump in on. I think that's one of the real promises that I see that you can take a lot of these very complex systems and be able to use um use some of these systems to be able to understand what actually goes on. So just understanding the um complexity. So let me let me just give you give you an example one that I that I heard. There's a there's a company calledai and I don't know a lot about them. They're a um They're a US-based um US-based company. [50:03] Richard Webbe: Oh, you told me about them. Yeah, we [50:05] Tony Kirkham: Yeah. [50:05] Richard Webbe: were talking about it the other [50:06] Tony Kirkham: So [50:06] Richard Webbe: day. Yep, don't [50:06] Tony Kirkham: it's [50:06] Richard Webbe: want to. [50:06] Tony Kirkham: run by a there's a guy called Chamath Palihapatiya. He's the he's the current CEO of it, but he's a like a self-made billionaire venture capitalist. So [50:18] Tony Kirkham: he was he was quoting an example of one of the government agencies in the um in the US that they're working on, you know, some some application. And and and the world is full of these sort of systems. They they were written like 50 60 years ago in COBOL. And you know, they're still, you know, running, you know, things like the banking industry [50:37] Dave Pengelley: Mm-hmm. [50:37] Tony Kirkham: and um, you know, tax officers and all of those, those sort of things. Yep, yep, yep. So he was he was he was saying basically this this application, they'd been trying to um they'd been trying to upgrade it, they'd been trying to move away from it for for years, but it was just impossible to do so. All the programmers who are maintaining it are all getting old, they're either retiring or want. to retire or just dropping off. And you know, they're the guys who have the real tribal knowledge of how these things [51:08] Dave Pengelley: Yeah. [51:08] Tony Kirkham: how these things actually work. So he said we were able to actually use the systems that they had developed to go and analyse this whole code base. [51:20] Tony Kirkham: And they were able to break this down to about a hundred hundred thousand hundred thousand logical rules. Which if you think about it, that's really what a code base is. You [51:30] Dave Pengelley: Yep. [51:30] Tony Kirkham: know, it's going through, you know, um it and it it's got all of these logical rules and corner cases and um, you know, special considerations and things like that that have been [51:40] Richard Webbe: I [51:40] Tony Kirkham: built [51:40] Richard Webbe: should [51:40] Tony Kirkham: up [51:40] Richard Webbe: apologize. [51:40] Tony Kirkham: over the last um, you know, [51:41] Richard Webbe: That [51:41] Tony Kirkham: 50 [51:42] Richard Webbe: um [51:42] Tony Kirkham: years, and [51:42] Richard Webbe: there's [51:42] Tony Kirkham: none of [51:42] Richard Webbe: no [51:43] Tony Kirkham: it's [51:43] Richard Webbe: internet [51:43] Tony Kirkham: documented. [51:43] Richard Webbe: in my area [51:44] Dave Pengelley: Yeah. [51:44] Richard Webbe: at the moment. The [51:45] Tony Kirkham: Um, [51:45] Richard Webbe: Telstra's down and I'm using my phone and someone rang me, so it killed my VC. But what you're saying, Tony, is a great segue. We've got a guy coming on next week, um, uh John Ainsley, who's the CEO of a company called Nobi. And Nobi are now um, they're all about using their AI to observe someone doing something, no matter what it is, and very quickly creating. The documentation, all the aspects of what they're doing and support in 15 languages in about 15 minutes. It's quite astounding technology. And they're now extending that to wearables. So whether you've got your phone or you're wearing your Google glasses or something like that. So we've got Matt, he's sitting at his computer, he goes out to set up a server, you know, set up some special stuff and work with you. It will create the documentation, the instruction, the how to do, the Operators manual and everything just from observing. And it's quite astounding so he'll be coming on next week, uh, John Ainsley from Nobi uh to talk about that, and it's playing right into what you're saying. That company you're mentioning, how does it capture what's happened? How does it go out and find out where we're at and using AI as a uh you know an agent of good? [53:05] Dave Pengelley: Yeah, I mean the the the the ability for these agents to break down code bases and understand rules and and they they can like uh learn the languages and understand languages that you know it would take a human a long time to retrace COBOL code and Fortran and all these sorts of things, whereas the compute the AIs can do it much quicker. Even I told the story a few months back where uh someone needed um had a little USB recorder and there was a corrupted file on it. And I used AI to point it at it and it knew, worked out how to use the tools to go and pull a disk image and read through the file system and rebuild the file allocation table to get the full reference file back and restore this supposedly corrupted recording, which would have taken me as a human a million hours to work out like what commands I need to run and which logic, because it's not something I do all the time. And that sort of data recovery was a highly specialized field 10, 15, 20, 30 years ago. Now the AI knocked it over for me and under Now, like it was amazing. [54:03] Matt: Yeah. [54:03] Tony Kirkham: Yeah, it's pretty pretty amazing. It's pretty amazing what it can do. And it it it just in terms of you know productivity and and stuff like that. Like one of the last consulting gigs that um that that I did. Um just as a part of part of um do doing the engagement, they they gave me a uh well, I asked for it, it was a was a was a piece of data, I think it was about uh it's half a million lines or something like that. had a lot of IP addresses in it, that sort of thing. So you can't really sort of use, you know, Excel to go and try and filter out, you know, things on IP address ranges and stuff like that. So it was really sort of developing, you know, some some custom code and something that could suck in something of that, you know, that that size. So it was like pandas and you know stuff like that. And and yes, you can pick your, you know, your textbook up which is sitting on the bookshelf behind you and go and figure out what libraries you want to use and stuff like that. But just whacking it into um just whacking it into into Grok. You could just I I I could just say, right, I want to do this, I need a script, um, Python script, which is going to um like you use um you use pandas, use some IP address libraries, I need to pull this stuff out, I need to filter on this, this, and this, and just describe it in English terms, [55:19] Richard Webbe: Yeah. [55:19] Tony Kirkham: what you want to do, and it just pumps out a script that just worked easily. And and it just it it just gave me the the ability to go a lot further in the analysis. than I normally would have and um you know some of the conclusions that I could pull out of that and turn those into um you know justification for recommendations was you know was much stronger [55:40] Dave Pengelley: Yeah, [55:40] Tony Kirkham: you know [55:40] Dave Pengelley: we [55:41] Tony Kirkham: so [55:42] Dave Pengelley: yeah, we we're coming to end now. So I want to round us out a little bit um as we as we wrap up. Uh and thank you, Tony, for all your insights and time that I really appreciate it. But I mean uh this morning, all these tools and things we are we are so early, and I'm gonna bring up a few posts uh from different points of view that that talk about how early we still are in all this AI stuff, but for the people that are getting [55:59] Tony Kirkham: I'm if not sure you're [56:00] Dave Pengelley: Getting across it and using it like you did, Tony, to break down that IP problem for the data recovery. I was doing some volunteering at my kids' school's library today. I signed up as a parent volunteer and going around, you know, Dewey decimal, putting the books back on the shelves when they've been returned, just simple stuff. And then, you know, you go, okay, that clearly doesn't live there. That's in the wrong section. And you sort of do a bit of them to tidy up while you're there. But it got me thinking, I could just get my agents to write an app where I can just go up to any section of the shelf, take a photo, it's gonna read the spines. Check the Dewey decimal catalog and tell me, hang on, book three, seven, and twelve are all out of order. Um, move them to a different shelf or or do that. And that is like, it's not the biggest problem in the world if a few books in a school library are out of order. But it's one of those things that if you were trying to do it [56:45] Richard Webbe: It's [56:45] Dave Pengelley: manually and [56:46] Richard Webbe: a three [56:46] Dave Pengelley: fix [56:46] Richard Webbe: minutes [56:46] Dave Pengelley: it manually, [56:47] Richard Webbe: just off. [56:47] Dave Pengelley: it would take you forever to go through every book and do that sort of thing. But now, in you know, like like yeah, I can whip up an app in no time that's gonna throw the picture through a through a image model that's gonna OCR felt format it out. Deterministically and have that mix of determinism and AI stuff to keep the cost down. But like the ability to build tools to do things is just like it's this untapped world for the people that are thinking in that way. Um, and it's that's there's a lot to be said for the future of where that's going. But we are early. Um, Claude, ambassador for Sydney, Dominic Fretz, um, he's posted today that he's just spent five weeks outside his AI bubble. He's been traveling the world. Dublin, Chicago, et cetera. Excellent. Thanks, Tom. Um, but he was saying that uh he's in this bubble, this AI bubble, doing Claude code, ambassador stuff all the time. Um, but when he's been out there, like he went to a wildlife health conference, brilliant [57:43] Richard Webbe: Yeah. [57:43] Dave Pengelley: people, world class in their field, [57:45] Richard Webbe: Yeah. [57:45] Dave Pengelley: most have barely gone past the chat window of Chat GPT or Gemini. They haven't even heard of Claude. Same thing happened in Switzerland. And so, like, we think all these things are like normal, common stance. We're living in this bubble. Natalia, who joined our show uh a few weeks ago, she She's just been over to Europe to uh do some mind-meld AI conference thing. So she's like, I fly 26 hours to an AI conference to get a read. One thing was clear: businesses building AI solutions are going the opposite way, less AI. So she's saying, you know, like people are like, I need AI, I need AI, but it's also coming back to that determinism thing. And while everyone's trying to chase AI solutions, because they think they're late, they need to be thinking about AI [58:24] Richard Webbe: What's [58:25] Dave Pengelley: to [58:25] Richard Webbe: the [58:25] Dave Pengelley: build [58:25] Richard Webbe: business guy [58:25] Dave Pengelley: non-AI [58:26] Richard Webbe: saying, man? [58:26] Dave Pengelley: solutions and get back to that determinism. [58:28] Matt: Yeah. [58:30] Dave Pengelley: Yeah. [58:30] Matt: Yeah. [58:30] Richard Webbe: Yeah. Yeah. [58:33] Matt: Rapid, uh fast, parallelism, [58:35] Dave Pengelley: Yeah. [58:36] Matt: understanding complexity. [58:37] Dave Pengelley: Right. [58:37] Matt: Yeah. [58:37] Dave Pengelley: But but it's it's like the AI might help you build the tool. Like Tony, you were necessarily using AI to analyze the IP addresses, but you used the AI to build the tool to analyze the IP addresses, [58:46] Matt: With [58:46] Dave Pengelley: right? Like [58:47] Matt: the [58:47] Dave Pengelley: it's [58:47] Matt: with the financial with the um technical literacy, write a Python script, use pandas, we're gonna be doing IP filtering. Like if you just said, hey, [58:55] Richard Webbe: Yeah, [58:55] Matt: I've [58:56] Richard Webbe: I was [58:56] Matt: got this [58:56] Richard Webbe: um [58:56] Matt: thing, [58:56] Richard Webbe: I [58:56] Matt: go [58:56] Richard Webbe: was trying [58:56] Matt: figure [58:57] Richard Webbe: to [58:57] Matt: it out, [58:57] Richard Webbe: I was [58:57] Matt: like [58:57] Richard Webbe: trying [58:57] Matt: it's [58:57] Richard Webbe: to [58:58] Matt: completely [58:58] Richard Webbe: do some [58:58] Matt: different [58:58] Richard Webbe: research [58:58] Matt: instruction. [58:59] Tony Kirkham: Oh [58:59] Richard Webbe: um a number about six or twelve months ago and um I was sending I was trying to get my LLM to do the research on a web page by web page basis like please find in here these saline Points, blah, blah, blah. And it wouldn't do it. I'm not allowed to go into that website. So I just went in and I photographed all of the web pages and then pasted them straight in. So it had the full catalogue of the information I was looking at. And this became a visual database. And I just said, tell me this, answer me this, what part of research. And it was like lightning. It was so good. It was another human doing the reading and the research for me, just because I took photographs of articles. [59:47] Richard Webbe: Well, some of them block that now. [59:48] Matt: Now [59:48] Richard Webbe: So [59:48] Matt: you [59:49] Richard Webbe: some [59:49] Matt: don't [59:49] Richard Webbe: of [59:49] Matt: have [59:49] Richard Webbe: them [59:49] Matt: to do [59:49] Richard Webbe: are [59:49] Matt: the photographs, [59:49] Richard Webbe: very aware [59:50] Matt: you can just connect [59:50] Richard Webbe: that [59:50] Matt: it with [59:50] Richard Webbe: they [59:51] Matt: computer [59:51] Richard Webbe: don't want [59:51] Matt: use. [59:51] Richard Webbe: their intellectual property used for someone else's research. So they stop LLMs getting access to the web page. [01:00:03] Richard Webbe: Yeah, I'm sure there is. I'm sure there is. [01:00:05] Dave Pengelley: Yeah, Matt Matt's like there's there's ways around that. But anyway, that's uh a chat chat for another show. We we're uh we have hit the uh hit the hour. Thank you, gentlemen. Great chats, great insights. I hope [01:00:17] Richard Webbe: Thanks, [01:00:17] Dave Pengelley: uh our [01:00:17] Richard Webbe: Tony. [01:00:17] Dave Pengelley: audience [01:00:17] Richard Webbe: If anyone needs [01:00:18] Dave Pengelley: got [01:00:18] Richard Webbe: Tony, [01:00:18] Dave Pengelley: some uh [01:00:19] Richard Webbe: just [01:00:19] Dave Pengelley: value [01:00:19] Richard Webbe: go to [01:00:19] Dave Pengelley: out [01:00:19] Richard Webbe: our [01:00:19] Dave Pengelley: of [01:00:19] Richard Webbe: website [01:00:19] Dave Pengelley: that. I [01:00:20] Richard Webbe: or [01:00:20] Dave Pengelley: know [01:00:20] Richard Webbe: look up [01:00:20] Dave Pengelley: we [01:00:20] Richard Webbe: Tony [01:00:20] Dave Pengelley: all did. [01:00:20] Richard Webbe: Kirkham on [01:00:21] Dave Pengelley: Um [01:00:21] Richard Webbe: LinkedIn. [01:00:22] Dave Pengelley: yeah, [01:00:22] Richard Webbe: Great [01:00:22] Dave Pengelley: please. [01:00:22] Richard Webbe: guy, high value. [01:00:27] Dave Pengelley: Yeah, well he'll he'll he'll he'll get a Profile page spun up on the AIOperatorspod.com website as we get this episode uh transcribed and uploaded. Um, I'll grab a picture of you off LinkedIn, Tony, so we can generate a comic version of you for our weekly comic strip. [01:00:41] Richard Webbe: Look right, [01:00:41] Dave Pengelley: Um [01:00:41] Richard Webbe: so [01:00:42] Dave Pengelley: that [01:00:42] Richard Webbe: I [01:00:42] Dave Pengelley: you'll [01:00:42] Tony Kirkham: I'll [01:00:42] Richard Webbe: love [01:00:42] Dave Pengelley: you'll [01:00:42] Richard Webbe: it. [01:00:42] Tony Kirkham: look [01:00:42] Dave Pengelley: see [01:00:42] Tony Kirkham: forward [01:00:43] Dave Pengelley: posted. [01:00:43] Tony Kirkham: to it. [01:00:43] Dave Pengelley: Well, I mentioned you on that one. Uh if you [01:00:48] Dave Pengelley: um please make sure to like, subscribe, comment, comment uh the way the algorithms know to share this content out. Uh, whether you're watching this on YouTube or LinkedIn where we post it. If you're watching on LinkedIn, please follow our LinkedIn. Page AI operators podcast, so we can continue to grow that and more people can hear these conversations and learn from the shared knowledge and wisdom of our experiences. As my grandfather would uh often say to me, [01:01:12] Richard Webbe: Well, [01:01:13] Dave Pengelley: the best teacher's [01:01:13] Richard Webbe: very wise [01:01:14] Dave Pengelley: experience, [01:01:14] Richard Webbe: this morning, Dave. [01:01:15] Dave Pengelley: it doesn't have to be your own. [01:01:17] Richard Webbe: Sounds like it. [01:01:18] Dave Pengelley: Yeah, yeah. My my granddad, he was one of a kind. [01:01:22] Richard Webbe: Thanks, [01:01:22] Dave Pengelley: But uh, [01:01:23] Richard Webbe: Tony. [01:01:23] Dave Pengelley: all right, we'll wrap it up there. Thank you, gentlemen. We'll see you uh next time.
Related episodes

Keep going

Chapters

Jump to a section

0:00Tony Kirkham joins the panel
2:42Cybersecurity and AI moving at machine speed
8:43Why cyber fundamentals still matter
11:14AI-assisted vulnerability discovery
14:19Isolation, segmentation and agent boundaries
15:17Securing agent credentials and secrets
18:13Combining cyber skills with AI fluency
21:03Why junior cyber roles are changing
25:41Observability and behavioural detection
29:17Security assurance versus insurance
32:34The cost of doing nothing
36:25What zero trust actually means
42:21Stronger authentication and passphrases
49:17AI for legacy systems and undocumented rules
53:05AI-assisted code analysis and data recovery
55:42Building practical tools with AI