Hosted by: Aaron Crow
Guest: Clint Bodungen
Clint Bodungen is a globally recognized cybersecurity professional and thought leader with 25+ years of experience (focusing primarily on industrial cybersecurity, red teaming, and risk assessment). He is the author of two books, "Hacking Exposed: Industrial Control Systems" and “ChatGPT for Cybersecurity Cookbook. Clint is a United States Air Force veteran and has worked for notable cybersecurity firms like Symantec, Booz Allen Hamilton, and Kaspersky Lab, and is currently the co-founder and CEO of a cybersecurity training startup, ThreatGEN. Renowned for his creative approach to cybersecurity education and training, he has been at the forefront of integrating gamification and AI applications into cybersecurity training, creating his flagship product, “ThreatGEN® Red vs. Blue”, the world's first online multiplayer computer designed to teach real-world cybersecurity. His latest innovation is AutoTableTop, which uses the latest generative AI technology to automate, simplify, and revolution IR tabletop exercises. As AI technology continues to evolve, so too does his pursuit to help revolutionize the cybersecurity industry using generative AI and large language models (LLM).
In this conversation, Clint and Aaron discuss the value of tabletop exercises in cybersecurity and the development of auto tabletop, an AI-based tool for facilitating incident response tabletop exercises. They highlight the limitations of traditional tabletops and the benefits of using AI to enhance engagement and flexibility. They address concerns about AI in cybersecurity, such as data privacy and security, and emphasize the use of local language models to mitigate risks. They also discuss the future of AI in the industry and the workforce, emphasizing the importance of learning generative AI and prompt engineering for future job prospects. In this conversation, Clint discusses the automation of tasks using AI and the benefits of using AI as a tool to enhance human creativity. He also explores the future of AI and its potential for accelerating technological advancement. Clint acknowledges the concerns about the potential misuse of AI but emphasizes the importance of using it for good. He highlights the role of AI in reducing barriers to innovation and its significance in cybersecurity. Overall, the conversation highlights the transformative power of AI and its impact on various industries.
To be a guest, or suggest a guest/episode please email us at [email protected]
—
Show notes by NMP.
Audio production by NMP. We hear you loud and clear.
Aaron Crow (NaN:00NaN) Hey Clint, welcome to the show buddy. Uh, why don't you, for those, uh, Clint has been on the podcast before. Um, but just in case somebody hasn't listened to you, hasn't listened to that previous episode, we actually will link to the, uh, show notes, uh, what you, what podcast you were on before, but go ahead and, and why don't you tell us who you are, what you do, all that kind of fun stuff.
Aaron Crow (NaN:00NaN) Awesome. Yeah. Clint and I have, have a very, uh, similar background in, in a lot of ways been doing this a long time. Um, I, I've been fortunate enough to have some amazing conversations with people like you, uh, you and I, you know, hanging out at black hat and, and talking about the art of the possible and, and AI and cybersecurity and OT and all these different things. So man, let's dig into it. You know, let's, you and I were on a, um, uh, a YouTube stream yesterday, um, doing a tabletop exercise, um, where we were the, um,
Aaron Crow (NaN:00NaN) the Death Star and we were on the Death Star and we were sour response and we were responding to an incident where the rebels were trying to attack us. It was a lot of fun. But why don't you talk a little bit about what that is and why that's important and why it's valuable and why it's cool beyond just the, you know, we were the bad guys or the good guys or whichever side you want us to talk about.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) Hehehe
Aaron Crow (NaN:00NaN) Yeah. You know, and the cool thing was that there's a lot of things. And I want to dive into this because I think it's super important. Um, you were able to on the fly, a made it fun, right? So, so we did this, this exercise, we, we did it in star Wars land. Um, it was a hypothetical scenario, right? You know, so it wasn't real, but it was fun. So not only was it, it was engaging, like the four of us were there. We weren't.
Aaron Crow (NaN:00NaN) I didn't have a clue what was going to happen. You didn't have a clue what was going to happen, but we were able beyond just, you know, the way that I've done this before. And you've seen me do these at conferences where we have a, you know, a 10 step scenario that we want to run people through a tabletop and it's a predetermined, you know, step one has these three options and step two has these three options and step three, you get the point. Right. And really it's about for those, especially the, that we do with, that I've done multiple times with ICS Village.
Aaron Crow (NaN:00NaN) It's more about conversation. It's more about team building. It's more about people giving people that have never done one that maybe they're dipping their toe into OT or they're dipping the toe into cyber security. Right. It's a really, it's a, it's an understanding of, wow, I didn't even think about that. Right. And we re we got some really amazing answers and perspectives based on that. But because of the constraints of, of the tabletop being in a PowerPoint and we had to have all the answers and we had an hour's worth of time to do this in, you know, we, we had to.
Aaron Crow (NaN:00NaN) you know, really have it be, you know, analog, right? It, there were only certain things that we could do. So it limited the conversation. Like we had a lot of good conversations, but we couldn't dive down that path. So the thing that I loved about what we did yesterday was every step as we're communicating amongst ourselves, we say, Hey, let's go, let's do this. So we tell the, the chat GPT or the auto tabletop to, right, right.
Aaron Crow (NaN:00NaN) If we, we tell the auto tabletop, the AI model to, Hey, we want to, you know, lock down the, the Death Star. And we want to, you know, send storm troopers out to this area. And we want to, you know, do all these things. And then it gives us a response based on our actions. So it's very dynamic. It's a, you know, it's a, uh, it's a, it's a role place game, very similar, like you said to D and D, but all along the way, even though it was this fake scenario and, and the Death Star.
Aaron Crow (NaN:00NaN) We were still doing cyber hygiene things. Like we were still having incident response. We were still communicating to our, our leadership. You know, we were still, you know, sending physicals response folks out there because we were afraid that there was maybe a response required. So it's really powerful to be able to do that because when you do a tabletop for a large organization, how many people actually get to sit at the table, right? How many people actually get their voice heard? And like you said, if you do it once a year, if I go work out once a year, I'm not going to have a six pack.
Aaron Crow (NaN:00NaN) Right? Um, I'm going to have to do it more consistently than that. It's the same reason why you have, you know, fire, uh, sit, uh, practice. You, you, you go through these procedures and you test those things. Where do I go? What is the muster point? Like it should be second nature. As soon as those things go off, people aren't looking around like, I don't know what to do. Like we did this once three years ago, but I don't remember what to do. Like you should be.
Aaron Crow (NaN:00NaN) trained, it should be repetitive. It's like CQB in the military. It's like, why the seals train so much? Like it's all about understanding what the next step is. Cause you're going to step your toe. You're going to make mistakes. But when you do this on a regular basis and you could do this for everybody because you lowered the barrier of entry. Like I don't have to have a McKinsey. I don't have to have a booze. I don't have any, I have an UI or this consultant to come in and do this big orchestrated thing that costs time and materials and bringing, bringing in all this stuff, I can do this.
Aaron Crow (NaN:00NaN) weekly, monthly, quarterly, like it really opens the floodgates to be able to provide this understanding to the masses.
Aaron Crow (NaN:00NaN) Right.
Aaron Crow (NaN:00NaN) Right.
Aaron Crow (NaN:00NaN) That's all right.
Aaron Crow (NaN:00NaN) I could, but we'll get it out and post, don't worry.
Aaron Crow (NaN:00NaN) That's fine.
Aaron Crow (NaN:00NaN) So it's, it's really deep diving into how you, you take the gloves off. Like there, there's no scenario that you can't do. I can, I can tell it to check logs. You know, we, we went through and told it to check logs. We looked, we, we told it to check video surveillance, um, for, uh, physical, you know, in these areas, we, we sent, uh, stormtroopers out again, you could do physical security when it's not a hypothetical situation.
Aaron Crow (NaN:00NaN) I think you even said that you can feed it, you know, architecture diagram. So it actually is using your environments. Again, you're not going to want to potentially put, you know, IP addresses or things like that. You don't need to, but you can put a general high hierarchical, you know, architecture drawing in there that is more realistic to your environment. So, so you have less of those managers saying, well, that's not how our environment works. Right? We don't have that problem because we've done X, Y, and Z. And then you can just give it that feedback saying.
Aaron Crow (NaN:00NaN) Well, we don't have that problem. We've turned off that secure mode access, or we don't have active directory, or we don't have that vulnerability. So that's not a viable attack.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) So that gives you, you know, I know when we first started, we were like, I don't know what to say. Like, I don't know where to start. So you kind of helped us guide that, but you can just ask it. I don't know where to start. What are some ideas on things? Like there's all sorts of things that you can do to get the ball rolling. For me, that means I can give it to my junior people, I can give it to my mid-tier people, I can give it to my super experienced people, right? And they're all gonna get value from it.
Aaron Crow (NaN:00NaN) They're not going to, you know, that's another problem that you have in a tabletop exercise, your junior people are going to sit in the back. They're probably not going to say anything. Your, your mid level people may say something, but they may get overrun by the, the guy that knows everything and talks all the time. Um, whereas if you do this in the right scenario and, and depending on how you put the teams together, you can take your junior folks and let them run on it on their own and practice it and run through it a couple of times and, and that kind of thing, right. And, and they're able to.
Aaron Crow (NaN:00NaN) get value and improve their skillset because they're putting in reps. You know, it's just like anything, the more of these things I do. And the other thing is, is every time I do it, it's a different experience. So it's not like I'm just going to run back through it. And I have the same thing again. I can run through it with a different scenario, with different outcomes, with different perspectives, a different attack vector. You know, this one's malware, that one's a phishing attack. This one is, you know, social engineering, you know, really again, going back to the sky's the limit. So, so you can really be.
Aaron Crow (NaN:00NaN) is as flexible as you want by the teams, the scenarios, the amount of times that you run it, it really opens the door to get a lot of value out of this for entities that may again, like you said, maybe they've got, you know, they do one a year to check the box for compliance. And that that's good enough. But that's because maybe they don't see the value in it from this perspective, because it's just not it's not the same.
Aaron Crow (NaN:00NaN) Yeah. And, and man, it's, it's really the sky's the limit. I know you and I've talked about a lot of things that, um, aren't, aren't there yet, um, but you know, the sky's the limit of where, where we can take this, right. And this, the overarching AI and, you know, I wrote an article the other day and posted it around, you know, what, what is OT going to be like? And how do we incorporate AI and how do we make people feel comfortable? Because it's just like anything. It's, it's the difference of, oh, you know, I don't want to have a car. I'd rather just stay with my horse. Right.
Aaron Crow (NaN:00NaN) You know, those people are long gone, right? As much as I, and I grew up riding horses, but I was not doing it for transportation. I was doing it because I liked riding horses. I definitely would rather get in my dad's, you know, 77 Chevy pickup to go to the store because it's a heck of a lot faster and I can haul a lot more stuff. And you know, it's a lot more comfortable ride, even in that old truck. It was a lot more comfortable with my horse. I love my horse, but it's not the same. So even with this, like an OT,
Aaron Crow (NaN:00NaN) there's, there's no doubt in my mind that OT is going to get brought into, or AI is going to get brought into OT. It's just a matter of how do I do it in an intelligent way. And I know you and I are, you know, looking at some of that and working on some of that, but some of that is, you know, making it be on prem, making it be, you know, uh, have confirmation by a real operator. So I'm not necessarily taking action in blind, especially in the beginning, until I believe it, until I've grown this thing.
Aaron Crow (NaN:00NaN) to a place that, you know, the operator feels comfortable, or maybe never, maybe never is a relatively long term, but you know, in the foreseeable future, maybe that's not even my focus. Maybe I'm just saying, how can I get decisions and ideas and data in front of my operator faster? AI and the ability for it to be able to look at this data and make a decision or narrow things down, which I know you and I've been working on a lot, right? How can I just get it to narrow down to, it's one of these five things.
Aaron Crow (NaN:00NaN) these things instead of the list of 8,000. Just look at these five. Like tell me which one of these you think it is right? That's hugely powerful for you to be able to make a decision as a human because I know what I know about my plant and now it's just narrowed it down. So it helped me make a decision and choose from a smaller list that and that's hugely valuable.
Aaron Crow (NaN:00NaN) And I'll give you a transcript of all this and I'll give you the audio of this or the video of this as well, so.
Aaron Crow (NaN:00NaN) Mm-hmm.
Aaron Crow (NaN:00NaN) Yeah, I mean, obviously that that's a good point to talk about, right? And how do we, and that's just basic cyber hygiene. It's basic, you know, data, you know, exfiltration, where do I put my data? It's no different than, you know, putting data in GitLab or GitHub and what data can I put there just because it's there in my environment doesn't mean I should, you know, I've got to be careful with that as a, as a, as a consultant or whatever my role is.
Aaron Crow (NaN:00NaN) My customer may not want their data in that location for obvious reasons, right? For the same, same purpose, right? It's, it's the same concept we've done with GitLab. We're sharing content, we're sharing code, we're sharing all this different stuff. We just don't want to put, you know, customer proprietary information up there. Same thing you wouldn't want to do in GitLab. Same thing you wouldn't want to do in, you know, uh, open AI, right? But then the other piece to that is that, and you and I've been working on some of this, right, is there's also local language models.
Aaron Crow (NaN:00NaN) right there you can pull those things out of the cloud and run them on your machine right so with gpus with just normal computers not even something that's got some crazy amount of gpus on my laptop i can run a llama and all these different uh you know language models right on my machine so i'm not exfiltrating the data the stuff is local it's running on my on my site on prem so i know a lot of the ot stuff they're like oh yeah well we don't put stuff in the cloud
Aaron Crow (NaN:00NaN) Okay, but this is another way you can do it. You can do that same thing, those same language models that you're getting. Now, it's not the same for same, right? Obviously you get the benefit of the larger training data set on a large model like OpenAI. If I'm doing ChatGTB4, it's gonna have this huge thing of all these people's trained data that it's been doing and scouring the internet and it's got Dolly and I can create images and it can search the internet, all that kind of stuff.
Aaron Crow (NaN:00NaN) I'm going to be limited. It's not the same for same, but I can still do local stuff and create like auto tabletop and other, other like products that I can actually do things locally. So I'm not sending my data to the cloud. It's all on my computer, right? And it's not going anywhere.
Aaron Crow (NaN:00NaN) Right. Yeah. And that's hugely powerful. I mean, the sky's the limit with that. Again, I go back to the scenario we were talking about before, whether it be auto tabletop or I can feed it architecture diagrams. Well, I don't want to get feed, you know, that across the internet to open AI. Okay. So don't like you can do that locally. Um, you can, you can start feeding it, you know, uh, the architecture, the, the build types and, and configurations may be even. So when we're doing these tabletops,
Aaron Crow (NaN:00NaN) you're actually able to give it, you know, actual log exports from, from a type of device and, you know, PCAP, maybe you can feed it a PCAP of, this is some data that we have in our environment. This is what the inject looks like. You know, uh, all these different things become possible and you're not worried about your data getting out there. You're not worried about my architecture or, you know, some, some China or, or bad actor getting my data and knowing what my attack vectors are, because now they just got, they saw my
Aaron Crow (NaN:00NaN) saw my tabletop exercise. So now they know where you know, all my, all my, my weaknesses are right. So that, that you can do this in a, in a, in a powerful way, get the benefit without the risk. So it's just a matter of how you want to do it and what's important to you. But to your point on, on the IT side of the house, you're already doing this. Like you already have all your stuff in the cloud. You already are using all these cloud based services. Maybe OT is a little different, but on the IT side,
Aaron Crow (NaN:00NaN) we're already doing these things and we have been for years. Like we've been in cloud and online and, and edge and all this type of stuff for forever. And it's not going away. So I think we're more comfortable on the IT side of the house than the OT, but I can see both of them being valuable.
Aaron Crow (NaN:00NaN) Right.
Aaron Crow (NaN:00NaN) Yeah, and I think that's gonna be more so around how do I get comfortable, right? And a lot of this is fear of the unknown, right? I'm scared of what I don't know, I'm scared of, you know, I don't understand how this AI thing works. I remember, it must've been 2010, when one of the control vendors was rolling out remote VMware, you know, virtualization, and using virtualization, having a VM instance to be an engineering workstation.
Aaron Crow (NaN:00NaN) And I was trying to explain to an operator and an engineer, a plant, you know, control system engineer, the concept of virtualization and where the server lives. And even though the server is over here, I'm going to access it over there. But it's not secure mode access, it's different. And that whole concept was beyond what they could understand because they'd never been exposed to virtualization. Now,
Aaron Crow (NaN:00NaN) Virtualization is used all over the place in OT. Everybody understands it. It's not scary. They have virtual control processors and field IO and all this different stuff. It's become a thing. But even at that point, this was again, like 2010, virtualization was not new in 2010. Virtualization has been around for a long time. IT has been using it for 30 years. But in OT, we're probably 20 years behind them, right? So I think the same probably adoption rate is gonna be here.
Aaron Crow (NaN:00NaN) And obviously there's a reason for that, that caution and OT, right? You know, obviously the impacts are bigger. Um, I'm dealing with death. I'm dealing with, you know, life. I'm dealing with safety. I'm dealing with availability of my lights, our internet, our infrastructure. There's a reason we've got to go a little slower and make sure that we fully understand the ramifications of the actions that we're doing. Um, but, but it doesn't mean it's not coming. So you can't just say we're never going to do that because it is coming.
Aaron Crow (NaN:00NaN) You need to start thinking about it. You need to start thinking about what would make me feel comfortable. What do I, what are the check boxes that they would have to do for me to feel comfortable to do this in my space and how could I do it, you know, and phase it in instead of it, just getting rammed down my throat in 10 years, because that's my only option.
Aaron Crow (NaN:00NaN) Hehehe
Aaron Crow (NaN:00NaN) Yeah.
Aaron Crow (NaN:00NaN) Yeah. Yep.
Aaron Crow (NaN:00NaN) Absolutely. I mean, you know, day to day basis, I use it to, you know, I'll write an article, but instead of worrying about, you know, sentence structure and fragments and any of that, I just flow. Like I'll go through and I'll say, this is what I want to talk. I want to talk about this. And, and I just start writing out notes, like just, just as it flows out of my head and you know, this topic and that topic and this thing and that thing. And I just go, cause I don't have to worry about this goes before that or any of that kind of stuff. And then I can put that and kind of
Aaron Crow (NaN:00NaN) build it into strat. This is what I want to say. And then I can post that into chat GPT. I'm not getting chat GPT to write anything for me. I'm writing it. I'm just getting it to reword it, to put it in a structure that makes sense. I can say, Hey, make sure that we're using this language. You know, so I've, I've trained it. I've built a custom GPT for me using the language, the way that I speak, the words that I use, like, cause I don't want to come across using words that I never use in conversation. It does it. It's getting better. Sometimes it does.
Aaron Crow (NaN:00NaN) But right. Yeah.
Aaron Crow (NaN:00NaN) Correct. Exactly.
Aaron Crow (NaN:00NaN) Yep. Yeah. And it could be a powerful tool. It's just like anything, right? It's what you do with it, right? And how you wield it. Um, and you can use it to be a powerful thing. Like my kids are in school and you know, uh, the conversations with the teachers, like how do they have, how do they make them write an article or a paper or things like that? Like, okay, well, you know, they're going to put it through AI.
Aaron Crow (NaN:00NaN) Okay, so
Aaron Crow (NaN:00NaN) I still have to put thoughts into what I want it to say and what I want it to do. I can't just say, Hey, chat, GDP, write me an article. Like I can, but it's going to be the quality of a junior level person. Right. If I wanted to actually have some meat and some value, I'm going to have to write the article and then I allow it to do what the junior person would do. Hey, go fix the center structure, go fix the typos, you know, go make the fonts the correct way, you know, put it in a format that I want it to be in. Here's my template.
Aaron Crow (NaN:00NaN) like doing all of those little menial tasks that I don't need to spend my time and focus my effort on. It's the same thing with this podcast, this platform that I use, it automatically transcribes the transcripts. Like it does all of the, you know, speaker A, speaker B, I can actually take this transcript and I can delete the words in the transcript and it cuts that part out. So I'm editing by just deleting words and sentences and paragraphs out of the transcript, it deletes that content from the podcast.
Aaron Crow (NaN:00NaN) So before I was having to go to an editor and do it, I still send it to an editor. But when I send it to them, I've already cut out the things that I don't want in there. So then they're just fixing auto tones and some of that type of stuff and they're really polishing it. So it's not that editor is getting no work. It's that they don't have to do as much stuff. They can, I can outsource that to AI instead of a VA or a junior intern, that kind of thing.
Aaron Crow (NaN:00NaN) So next, obviously we talked a little bit about this already, but next five to 10 years, what is coming up over the horizon? What's something you're excited about, obviously in AI, and maybe what's something that's concerning that you see maybe coming up the horizon that people, that we need to, as an industry, as a whole probably need to get a grip on before, before it's too late.
Aaron Crow (NaN:00NaN) Don't start me lying to you. I'm not the grammar guy. We got a couple of tech guys trying to talk grammar. That's why I have chat GPT. It tells me what's right.
Aaron Crow (NaN:00NaN) Sure. Yeah.
Aaron Crow (NaN:00NaN) That's right.
Aaron Crow (NaN:00NaN) Great power comes great. Yep.
Aaron Crow (NaN:00NaN) Yeah.
Aaron Crow (NaN:00NaN) Well, and you hit on something there that we're being hesitant to use it for good because we're afraid of what it can do, especially in OT, right? We're afraid of what it can do and how do we do it safely? The bad guys aren't, they don't care. They're going to use it right now to figure out how can they build something to get into these spaces, right? So they're already using it for their advantage to build, you know, the MVP, you know, that, that grant, that barrier of entry, like we talked about on the,
Aaron Crow (NaN:00NaN) I can build a platform. I can build a product. I don't know how to code, right? Let's say I've never, I can't write a script. I can't do anything. Like I'm, I'm a newbie. I can barely use my iPhone, but if I can talk to a GP GPT or, or some language model AI, and it can create some basic MVP for me enough that it can get the message across and then I can hand it to somebody that actually knows how to build something advanced, then they can take that idea and that basic concept and then grow it into an actual productive thing.
Aaron Crow (NaN:00NaN) it's able to bridge that gap that much faster. Cause sometimes that MVP is the hard part to get to, especially if you're a non-technical person and you're trying to do something technical, then you've got to hire somebody and you've got to get your message across, you've got to pay them, and you've got all these things that stop you from doing it. It's probably why a lot of ideas don't happen, but this is going to remove that barrier or at least reduce that barrier so that more and more people can do it. And that's good people and bad people.
Aaron Crow (NaN:00NaN) Good products and bad products, evil and good. So we've got to be able to use it for good and we need to be safe with it, but that doesn't mean we can just avoid it. I was just going to say, tell folks, how do they get to the tabletop? I know you're going to do these every Tuesday, I think you said, is when you're going to live stream them. How do people get access, find out more information about it and maybe even, obviously you've got a book coming up as well. So why don't you kind of share all that stuff? We'll put it in the show notes too, but go ahead and talk about it a bit.
Aaron Crow (NaN:00NaN) Awesome man. Hey, I appreciate all the work that you do. I think this is hugely valuable and beneficial to the greater good of, of humanity and OT and cybersecurity and all the different things. Uh, obviously I geek out with this stuff, as you know, and, and love digging into this stuff. So it's, it's a, it's a fun, exciting place to be. Um, it's a fun exciting thing that's coming up over the horizon. And, and, uh, I think a lot of folks are really excited to get their hands dirty and dig into this stuff cause they're, everybody sees the writing on the wall. This is the next.
Aaron Crow (NaN:00NaN) you know, gold mine, gold rush, whatever you want to say, coming that everybody needs to have this in their tool, their tool belt to be able to use this for whatever their role is, it's going to be an impact in all future capabilities. So I dig it, man. Yeah, 100%. Well, awesome Clint, thank you for coming. Appreciate your time today. And again, I'll put all the show notes then in the bottom. Until then, thanks everybody for coming. And until next time.
Aaron Crow (NaN:00NaN) Yep.
Clint (NaN:00NaN) Yeah, cool. Thanks for having me. And yeah, so about me, I'm a 25 plus year veteran in cybersecurity, United States Air Force veteran as well. It's where I got started, but been doing the cybersecurity thing for more than 25 years, been specializing in OTICS before we called it OT and ICS since about 2003 or something like that. I mean, kind of got introduced to it in the 90s, but really formally got into it in early 2000s and been doing
Clint (NaN:00NaN) pretty much OTICS, cybersecurity, solid, nonstop, since then never looked back, anything. I focused on the offensive side of things, mostly writing code, pen testing, development, but throughout consulting, as you know, you can't get away from the compliance and all the other, all the good stuff. So been doing pretty much that. So now I am the co-founder and CEO by default of ThreatGen, the cybersecurity gamification and simulation.
Clint (NaN:00NaN) company. And so if it matters, some of you may know that there may know me from my previous works in as one of the principal authors of hacking exposed industrial control systems in my upcoming book, which is cyber chat GPT for cyber security, which is not just chat GPT, it's just a buzzword. But yeah, so we'll just start there and go from there.
Clint (NaN:00NaN) Yeah, so yeah, we were using a platform that I just recently developed called auto tabletop. And the it was really cool because it was the very first that I know of live stream tabletop exercise and the product that I developed in this all started way back, I guess when large language models and generative AI
Clint (NaN:00NaN) first became a thing in late 2022. And this, the really kind of the beginning of that was, I was, and I've just backtrack a little bit more. So I've been working with AI for quite a long time anyway, and even early open AI products before anybody knew really the general public knew who open AI was. And this is because of the gamification product that,
Clint (NaN:00NaN) we'd been working on at Thretchen. So a lot of AI work there and stuff. And I've done a few presentations at conferences on AI and OT and stuff like that. And so it all started when I was with my kids working on, hey, can we do a D&D, a Dungeons and Dragons like kind of thing with AI? Can we have it automate this and all that? And then that naturally went into, wait a second.
Clint (NaN:00NaN) this is working pretty good. Can I use this for tabletops? Because, well, that's what a tabletop is, right? I mean, when you talk about IR tabletops, it's very much in the spirit and fashion of the D&D tabletop, Stegin's Dragons, and it's role playing. And so I developed an application of that through different techniques and different large language models of how can I turn this into something that can facilitate an IR tabletop automatically?
Clint (NaN:00NaN) And the reason why that's important and going back into why tabletops are important and, and some of their limitations is that anytime you have an incident response plan, which you should have all the time, whenever you get into the thick of it, whenever something happens, the bad thing happens, that's not the right time to see if it works, right. And so a lot of regulatory agencies or even non regulatory, but just compliance and standards are saying that, hey, you know, you should
Clint (NaN:00NaN) test your incident response plan, you need to exercise this. And the general recommendation is annually, which I am highly against. I mean, it's better than nothing, but you're not really gonna get that much out of it. And annually, all that's doing is checking a box for compliance. And you're not actually going to remember what your after action was. You're not gonna remember what needs to be changed. And so like anything that needs to be practiced once a year,
Clint (NaN:00NaN) isn't good enough. And so this needs to be practiced regularly. And you need to see actionable change actionable items and change. And so the problem is that with regular tabletops, the standard way of doing things, a lot of people use what PowerPoints and slides and Excel spreadsheets and those sorts of things. And they take
Clint (NaN:00NaN) a lot of time and resources to plan properly. And then you have to have somebody who's an expert come out and facilitate that and all this ends up being time and money, and all these things. So most companies don't have the capacity and the resources to do it more than once a year. So now with the advent of generative AI and large language models, we can build tools like auto tabletop that has
Clint (NaN:00NaN) very human like analytical capabilities, narrative capabilities. And for the most part, the entirety of human knowledge wrapped up into one model that this thing can automatically reference instantly. And so that's what we did. We were using auto tabletop to, for the most part, instantly and dynamically create a scenario based on some
Clint (NaN:00NaN) simple settings that we gave it to start and it played out the entire story, which was, you know, we were called upon to defend the Death Star from a rebel alliance cyber security attack. And it was, you know, that was the first time I'd done it live online streaming. I've done it at a couple of conferences and, but it even impressed me. It was really cool. It was
Clint (NaN:00NaN) It was scary how good it is. And then we also gave it voice capability. So not only does it generate the scenario and the injects and facilitate, run, and keep up with everything, it was also narrating it, narrating, narrating it to us via audible voice and in a very, I would say convincing accent and tone that sounds like somebody who could have been a commander on the Death Star. And so it was really engaging and it was, and in
Clint (NaN:00NaN) It was quick and it was easy and it was very accurate, I think. I mean, we don't know what your impression was, but it was very accurate.
Clint (NaN:00NaN) Yeah, it's not it's not chat GPT. So let's not get confused.
Clint (NaN:00NaN) Yeah.
Clint (NaN:00NaN) Yeah, and you hit on something also, which was the lack of limitations, right? And I think that's what makes it truly valuable and truly just, I keep saying truly, but that's what really makes it, I guess that increases the value because, with a pre-scripted set of N-checks or a scripted scenario, you have those limitations. And I think that limits.
Clint (NaN:00NaN) the learning in a way because you have a certain set of things that you are exercising. And if the participants try to go outside of those boundaries, you don't have an answer for it or you have to guide them back or your answer may not be accurate to their situation. Or what if you didn't plan it exactly properly and you always have that engineer, you always have that IT person, that manager that says
Clint (NaN:00NaN) Well, that would never happen in our situation because this and this and this. Oh, that can't happen because our system doesn't have that. So if you have a system that we can now utilize AI to generate everything, there are no limits now. Now somebody can try to throw you a curve ball and you're like, okay. Like somebody literally did. Somebody said, hey, well, where is Darth Vader during all of this? And we said, well, let's ask it. And it answered that, right? I mean, and it...
Clint (NaN:00NaN) And so you can't stump it, you can't trip it up. And then if you do have a situation where somebody says, well, that our system doesn't do that. So going back is that, okay, let's say we're not doing a Star Wars themed exercise. Let's say we are doing a theme that is more realistic to somebody's systems, which it can do as well. We were just having fun yesterday. But if we get into a situation, somebody says, well, that our system doesn't.
Clint (NaN:00NaN) look like that. It doesn't act like that. Well, then you just feed that information to the AI, the AI, the AI makes the adjustments and it says, Okay, well, we'll move forward accordingly. And so it takes away the limits of conversation and the injects, it takes away all limits. And there are no limitations now on what kind of questions you can ask what can be answered. And so I think that is the true value of where we are today.
Clint (NaN:00NaN) Can you hear my dog barking by the way? Cause I know you're gonna have to cut this, but could you hear the dog barking? Yeah. Hold on real quick. Just, I know you're gonna have to edit this. Hold on real quick.
Clint (NaN:00NaN) I really need her.
Clint (NaN:00NaN) All right, getting back to what I was saying. Yeah.
Clint (NaN:00NaN) I forgot what I was saying.
Clint (NaN:00NaN) Yeah.
Clint (NaN:00NaN) Right.
Clint (NaN:00NaN) Yeah, exactly. And I think that's where the problem of tabletops really kind of start is that it is so scripted and they're so structured and it takes so long to plan is that there are limitations in the discussions that you can have because there's limitations in the questions you can ask or the knowledge. And it's, you know, you have to have that expertise, not only from the staff participating, but from the person running it as well. And so
Clint (NaN:00NaN) It takes away that, and you said earlier, the barrier to entry, because now the team itself can just say, well, here's what we're going to do. Here's what we're going to run, whether it's a, we want to run the specific scenario or surprise us and here's our environment now go. And even from an IR expertise perspective, you can have the AI itself, make sure that you were following the identify.
Clint (NaN:00NaN) classify, isolate, eradicate, recover steps of IR and even explain that to you. It can help you along and it is an expert. It does know all the things that a human would know about IR and cybersecurity and such. And so, let me, you have expertise built in.
Clint (NaN:00NaN) Yeah.
Clint (NaN:00NaN) Right, and that's one of the benefits of using AI-based tabletops. And the reason I'm not really just gonna sit here and say, you know, auto tabletop, auto tabletop, you know, Threat Gen, because I'm not trying to make this a sales presentation. I'm just, I'm an advocate for the use of AI technologies and cybersecurity. And the auto tabletop just happens to be the product that I developed based off of it. But the benefits of using AI are, and for tabletops,
Clint (NaN:00NaN) is like what you just said, but to add to that a bit is that all of these things that you can do, this limitless capability can be done instantly to start a new one. So I've done this for customers to where we would do one, it would take an hour or so, and then we would spin up a completely different one right afterwards. And then we would do one day, we would do one for the junior people and the engineers. And then another day we would do one or that afternoon, we would do one tailored for management. And so
Clint (NaN:00NaN) it takes away that because it doesn't take any time to set up because it's unlimited potential, you could run one right after the other. And one of the things that I noticed that I'd never seen before is we ran a couple of tabletops in the morning on one day, ran one in the afternoon, then the next day we ran a couple more. And by the time we were done, I was, or by the time we got to the last one, which was kind of called the final test, right? We threw the kitchen sink at them. And
Clint (NaN:00NaN) They were already improved. They were using lessons learned and techniques that they had gotten bitten by from the first and second ones a day prior. They had already improved. You are not going to see that at all with a once a year annual tabletop. And that is the big thing. That is why I hate annual tabletops because you don't have noticeable improvement. There's really no gain from it other than saying, okay, our IR plan works in theory, but.
Clint (NaN:00NaN) being able to just do boom, one after the other and change up scenarios is I have literally seen it 100% of the time to where people see noticeable improvement from the beginning to the end because you can do them right in a row and you can exercise so many things. And you know, another benefit of it is, well, what if you're not doing a cyber IR? So for example, I have a friend of mine who wants to do this for
Clint (NaN:00NaN) the like emergency response, incident response for pipelines, not even cybersecurity related. So, you're not limited to cybersecurity. Basically you can test the efficacy of any process, any procedure that you have using generative AI technology.
Clint (NaN:00NaN) toward what I'm gonna say next.
Clint (NaN:00NaN) Hold on just a second, let me bring that up because what I'm gonna say next, I need to record my notes. Come on, hurry up, hurry up. I need to record my notes.
Clint (NaN:00NaN) Okay, okay. All right.
Clint (NaN:00NaN) And there we go.
Clint (NaN:00NaN) All right. Yeah, and the reason, okay, so.
Clint (NaN:00NaN) Yeah, so let's pivot real quick and talk about that aspect, which is, look, AI is coming. It's inevitable, whether you want it to or not, right? Just kind of like, you know, like ITOT convergence, right? It's coming whether you like it or not. You know, SCADA in the cloud, you know, it's all these things that people don't want. They're going to happen, virtualization. It's going to happen, it's happening. So let's talk real quick about
Clint (NaN:00NaN) some of the misconceptions that people have with AI in the industry and the pitfalls. And I'm not talking about the existential threat of this is how you get terminators. But, you know, there are some misconceptions that people have that are causing some unsubstantiated fears of AI in their industry and their companies. There are some valid concerns. And so let's talk real quick about
Clint (NaN:00NaN) you know, what are some of the concerns? Are they valid or not? And then how can we protect ourselves against adversaries using AI? Or how can we use AI effectively in our companies, organizations and our industry effectively and safely? And so I think one of the big things is right now, a lot of organizations are scared of using AI.
Clint (NaN:00NaN) because of the claims, and then some of these are valid, that their data was used in training in the OpenAI models. And so we're like, well, I don't want my sensitive information exposed. So company policy, you don't use chat GPT, da da. Okay, so let's talk about this for a minute. So first of all, people need to understand that chat GPT is the consumer-based web interface
Clint (NaN:00NaN) for the OpenAI models. And so that information, while you can opt out by default, that information is saved. That's how whenever you go to the chat GPT interface and you can click on your conversations because it's saved out there. It's saved. And the data, even if you opt out, can be saved for up to 30 days. And then if you don't opt out,
Clint (NaN:00NaN) that data can be used for training. And that's where people start to see their private data used in the models. But you should know that Chad GPT aside, but OpenAI, the backend, the LLMs, and building apps on top of it, using the API, they are audited for SOC 2 compliance and they are GDPR compliant. And data, if you're using the Teams data,
Clint (NaN:00NaN) if, sorry, if you're using the Teams version of OpenAI of ChachiPT, if you are using the enterprise version or if you're using the API, okay, that data is not used for training. If you are building an application on top of the API, that data is not saved anywhere unless the app builder saves it. That data is not used for training. Whenever you make inferences, meaning if I have a prompt,
Clint (NaN:00NaN) and I put data into the prompt and I send it to the OpenAI large language model for inference to query it. Yes, it is going across the internet encrypted and it hits the cloud. It hits the model and then it makes that inference and then you get the information back that data is then it disappears into the ether that prompt is not saved anywhere. So there is a
Clint (NaN:00NaN) there is a slight risk when you take that data and you send it across the internet to make the inference and then it disappears. Even it is encrypted. So what does that mean? That means that you have the same data in transit, security and privacy that you have whenever you're storing all that data in your SharePoint or any, any.
Clint (NaN:00NaN) thing that you have in your organization that has a cloud-based infrastructure, like AWS, Azure, SharePoint, if you're storing that data anywhere other than on premises, and by the way, if you have a site to site, if you have an office in Georgia and an office in Houston, guess what? That data is still going out there somewhere. If I'm sharing it at all, and so that's what we're seeing. Now the difference is,
Clint (NaN:00NaN) is that if that data is going, if I'm not saving that data anywhere, it's being transmitted, but then it disappears if I'm only saving it locally. So it's actually more secure than if you're using any type of file sharing services, data transmission, things like that. So if you are a company that is using any type of cloud infrastructure, it's no different. It really is, it's no different. And so...
Clint (NaN:00NaN) That's what you have to be aware of from a data inference, data storage, data transit, when you're talking about these large language models. Now, how much can we trust what OpenAI is saying about your data isn't stored, it's not used for training or whatever? Well, that's the question, isn't. But that's also the, we signed that trust contract when we use cloud services anyway, anywhere. So I don't know, do you have any comments or anything to say on that?
Clint (NaN:00NaN) Well...
Clint (NaN:00NaN) Right, and that's where I was gonna go next is that, yes, there are large language models. You can use large language models that are local, open source, and this technology is moving so fast. Right now, the general consensus is that open source is about six months behind your best models in open AI. What that means is that, and yes, the quality of GPT-4
Clint (NaN:00NaN) say you're open source, llama, llama two, whatever, but that's gonna change. And that's gonna change very fast. And as time goes on, you will have that same quality and it's very close anyway you'll find, but you can also fine tune local models. And what that means is that I can take question and answer sets. I can take, I can basically create data.
Clint (NaN:00NaN) that is specific to what I'm gonna use the model for, I can fine tune it, create another variation of that open source local model. And what research is showing is that fine tuned versions of the top quality open source models are actually as good at your best quality like GPT-4 in that particular domain. And that's because, you're not...
Clint (NaN:00NaN) It doesn't have to, well, basically long story short, what happens is that the number of weights, the number of transformers, the number of, let's just call them this, the parameters we'll call them. But the open source models weren't trained with as many CPUs, with as many resources. And so,
Clint (NaN:00NaN) They're not as good at looking at the broad scale, that broad knowledge base, that data set within that model and making the proper inferences. So their weights aren't as good. Anyway, just long story short, because of that reason, they're not as good. However, when you fine tune a model for a specific task, it doesn't have to then comb through all that data in general to find the answer you're looking for. So the open source models,
Clint (NaN:00NaN) are just as good as the top quality models once they're fine tuned for a specific task. So, and that's really what you're gonna be doing when it comes to OTE and cybersecurity and stuff like that. So yes, you can absolutely benefit from artificial intelligence, generative AI, large language models, completely private, locally, and your data never leaving your site.
Clint (NaN:00NaN) Yeah, I mean, as time goes on, I mean, look, you know, there are people already doing things like skater in the cloud. I mean, technically, if you think about it, what the nature of skater is, you know, unless you're using, you know, point to point frame relays and things like that, I mean, that data is traveling, you know, over the you know, you know, unless you're point to point satellite and things like that. I mean, in a lot of cases, that data is traveling over the internet, right? I mean, remote communications. And so
Clint (NaN:00NaN) but there are people that are moving to that. And so I think at some point, there is going to be a certain amount of data from OT that is accepted in cloud infrastructure.
Clint (NaN:00NaN) Yep.
Clint (NaN:00NaN) Yeah.
Clint (NaN:00NaN) Right, yeah, and that's just saying, and I'll echo what you said, rightfully so. Yeah, we're worried about it, and rightfully so. And of course, I'm only speculating. Obviously, I'm not saying, okay, I said it, but I don't mean like it's going to happen whether you like it or not. I'm saying more than likely, history would show that technology will evolve into these things that we're uncomfortable with, but we'll find a way to do it. But that's where we are with AI, right, across the board, in that everybody's sort of
Clint (NaN:00NaN) afraid of what is this AI mean? You know, what are the risks? And, you know, there is a risk of and what I don't really want to, you know, we probably should not put this in scope here. But, you know, in terms of prompt injection, large language model injection, right to get data, you don't have to worry about that if you're using open source private models locally only. And so that's the solution to that. And then I think that once you get into the conversation of
Clint (NaN:00NaN) we can use local models, completely private, nothing going out anywhere, then the risk of prompt injection remote access, our data being exposed significantly diminishes in some cases completely. And depending on how well you secure your onsite data from any remote access. But at that point,
Clint (NaN:00NaN) that's where we can start to fully take advantage of the benefits of generative AI, large language technology. And I think that everyone should. I think that the benefits of the ability for AI to enhance human capabilities exponentially, the analytics capabilities, the reasoning capabilities, the search capabilities and what it can do can actually
Clint (NaN:00NaN) make our industry organizations more efficient and not even get into the conversations of, well, it's gonna replace jobs and da da. No, that's a ways off. We're not even gonna get into that. Would I trust, everybody says, well, not everybody, but I've had people tell me, oh, I wouldn't trust these large language models to make decisions that are, that's...
Clint (NaN:00NaN) you know, concerning human life and to make a split second process decision or whatever, you're already doing that, by the way. And what is process automation in the first place? And so, you know, I would say that, you know, once you have a really fine tuned model and once you have tested it and trained it, the large language model capabilities, the generative AI, the AI
Clint (NaN:00NaN) is actually less likely to make a mistake that a human would make. And so humans are prone to mistake too. And the difference is, is that AI doesn't have emotions and AI doesn't get sleepy. AI is not hung over. AI doesn't get sick. So it's, we'll get to the point to where we are trusting AI to make a lot of decisions and do these things more so than humans.
Clint (NaN:00NaN) if we can protect that data, if we can protect that, you know, the proprietary stuff and the sensitive data and all of that, then I would say that using where, using the capabilities of AI and where we're going, where it is today and where it's gonna be a year from now, six months from now, I think is a benefit. I think that everybody should be preparing to use AI to make things not only more productive, more efficient, but to make things safer and I think they can.
Clint (NaN:00NaN) Yep. Yeah.
Clint (NaN:00NaN) Yeah. Or just a first draft, right? I use it all the time to give me first drafts of things. But the thing is, is that, you know, I would say that, you know, this is scary for the workforce, but that generative AI can do those things that I would normally have an intern do or a junior person do a junior program or a junior engineer. So I think if it's going to affect anything in the workforce,
Clint (NaN:00NaN) it's going to make entry-level positions harder to get. So I think here's a clue, here's a hint people, in order to increase your chances of getting entry-level jobs in the future, learn generative AI, learn prompt engineering, learn how to use these tools.
Clint (NaN:00NaN) Yeah.
Clint (NaN:00NaN) Yeah.
Clint (NaN:00NaN) Right. Yep. Exactly.
Clint (NaN:00NaN) Yeah, you know, I think that...
Clint (NaN:00NaN) I'm not worried about like, you know, this existential threat that everybody, you know, you have some conspiracy theorists and there's two different camps, you know, quite frankly, I think that, you know,
Clint (NaN:00NaN) kind of what I said about AI and safety, right? I think if you eliminate human emotions and human spite and human, these negative human characteristics, you eliminate that. I think they could probably manage humans better than humans. I think they probably manage the environment better. They can manage everything better. So I think, yes, there's the argument of like, well, what if AI says that...
Clint (NaN:00NaN) The way to protect humans is to get rid of humans. The way to protect the environment is to get rid of humans. Well, you know what? Then so be it. I mean, if we're that terrible, then maybe we shouldn't be here. So I'm not worried about the existential threat. I think that the things that excite me about AI and it's my. I think is that.
Clint (NaN:00NaN) Just the level of human creativity will be enhanced. I think our capabilities will be enhanced because one thing that we have that AI probably will never have is experiential creativity. We can create from our experiences and our emotions, right? People can create from passion and love or hate or anger and fear and excitement.
Clint (NaN:00NaN) And we can create, we have the capacity to turn the intangible into art, into creativity. AI will probably never have that ability. And I don't know, I don't know how you express emotions digitally or, you know, in silicon and binary. But I would think that that's something that we have, that if we use AI as a tool.
Clint (NaN:00NaN) to be able to express creativity, express, like whether it's writing code or creating art or videos or music, if you use AI as a tool and it can work so fast and efficiently or whatever, and you use your own creativity and your emotion and your experiences as the motivation, the epitaph for, is that a word? Maybe impetus, maybe, I don't know, epitaphs, what? I can't. Um.
Clint (NaN:00NaN) Impetus, right? No, what's the word?
Clint (NaN:00NaN) No. Yeah, I don't. Anyway, you know, the beginning, right? You know? Yeah. So. Yeah, yeah. Yeah. So. So but a bit if you use that and you use the generative AI as a tool, then you're going to be able to create things that you couldn't create before you're going to something I know, and I know the artists don't want to hear this. But but if you if someone is inspired and they use these tools to do things.
Clint (NaN:00NaN) that they couldn't do before without a learning curve or skills, you can create amazing things, right? If I have an idea, but I don't know how to code, then I can get generative AI to help me with that and create these things. And so I think what happens is that the technical skills become less of a barrier. And now it's about creativity and thought and ideas.
Clint (NaN:00NaN) And I think that's going to accelerate human advancement. It's going to accelerate the thing. I think we're limited by our technology, but we have unlimited creativity and capability. And so I think that there's gonna be a complete shift in the next five years, maybe a year, two years, but definitely within the next five years and certainly in 10 years, we're gonna see a shift in technological evolution and we're going to see an increase.
Clint (NaN:00NaN) an exponential increase in development and capabilities, because we're gonna learn how to use AI, because it's gonna get better and better. We're gonna learn how to use AI to create things based off of our ideas a lot better, right? And so I think you're gonna see a lot of a lot of medical investments. You're gonna see, but on the other side, here's the fear part, right? You also have people that have negative inventions and innovations and.
Clint (NaN:00NaN) and motivations, right? And so just like we're gonna be able to take this amazing technology and create something good, faster and better, people are also gonna be able to create bad things faster and more efficiently. And so, but that's with every technology. Any technology that allows you to accelerate advancement in one way, it can be good and it can be bad.
Clint (NaN:00NaN) And so we just have to be aware of that. And so when people are afraid of AI wiping out humanity, it's not because AI will make a decision to wipe out humanity, it's because humanity will use AI to wipe out humanity. And so that's where the fear is, is that we, you know, the Spider-Man quote, right? You know, with great power comes great responsibility. And then there are some evil people out there and there are some stupid people out there. And when you mix stupid and evil,
Clint (NaN:00NaN) Kim Jong-un, North Korea. You know, then, you know, you know, bad things can happen. So that's the only thing I'm worried, I'm worried about what people will do. The technology is exciting. I'm not worried about the technology making a decision to wipe us out. We're gonna do some great things with this as it grows, but I just, I'm worried about just how stupid and evil some people can be with it. So it's gonna basically be, can we bridle ourselves?
Clint (NaN:00NaN) Yeah, exactly.
Clint (NaN:00NaN) Yep.
Clint (NaN:00NaN) Yeah, I think that, go ahead.
Clint (NaN:00NaN) Yeah, so I mean, real quick, I mean, if you just want to get a hold of me, the easy way to get ahold of me is find me on LinkedIn, my name, you know, which will be in the show notes is I'm the only one with my name in the world. So just reach out to me on LinkedIn. And that's the easiest way to get ahold of me. But yeah, I've got this new book coming out should be hit February, March, something like that, called Chad GPT for cybersecurity. It's not just chat GPT. So that'll talk about a lot of like how I'm leveraging and I'm teaching people how to leverage this technology for cybersecurity purposes.
Clint (NaN:00NaN) But yeah, you can go to YouTube and search for ThreatGen, G-E- on YouTube. And every Tuesday we do live streams of the AutoTableTop where we're doing that sort of thing. Our TableTops live streamed with that. You can also go to threatgen.com to learn more about kind of what we're doing with AI and the products that we have auto, you know, just letting you know, unfortunately AutoTableTop.
Clint (NaN:00NaN) is not an individual product. It's priced for companies because it is for tabletop exercises and things like that. But if you want to eval it, or if you're interested, you want to use it for education, just talk to me. I'll work with you. We'll figure, if this is something that's important to you, we'll figure out how to work it out. And then finally, my personal website is cybersuperhuman.ai, where I do live streams and I also have some courses where I teach people how to do this for cybersecurity.
Clint (NaN:00NaN) Yeah, it's absolutely necessary. Absolutely.
Clint (NaN:00NaN) Yep, thanks for having me and take care everybody
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.