What happens when AI meets cybersecurity - and the music industry?
In this eye-opening episode of Protect It All, host Aaron Crow sits down with Hadi Heidari, a cybersecurity veteran turned tech entrepreneur, to explore the groundbreaking (and sometimes risky) ways artificial intelligence is reshaping both digital defense and creative innovation.
From AI-driven SOC operations and threat detection to music creation, data privacy, and identity protection, Aaron and Hadi dive deep into how the same technologies fueling creativity are also rewriting the rules of cybersecurity.
You’ll discover:
Whether you’re protecting critical infrastructure or composing your next track, this episode will challenge how you think about creativity, ethics, and security in the AI era.
Tune in for an inspiring conversation that bridges tech and artistry, only on Protect It All.
Key Moments:
06:34 AI: Opportunities and Regulation Challenges
09:57 AI Risks: Data Privacy Challenges
11:03 AI Education for Security Awareness
15:50 "AI Risks in Cybersecurity Actions"
18:54 "AI Trust and IAM Policies"
21:13 AI Decision-Making Ethical Dilemma
27:19 AI Oversight and Quality Control
30:34 AI Ethics in Data Training
31:30 AI Ethics: Consent and Data Use
35:43 Detecting AI-Generated Fakes
37:59 AI, Security, and Challenges
42:33 AI Revolutionizing Security Analysis
47:14 "Learning Daily in Tech Space"
50:58 "Embracing Change in Music Industry"
About the guest :
Hadi Heidari is the founder of TunePact, an AI label service designed to support independent musicians. With over 20 years of experience in cybersecurity, Hadi’s journey into the music industry is an unusual one. While he continues to work as a governance and compliance advisor in cybersecurity, his move to Los Angeles inspired him to bridge his technical background with his passion for music. His unique blend of expertise in technology and creativity now helps empower indie artists in today’s digital landscape.
How to connect Hadi :
https://www.linkedin.com/in/hadihheidari/
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Please leave us a review on Apple/Spotify Podcasts:
Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
Aaron Crow (0:0.920): Thank you for joining me on another episode of the protected all podcast. I'm excited. This is a different conversation. you've got some different background and some different experiences. It kind of melds in multiple worlds, which is kind of a cool thing with, with music and cybersecurity and how that stuff ties together. So I'm excited for this conversation. So thank you for joining me today. Why don't you introduce yourself to the audience? Tell us a bit about who you are and, a little bit about your background as well.
Hadi (0:25.520): Hey Aaron, thanks for thanks so much for having me on your podcast. I really appreciate that. So this is Hadi, founder of TunePack, like AI label service for independent musician. But like mostly my background like falls into cybersecurity like 20 years. That's maybe interesting story of how I came to the music industry. I still in the cybersecurity space.
Hadi (0:53.074): advisor, on the like governance as well as compliance work and that space too. And I live in LA, so that's maybe explain why I'm the music industry too. So yeah, my heart is in the music and art and my brain is in tech, like so that's another story. So I was doing DJing for a while and like I saw lots of problems.
Aaron Crow (1:6.593): Yeah, for sure.
Hadi (1:22.376): like a music industry and I said okay maybe I can like bring some like value in this industry like helping the independent musicians there and my background tech and cyber cyber security definitely gonna help there so yeah oh yeah
Aaron Crow (1:42.402): That's awesome. Yeah, you know, it's such a different world, but if you think about it, right, you know, the creativeness and the analytical mind and all of that, they're so aligned. you know, we look at engineers and we think that they're logical and all those types of things. But, you know, some of the greatest engineers were very artistic in the way they design networks and the way they problem solve and all those steps. So those skills are so interchangeable if you know how to use them. Right. So
Aaron Crow (2:11.734): How did you get into cyber and music and all the things obviously being close, but you know, how does that all that intertwine into into your career and what got you to where you are today?
Hadi (2:20.856): OK, OK, cool. So like. How I get into the cyber secret space it was like I was like 20 years ago I was taking Cisco courses like a network at that time. So I was involved in a project and that project I had to work on firewalls like an and suddenly I saw that OK, that's a great space and I I could see that.
Aaron Crow (2:29.037): Mm-hmm.
Aaron Crow (2:34.797): Yep.
Hadi (2:49.426): there would be lots of like a opportunity later on, like 20 years ago and started like working on firewalls and like after that going to the one one reality assessment and after that going to the science space at that time, it was Cisco Mars. That was the first science that I could work or probably that was the first science like a like a introduced by Cisco at that time. So
Hadi (3:18.138): I hate to keep all the names, but brands. this is like explain me how I get into this space and what I did. So after that, after a while, after five, six years, decided to start my first company. I I could say my first startup offering some solution to the small businesses because small businesses have no budget.
Aaron Crow (3:39.683): Mm-hmm.
Hadi (3:47.549): going like having someone to take care of their server security. So we offer like a new service, like MSSB service for the small businesses that was really successful up to eight years ago that I decided to move to the U.S. And here like a focus on like a compliance, one-line assessment, as well as like a cloud security, like a stuff on AWS and Google. So.
Hadi (4:16.358): Yeah, and how I got to the music space. So while I was doing DJing and like vlogging for a while, I found that there are lots of issues on the like consumer side and also on the musician side. after like maybe five, six iterations and few of us, got to the solution called TunePack. That's the AI power label service. So imagine you like to like make a label service, but
Aaron Crow (4:28.738): Mm-hmm.
Hadi (4:45.212): like a SaaS and AI powered. I got to know my co-founder Cindy, she lives in Ohio and like we got to know each other and like she's a musician and a singer songwriter and label company there. So yeah, that's how I came to like a cyber security and like right now working on the music industry.
Aaron Crow (4:47.512): Mm-hmm.
Aaron Crow (5:9.282): That, that, is, that is so awesome. You know, it's, it's, it's funny. It's almost like every conversation I have now, on this podcast, even, even outside of the podcast, everybody's talking AI and how it interacts and, and where it's going to be used, where it's going to, you know, how it's going to, you know, displace people or change the way we do work and make us faster, more efficient, how bad actors are going to use it against us, you know, where are the risks and all those things are cool.
Aaron Crow (5:39.423): I see it as a, you know, the kind of the next internet, the next, you know, revolutionary product. I think it's going to take people that are looking at the problems and saying, Hey, it's coming. How are we going to use it? How are we going to get benefit out of it? so, so dive, let's dive into that. And like, obviously you're, you're looking at record labels and changing and using, cause I know some musicians and artists are really concerned and, you know, anxious about how AI is going to.
Aaron Crow (6:7.394): you know, take away from the music industry or make it less than. how are you feeling about the music industry, AI, cyber, kind of all of those things kind of rolled in together?
Hadi (6:10.482): Yeah.
Hadi (6:18.920): So definitely AI is going to bring lots of opportunities at the same time, lots of risk because it's a bit unknown space and we are not sure where we are going, especially when it comes to governance and compliance regulation. Already most regulation we have even in the cybersecurity or even the music space, they are not really aligned with what AI is going to bring and definitely need to be changed. So for example,
Hadi (6:47.462): When we are talking about GDPR, where we are talking about all the information or software compliance, all those things, it's about how you are going to control the data of the customers and consumers, how you want to get that information. But what we are dealing with a new problem is that consumers are giving the information.
Hadi (7:12.326): By themselves, without asking them, you are asking lots of personal questions. People are asking lots of personal questions to the AI without even AI asking them. So where we are in the regulation. So these are some constant risks. I wrote an article like two weeks ago about how like people are using like AI for their therapy and like late night they are saying, okay, I have this problem, how you can help me? So
Hadi (7:41.949): This sort of data that we are providing for the AI, we are not sure they are stored properly, they are analyzed properly, how maybe they're going to look like later on. So these are really concerned. So on the data, how data is getting stored on the silos, how they are managed and analyzed. And these are some issues that are concerned.
Hadi (8:7.302): When it comes to music, space is a little bit different. That's like a music is going to generate through the AI. That's I'm, I'm against that one because I would like to hear still human music. And, and I really respect the music that musicians generate and, but it's still happening like every day, every single day, every hour, like lots of musician getting like a offloaded streaming platform. So, and there is no really special rule.
Hadi (8:37.324): and compliance that restrict that about the monetization. There are some of them, but they're not really a tough rule that restrict monetization through that. And what I see, prongs and cons. So how are going to deal with those? Those are questions that we need to ask from ourselves, maybe experts in that area, and see how we can offer a solution for that.
Hadi (9:6.152): I was in Vegas last week. We were talking about, so when you are gathering those information, how you're going to make sure those information going to be good enough for, for example, the SOC, for your SOC, and how you want to use those for, automate your process to detect and isolate or remediate the issues. So, yeah.
Hadi (9:33.171): There are some concerns. think like the concerns are getting really advanced and like lots of people talking about it. And as it's a new, like it's some sort of new technology, we need to like take some time and see like how we can resolve the issue. So right now it's a big chaos, but I'm sure that like later on we can solve the problem like other problems that human could solve with that.
Aaron Crow (10:1.485): Yeah. Yeah. You know, it's, it's so, it's such a big, vast problem and it's one we obviously haven't solved in our, in our lifetime. It's a first time. It's a different problem than we never have to deal with before because everything is tying into AI, right? To your point, people are using it as their therapist and they're, they're, they're putting their family recipes in it. And, know, and then they're also putting, you know,
Aaron Crow (10:27.267): intimate details around their financial history and they're using it to help them budget or they're, know, all of this data is going into AI. And many people are doing it on the public versions of things instead of doing local models and all that. Obviously corporately there, you know, I see more and more folks that are moving towards, you know, private and local models and things like that, but there's still.
Aaron Crow (10:50.859): multiple examples of Microsoft Copilot that is just for that business, how that is being used to exfiltrate data or to bypass security controls because the AI, has embedded prompts in an email and Copilot is scrubbing emails it's coming through to give you the summary of all of your emails and that's used to get data out. So it's definitely a big problem, but just like with anything that we've had in our.
Aaron Crow (11:18.637): you know, history of, of mankind. That doesn't mean we can't, we can't solve it, right? It doesn't mean that we just throw it out because it's hard. It just means we have to constantly be looking at it and be intentional. you know, it's, it's a, you know, my parents are probably, they don't use it, but I can see elder, elderly, more elder folks that are less technical, technically savvy, putting things in AI that probably you and I would not.
Aaron Crow (11:44.771): because we know the inherent risks around those things and, and why we wouldn't want my financial, my social security number or my kids birthdays or any of that type of stuff in those types of environments, because it's not protected. It's not a great idea to put that stuff in there, but you know, really understanding. so do you see, do you see training and, and, and, kind of messaging around that for the general population as well as even just from a corporate organization, we're already doing cybersecurity awareness training for
Aaron Crow (12:13.785): phishing attacks and we're practicing that kind of stuff. Do you see that kind of coming across and from an AI perspective for training both on the corporate side, but also maybe even public awareness campaigns or something for people on Facebook or Instagram or whatever coming to help people to protect their identity and their information.
Hadi (12:34.268): So I would say it's gonna be a little bit difficult like a ruling, like giving like an instruction how to use the AI. It's a bit different than other like tools because they are seeing really like a advantage of using AI. So we cannot ignore that it's making the life easier for lots of like people like, okay, you can craft email, you can like make marketing planner. You can like,
Hadi (13:4.616): maybe you had to spend lots of time to generate something. like, but right now in like in five minutes, 10, they can generate those. can like save lots of time. So definitely like every sort of company should have some sort of like policies, how they gonna need, they need to use the AI and also the companies come with some plans how to like purchase some like a.
Hadi (13:31.195): like subscriptions for their employees to use the AI because on this URL, you don't need to ask your employee to spend hours and hours to sort a Google shit file or go ahead and make some planner. So regarding to that, I would say it's possible for the companies, but
Hadi (13:59.377): like asking people to stick to that policy gonna be a little bit difficult. for now, when it comes to the like people like individuals, it's gonna be more problem, I believe. like how we are going to like how we are going to train people like millions and billions of people out there to like apply.
Hadi (14:26.054): Like these are something you shouldn't put on your, on the AI. You shouldn't ask those things. Still, they are getting benefit from it. I think at that point, the regulation comes to the play, like comes to the game. We need to like apply those like a regulation on the AI companies, how you are gathering those information, how you are sanitizing those information from the user. And that's, I think that's would be more like a beneficial and
Hadi (14:53.990): like applicable when it comes to like individuals. But still people should really take care of themselves. So because it's like someone take your credit card and you are not sure that this guy gonna go ahead and like buy something without your permission or not. That's the same thing. Or someone has your social security number. Maybe that person gonna go ahead like take advantage of that number or not. These are the questions that like you need to ask first.
Hadi (15:23.324): before you are going to put your your paychecks on AI and say, okay, how I should analyze my paycheck or how you compare these two paychecks and et cetera things. So yeah, I believe we need to have that like sort of awareness, but definitely it's gonna be a little bit difficult like to like ask people not to do that because they are seeing lots of benefits from AI.
Aaron Crow (15:52.065): Yeah, and for sure, like I use AI daily, you know, throughout the day on many of the tasks that I'm doing. Now, obviously, I'm in cybersecurity, so I know I have a pretty good idea of what to include in AI and what to not include in AI and what to copy to a public website and things like that. know, it's not that hard, right? If you wouldn't put it on the Internet just generally, then you probably shouldn't post it into AI, right? You know, if you wouldn't...
Aaron Crow (16:21.049): put it up on the billboard at Starbucks, then, then you probably shouldn't put it into AI because you never know who's going to have access to that, that information and be able to tie it back to you as well.
Hadi (16:28.764): Yeah.
Hadi (16:32.056): Exactly. It may be even it's going to be more like a it's going to be bigger issue when you are dealing with the agent like AI. So they are going even take action based on the information it's getting. So that's going to be like a little bit more scary like scary there. Like when it comes to that, like a sort, for example, even in the SOC, for example, that I'm telling the SOC because
Hadi (17:1.028): I believe there are going to be lots of benefits from the AI for detecting and protecting the malicious atom. So if you are bringing some data and the MLs and LLMs are going to integrate it with the SAR and SIAM solution and based on that take some action.
Hadi (17:25.328): What if like there are some like the false positive and true negatives there. So based on that, go ahead and take some action. That's going to be like white. There's some IP that shouldn't be white listed or blocking some traffic that shouldn't be blocked or letting some traffic goes and like, or commanding. One of the things that I see a big, big, big deal in the cyber secret is the command and control.
Hadi (17:54.469): like issues like a malicious attempt. imagine like command and control can change themselves very fast in the era of AI because the command and like the controller can give a new instruction to the like to the malicious code like on the servers and like individuals computer and based on that, they cannot stop it really easily.
Hadi (18:23.718): They can change the protocol. They change the report. They change like it how they are behaving in the network. So that's going to be one of the biggest problem, I believe, in the new future.
Aaron Crow (18:35.575): Yeah, absolutely. And those agents are super powerful, but with great power comes great responsibility, right? You know, I've seen a lot of those. There's the agents now. can tie it into your social media. can auto respond to things. It can dive into your email. It can help you with all of these things, but you have to realize who you're giving that access to. It's no different than at a corporation that I have delegation of duties. I don't have one person that can
Aaron Crow (19:4.853): sign the check and is, is doing the books and all that kind of stuff, because that's how you, that's how people embezzle money, right? That's why I have a CFO and I have a different accounting department and I, I separate those duties. Same thing with administration of a domain controller. I don't have my normal account that I'm logging in on my laptop at Starbucks be the domain admin that I log into the domain controller with, because obviously that gives me rights that I shouldn't be using just to log into a, to a normal system. So.
Hadi (19:33.862): Yeah.
Aaron Crow (19:34.051): You know, that's where that's where it really grows and, can be to your point, right? It can be really powerful, but you just have to really understand what you're giving it access to and what the outcome or potential good and bad could be of that.
Hadi (19:48.689): You mentioned a great point. So when we are talking about AI, so we are trying to humanize, so like using data and humanizing, right? And to take some action. So we should behave the AI a little bit as a human too. Are you going to trust a person in a company who has access to all the information of the employees? Are you going to like trust a person to access all the information, security information, service security information?
Hadi (20:18.810): Are you going to give like a star access like to all the departments when you are bringing someone in? I would say no. So we should have really robust like IAM policy for the AI too. Like that's something we need to apply when we are dealing with this sort of like a looks like very like a neutralized, but they are not really neutralized. So I would say, yeah.
Aaron Crow (20:44.779): Agreed, yeah.
Hadi (20:46.776): I would say like we need to a little bit behave as a human when we are talking about AI. So how you are going to the access, what are the IEM policies that you are applying for, for the LLM models, for the ML. So yeah.
Aaron Crow (20:52.942): Yes.
Aaron Crow (21:4.973): Yeah, that's a great point. Like you should really treat this as another employee. And to your point, when I first hire somebody, I'm not making them top level admin in all departments and giving them access to everything, unfettered access with no restrictions, no whatsoever. You would never in a million years do that, right? You have to earn those levels and you only give them the access that they need. I'm not giving them domain admin. I'm giving them.
Aaron Crow (21:30.143): specific access to the things that they need access to. I'm not doing any, any rule on a firewall, right? I'm not doing those things because there's risks around those things, right? I don't do that for a human. I definitely shouldn't do that for an AI that is gonna do whatever the heck it's gonna do, right? So, and then all of that data then is it could be exfiltrated or used or even, you know, the other piece that we haven't really dove into when you talk about the SOC, the SOCs, right? Is, you know, it's great that I have this thing and I agree with you. think.
Aaron Crow (21:58.817): one of the biggest, the shortest term, biggest wins in our industry right now is going to be how can you use AI in a sock to help you find, mitigate and control, you know, an impact and incident, you know, a response, et cetera. Right. But with that, I have to be really careful because that's, I have to know to your point, right? What, what is it, what am I giving it access to and what controls and what responses because
Aaron Crow (22:23.885): You know, it's, the age old question. If I have to, you know, the, car analogy of, of, as, as we're treating AI or automation and cars, self-driving vehicles, and you have that conundrum of, I there's, there's only two ways. And on the left-hand side, I'm going to hit a bus full of kids. And on the right-hand side, I'm going to hit two old, old grandmas walking across the street. And I can only go left or right. It's only a binary choice. Which do I do? Neither of them are great options. Right. And.
Hadi (22:44.708): Exactly.
Aaron Crow (22:51.393): And that's where you would want a human to be in the loop, especially in the beginning until you know which direction, because you don't want them to hit one and then actually go over and hit the other. That'd be the worst case scenario, but which of those would you want? And if you don't have that thought process now, bad things can happen. And then you're like, well, I didn't think about that. I didn't know. And that's when that's, that's not where any of us want to be when, when we turn the lights on in the morning. Right.
Hadi (23:16.604): Yeah, that's a great point. when it comes to another thing that I would like, like, when I take a look on AI, not to like, like, think of as a like a one unique platform, we need to like, break it into the like, separate like elements that put together all of them and come to the AI things that we talked about.
Aaron Crow (23:41.497): Sure. Yep.
Hadi (23:42.685): So like how you are going to start from the data, where you are going to bring that data, how you're going to trust that data. If you are storing data, if someone can bring and add some data without your knowledge, without your permission, or they can manipulate the data. On the other side, how you are going to like use that data, how, what sort of algorithm you are going to use that data and convert to the ML and LLM.
Hadi (24:11.996): So when it comes to that point, if your algorithm gonna be like poison, gonna be like what by someone or something, it can be like a malicious or not. Maybe someone can change the algorithm. About the algorithm I gave the speech on the conference last year in Orange County that said, if you are using AI or prediction of the like a trade for trade marketing.
Hadi (24:41.810): So one day you get up and say, okay, why should I buy and sell today? So you ask the AI platform, we already really trust and say, go ahead and buy ABC and sell like a XYZ. You go ahead and do that. And millions of people gonna do that. Maybe some like you and you're gonna see, okay, that's gonna end up with a chaos.
Hadi (25:10.096): And the ABC that you already got it and you already bought that one, so all crashed. And XYZ already went up. So what's the issue? So someone maybe poisoned the algorithm or something like that that changed the whole story. Maybe that was done purposefully by someone, by an organization, by even a big organization out there. So it was done.
Hadi (25:39.731): So algorithm is really important. And on the other side, how it's going to decide, like how LLM is going to decide about what action it's going to take and how, if there are some way that you can like inject a prompt, that prompt going to take a weird action. These are all the questions we need to have answered. And eventually at the end, like a...
Aaron Crow (25:50.532): Yep.
Hadi (26:6.108): which sort of application you want to give access, where you want to integrate with every sort of application in your company, and how you want, if there are some people that supervising those application, this integration and stuff. So all of them like questions. We have no really clear answer up to the point using those and see how it reacts and how we can solve it there.
Aaron Crow (26:34.829): Yeah, man, that is so true. it really all comes down to AI is just like one step. It reminds me of almost the OSI model needs to be adjusted and adding AI at the top layer, right? Because all of the other things still need to happen, right? So I need to understand, and I spend a lot of time in OT, but also work in IT.
Aaron Crow (27:1.731): you know, how I respond or react to an incident or a problem, a system in an OT space, I may do it differently in an IT space. I may do it differently if it's just a temporary laptop in the, you know, an example, if you have a guest kiosk in your waiting room of your main facility and there's a bad thing that happens, you're probably going to lock it down, kick it off the network, all the things. If it's the CEO's laptop, you're probably not going to have the same response. Like it's going to be a different reaction than I'm going to have.
Hadi (27:28.360): That's gonna happen,
Aaron Crow (27:31.715): based on what that device is, what its function is, who owns it, all that kind of stuff. There's different implications of that thing, right? So we've got to know all that nuance in all the things that we do before we start turning an AI loose, because an AI will just say, hey, there's a problem. It's an issue. There's a windows machine that has a XYZ, you know, a malware or ransomware, whatever that thing may be, you know, shut the gates. And maybe that's the right answer, but sometimes it might not be. And you know, the, the, the OT analogy always give is like,
Aaron Crow (28:0.471): Okay, you found ransomware on an airplane. The airplane is 30,000 foot in the air. It's still flying and they're able to control it. Do you patch it and update it while it's in the air? Probably not. You probably land the plane, get everybody off the plane, and then you fix the problem. But you don't do it at 30,000 feet, right? You just don't. And AI, if you don't train the AI correctly, it could take immediate action because it prioritizes fixing the problem.
Aaron Crow (28:29.709): because it doesn't understand, if I do this, then there could be these other implications and bring the airplane down. And then I've lost human life. I've, or, you know, we just saw UPS airplane crash the other day, not saying it was a cyber incident. I'm just saying that's the type of worst case scenario. Big booms. That's nobody wants that.
Hadi (28:48.680): Exactly. Regarding to this issue, you brought a really, really big question. Is that if the AI works perfectly fine, what's going to do in different situations? So I think in the near future, so still maybe we have, but maybe I'm not aware of, we're going to have some people as a quality controller for the AI.
Hadi (29:16.892): who like every after every sort of patch, every sort of update, every sort of like a new model, they have to go ahead and check all the things behind the scene, make sure that AI like works perfectly fine. So give them some prompt, weird prompt and see how it reacts. Like I really like the OS Top 10 like a new like for the LLM application.
Hadi (29:43.133): really good. It covers almost all the things that right now we are discussing like from the prompt injection, insecure output handling, training data poisoning, model denial of service. So denial of service can be a big deal. So when we are dealing with billions of data out there, so how it's going to react when lots of people are sending and lots of information.
Hadi (30:10.600): prompt your to the AI model. So because maybe that model is taking a really serious action. If you try to do this and did us that like that AI model, what's going to happen then? So I believe like these sort of like job opportunities, opportunities gonna come up very fast. Or maybe maybe the big companies already have that.
Hadi (30:35.004): So only for doing the test and making sure that the AI works perfectly fine and there is no false positive there.
Aaron Crow (30:43.043): Yeah, there has to be a process, right? So we, we test out patches. We, put them in, we have this rollout procedure. Like we, we validate that everything is functioning and everything is still good to your point. We're going to have to do the same thing. The more and more integrated we get with AI, we're going to have to make sure that, we made these changes. Is there any impact to the AI and the, the, response and the, the prompts, cetera? because it becomes part of the critical path of our.
Aaron Crow (31:13.005): you know, functionality and of our system, really, if you really it's it's part of the overall system of my business now that I'm using AI in this way, I need to make sure that I'm testing it adequately. And right now, I think many don't don't understand enough of their environment and how they're implementing and integrating these things to really have that big picture. Right. And I think that's the we're on that bleeding edge. People are wanting to get the benefit out of AI because it can be so powerful.
Aaron Crow (31:41.401): but they're taking a lot of risks. I fear just like in many times, they're accepting risk only because they don't truly understand how risky it is. So they're making decisions, yeah, that's fine. We'll accept that risk. And then they implement it. then hopefully not, but what I've seen in the past, and I'm sure you have as well, we don't start changing until something bad happens and makes the front page of the news. And then everybody's like, whoa.
Aaron Crow (32:8.695): We should look at this and make sure we're not doing that in our space because I don't want that to happen here.
Hadi (32:15.432): Cool, yeah. The other thing that I wanted to add to your point is that, okay, lots of like when we are going to as organization, we are going to use the AI, how, other than the policy and stuff, because it comes to my mind when it, because I'm in the music space too, like...
Hadi (32:41.368): How ethic is that like a train gore model of some data is available out there like you can use, but it's not ethic like training your model of your of the like it's out of the security cyber security style, but it's a little bit. That's I would like to mention to like a you work on something for years and years and bring it as an article. So like a.
Hadi (33:10.630): like in 20 pages and in a minute, like AI can like, can get it and use it for training or like can make money off of it. So is it something that you would like to happen? How are we going to restrict that to it's the same thing for the music. If you are going to use some of these, like a AI model that generate music, they already got all the music from the streaming platform and
Hadi (33:38.221): Right now they are making music like using those and where we gonna go? Do we need to like give all the information to the AI purposely or the AI model gonna get that information without like getting any sort of permission because the crawler can like crawl every sort of website. The bots got
Hadi (34:2.696): and take a look at a scan your website, your articles, and they are really good at that, right? And converted something else. So these are other problem I see in this space that maybe they are not like it doesn't need to cover the cyber security. But it's something like comes to my mind I need to mention because we need to have some sort of consent when they are using like your information, your data.
Aaron Crow (34:8.537): Yeah. Yep.
Aaron Crow (34:31.257): Yep. Yeah. Agreed. Yeah. That's very, very true. And, and really, you know, it really changes AI changes how we approach problems in a good way. And also on the, on the risk side as well, right. As you know, to your point, music industry, you know, they're talking about it at the same way in the movie industry, like how, I think it was, gosh, Bruce Willis.
Aaron Crow (34:57.891): Just sold his likeness because of his medical condition, his likeness to AI so they can use that in the future. And obviously a lot of talented artists are concerned because they don't want their likeness being used by AI. They're also don't want an entire industry to crash because, I can just make things in AI. It doesn't have to be real. There's definitely a risk to those things, but to your point, I think there's a pro and a con. We just have to know.
Aaron Crow (35:26.733): You know, to your point as well, like, you know, who owns the rights to the data? and, and did you have a right to build your model off of that? You know, I think there was a, another one where the voice lightness of, think it's Scarlett Johansson, like her voice was used in some commercial or something, or they asked if they could use her voice in a commercial. She said no. And then they had AI create one that sounded kind of like her or almost exactly like her. Like it really sounded like her, but it wasn't her.
Hadi (35:53.256): Yeah.
Aaron Crow (35:54.797): Right. So they, they were trying to skirt around having to pay for her and get her permission because he was AI generated, but how did AI generate it? Because they used her voice in, training it to make it sound as close as possible to that. And it's, it's amazing how well it does. Now I did that for a buddy with his permission. I was doing a marketing ad thing and I took a buddy of mine's voice. he's got a real raspy voice. so I took like five minutes of him reading something in a podcast or something like that.
Aaron Crow (36:24.279): and created an AI chat agent for a website using him as the voice. And it's not perfect. You can definitely tell it's not him, but it's close enough that if you know him, you'd be like, wait, is that, is that Pat? It sounds kind of like Pat, not exactly, but it, man, that sounds like Pat. you know, it's like a long lost friend thing. It's like, man, is that him? Like, so.
Aaron Crow (36:47.673): There's a lot of that that's going to come up with licensing and rights to data and who owns what, and if it's created in AI or if it's created in the public space and that gets to all data, not just music, not just voice, not just video. You see all these, these, these fakes coming up now with video and, advertisements that are coming up from, you know, people like Joe Rogan that, know, he, I think they did an interview with him and, the Apple creator, whatever Apple guy, can't think of his name on the line. Steve jobs.
Hadi (37:0.264): Yeah.
Aaron Crow (37:17.977): an interview with him and Steve jobs, he never interviewed Steve jobs. So they just, and he talks about it. He's like, I never did. I never interviewed Steve jobs, but that's a, and he's also been talking a lot about the music industry and how some of the, they've taken like 50 cent, a song for 50 cent and made it in a blues song by this, this AI using all the, and it sounds amazing. I'm using his lyrics, but again, it's not a 50 cent song.
Hadi (37:22.162): Ha ha ha ha.
Hadi (37:39.548): Sounds amazing, right? Yeah.
Hadi (37:43.625): Yeah, one of the thing that sometimes my wife and I like sent to each other say, okay, which one do you think that's real? Which one is not like that? And it's really difficult even like for some expert difficult to understand which one of these are real and which one of the big. So that's being said, I believe there's another role gonna come up like a fake, like AI generated, like a detector or something.
Aaron Crow (37:51.151): You're right.
Hadi (38:11.404): that's his or her job gonna be like, go ahead and take a look all the videos, all the songs and which one of them are gonna be like, for example, imagine we can talk about like a physical thing. if you have like, if someone has a fake US passport, maybe like a detect or someone who's really like know how to detect that one gonna be able to find.
Hadi (38:40.582): that one, the fake ones, the same thing maybe for the AI. Because right now it's AI is getting advanced and we cannot stop it. Especially with content video, for example, someone like clone or fake CEO of a big company there and for taking any action. So what, how are we going to like go ahead and make sure that's the fake or not? And that brings another solution. Okay.
Aaron Crow (39:5.967): Mm-hmm.
Hadi (39:8.850): how are you gonna take action? Or only for example, before that if like Aaron called me say, Hadi, can you do to take this action? said, yeah, because you called me, that's all like, it's all yes, yeah. And after, right now cannot say yes, because I just wanna make sure I need another proof that's Aaron. So what would be that like a proof then? So that's some sort of cybersecurity solution that comes.
Aaron Crow (39:33.486): Right.
Hadi (39:38.064): I mean, that's gonna go ahead and like a develop soon that like how you gonna react like a, like a, are the, it's some sort of maybe like a authentication authorization solution, the new advanced authorization, like a authentication solution out there, right.
Aaron Crow (39:59.043): Yeah. I mean, it really takes into the dual factor of a, to the next level to cause to your point right now, facial recognition, they've already shown where they can fake that really quickly. I've seen some really amazing things. So facial recognition isn't going to be enough. you know, obviously a physical fingerprint that can work, you know, having, you know, physical keys, you know, like a Yubi key or something like that. That's something that I have along with a password.
Aaron Crow (40:25.395): But to your point, like these are going to be problems that we have to overcome and understand as AI changes the game. It can be used for good, but the bad actors are going to be using them as well to bypass the things that we're setting up. So we have to be just as knowledgeable about the ways they're going to try to, you know, fix the system or break the system or get around the system because they're going to be using AI to come up with those ways. Hey, I know this person has this, they've got this firewall, they've got this thing.
Aaron Crow (40:51.491): They've got facial recognition. How could I get around this thing? Right. And that's, that's, that's some of the upcoming dangers of, you know, back in our day, it was the script kiddies, you know, you copy and paste and use somebody else's hacks on this environment. didn't have to create it. I just copy and paste it. AI is that times a million.
Hadi (40:58.074): Exactly.
Hadi (41:11.174): Yeah, look at the phishing email. So right now, like if you, I could easily like detect any sort of phishing like attempt like scams like easily because I could see like spelling issues. I could see how like it's not written properly, but right now they not only write properly like the intruders.
Hadi (41:36.253): But also they go ahead and research through the AI and say, okay, like, ABC companies, can you find out ABC companies use it, which sort of application out there? And if that like information is available, say if they are using that to sign, they are using, for example, this application, they bring together an email and say, Hey, howdy, I hope you are doing well. This is a new contract. Go ahead and sign on that.
Hadi (42:6.704): And then this is your password. This is the link. ahead. And it's pretty legit for me. And it's really good looking, really legit for me. And like these sorts of things, even for some people who are in this space, it's a bit difficult. Like I cannot like blame people that are not very techy, that like take action on those. So that these are something that happening.
Hadi (42:32.370): But I would like to go ahead on the positive side because we were talking about the concerns only and maybe people are gonna listen to it, okay, say, okay, why we are using AI? So then all of them are about concerns. So yeah.
Aaron Crow (42:39.352): Yeah.
Aaron Crow (42:44.143): Ha
Aaron Crow (42:48.562): Yeah. I agree. Yeah. And, and the, the pros are so vast, right? You know, I can have a, a, you know, I can, I can make a person more effective. I can have them look at more data. You know, it's very, you know, take a password, you know, or, just any phrase or text, or, if I have to write down a license plate, you know, using that as an example, right? It's very easy for me. Is that an I or a one?
Aaron Crow (43:14.639): Is that, is that an E or a three? Like there's all these things, whereas an AI can read through these things and is not misunderstanding characters. It's able to see things. It's not getting tired. It didn't have a bad day. You know, it's going to do the same level of production on a daily basis. So you can, you can really, especially as you talked about earlier, as I compartmentalize these things and I build up an, a bot that is focused on, you know, parsing logs or, you know, looking at alerts and you know, whatever that
Aaron Crow (43:44.420): function is that bot is going to be able to do that at a very high level because they're just focused on that one task. They're not trying to cook you dinner. It's not trying to read your resume. It's not trying to create a recipe like none of those things. All it's doing is that one function so it can get really good at it because I can have very clear line of defense of explanation and instructions on what I want it to do, what its boundaries are, what it does in these certain scenarios because I don't it's very simple, right? If this then that.
Aaron Crow (44:13.303): Right. It's very much binary in an old traditional way. And when I, to your point as well, like if, if you, if you then have multiple of those bots and this one's focused on this function and this one's posted on this function, they can be really effective in those places. And then I can put a human above all of those things. So all that stuff feeds up. And then my, my sock analyst is able to see, you know, they're not having to go through the stack of needles to find the needle that is the most important to look at.
Aaron Crow (44:39.821): you've trained those AI bots to be able to, Hey, Hey, look at this one. This one looks different. This is something that seems like you should be paying attention. And then your analysts are able to focus on the things that bubble up to the top instead of having to look through all of that stuff. And then also focus on the one is the most important.
Hadi (44:47.240): Exactly. Yeah.
Hadi (44:58.160): Yeah, one of the big issues still like I face is that like the ideas, IPS are set up based on the rules and like some love logics and they cannot take something out of it. Like a behavior analysis, like a joke. We are saying that they are like having a behavior analysis, but they are really joke. But when an AI comes to the game, so the center going to be changed, they can really detect some
Hadi (45:27.908): issues that was not possible or was not possible before. And even like one of the big issues in the like in the SOCs that parsing the logs, how difficult was it like writing a log parser for any sort of application out there and connecting to those like the SIEM should be able to read those. But right now it's like it can happen in a minute that you can
Hadi (45:57.149): just paste like a big like a logs there, it's gonna parse it properly. And even it's gonna give you like a what's the issue there. So, and these are something really benefit that you are getting from the AI for the server security space. Another thing is that some of the issue like the phishing things, I think AI is really good at that one to finding those and like taking action on those ones.
Hadi (46:26.408): really good than those one. And taking action like connecting the AI to the other services. So again, I know the concern, but we are talking about like a really realistic and really lullaland of the AI that AI works like as a as a good thing for us. So it can take lots of action out there without like needing like 10 people, 20 people. So
Hadi (46:54.278): Yeah, again, we mentioned another concern that, okay, we are going to shrink the size of the team. But yeah, it's definitely, it's gonna go ahead and help us there. On the other side, intruders. Intruders are now take advantage too, right? One step ahead of us that go ahead and like advance like attacks at them. Like I remember like 10 years ago, like APT.
Hadi (47:21.736): attacks was really hot in that market. Everyone talking about that one, but right now no one talks about that. Right now people talk about, okay, someone like builds a drone and drone can do something dangerous, right? Out there. So because it's using AI things there, so it can find someone's face taking action like against that person. So at the, like a data side, we have, we're going to have that problem too, but
Hadi (47:52.145): We need to know that like, okay, the benefit that we are getting from this AI thing is going to be very, very vast. Where are we going to use it? How are we going to use it? And I believe the companies are most of them, and as I know, they are developing their LLM and ML models and they're going to like connect their application and like devices later on.
Hadi (48:16.498): So be able to fetch information from it, like send prompt and based on that, give the services to the companies out there. So that's a new sort of service that's going, like is going to develop.
Aaron Crow (48:24.186): Sure. Yeah.
Aaron Crow (48:29.528): Yeah, that makes, that makes a lot of sense. You know, it's, it's, it's coming. It's not going away. There's a lot of benefit in it. doesn't, to your point, I don't want to scare everyone. And like, why are we doing this? Cause there is a lot of benefit in it for sure. There's, there's a lot of value. it's going to make our people work faster, more, more efficient. They'll be able to work on the things that they want to work on. Cause parsing through logs manually is no fun. Nobody's ever injured. Well, not nobody.
Aaron Crow (48:56.046): Very few people enjoy doing that. You know, I've had to do it and it's not fun. writing scripts, finding ways to automate that stuff has always been great. So AI really fast tracks that it makes it where I can focus on the actual thing that I care about, like locking something down, updating a policy, you know, making something work, troubleshooting things like that, right? Instead of the, the minute, you know, boring, tedious, monotonous tasks of
Aaron Crow (49:23.556): going through this and as we know more and more and more data means more and more and more of that. So this helps us work faster and be able to focus on the things that are more fun to do and more enjoyable to do. So you can have your team doing those things instead. So that's awesome. Well, you know, we've probably hinted around and talked about it multiple times today, but I'll ask it anyways. You know what's coming is.
Aaron Crow (49:44.802): in the next five to 10 years, what's one thing come up over the horizon that's exciting and maybe one thing it's concerning in this space? It's probably the things we've already talked about, but what do you say?
Hadi (49:54.087): Yeah. So when, when I know that like maybe that's something that you, you know, that like, like me, I think that really excite like, make me excited. Like it's really exciting for me and make me motivated. Like in the tech space that every day I should learn something. If I learn something new on my day, when I go to bed and say, okay, that was a great day for me.
Hadi (50:21.798): That's something I really like about when I'm in the tech space because my mind got fresh. I know I'm still my brain like for functionally like for spine and it's functional. And I love that like learning something every single day. That's something that I would take like in the last four or five, 10 years. I mean, last 20 years working in the tech space. I like that.
Aaron Crow (50:49.518): Yeah. A hundred percent.
Hadi (50:52.296): Yeah, it's difficult to keep up with the technology, especially right now. That's why I would really, right now in TunePack, I try to bring Gen Z's working with me because they have something I really cannot understand by myself. They are guiding me. They are helping me to understand what's going on in space because,
Aaron Crow (50:58.147): It is, yeah.
Hadi (51:21.980): These are some people that we need to work for. And like these are people that like they know that they work better than us and they're to govern. They are they going to lead the world. And that's why I would like to work with them and learn every single day something.
Aaron Crow (51:40.303): Yeah, you know, that's, that's a great, great mindset to have. And that's how we, know, when you stop learning, that's, that's the end, right? Just cause you're not in school or you're not taking a course or you're not getting the certification, that, that, that quest of knowledge is it's, it's the pursuit. It's how we get better. you know, I want to constantly learn how to better communicate, how to better be a better dad, be a better husband, father, you know, friend, brother, all the things, right. And, and, it just aligns with all that type of stuff. So, so.
Aaron Crow (52:9.338): call to action, what tell people how to find out more about your company, what you guys do, come see you, all the things. What's the call to action you have for everybody.
Hadi (52:19.804): So I would say check out TunePack, tunepack.com. That's the website. That's, that's build with musician. So if you love music, go ahead and check that one and try to bring like someone who like would like to create a music there. Also we are developing tune page, tune.page. Tune.page is where you can find the musician sign up through the TunePack. And we would love.
Hadi (52:47.816): to serve every single musician out there, regardless of their location, regardless of their genre, their stage. 12 million expert musicians out there that they cannot have access to the services that label companies already offer. And we build this platform for every single musician out there. I try to like take advantage of my knowledge, my experts in technology.
Hadi (53:14.458): and bring that to serve the musician because I would say we should, the technology should be in the favor of musicians, favor of art, not against them. So that's been because they, some musician had that feeling that technology are against them. But like in TunePack, what we are doing to utilize technology for them and we are building that with them. So check out TunePack.
Hadi (53:41.152): and like talk to us on social media like tag us. So yeah, that's great. And it was an honor like being on your podcast.
Aaron Crow (53:51.375): Yeah, that I appreciate it, man. And it's exciting space. As you talk through that, it made me think of back in the day when all the musicians were against Napster and MP3s and digital music and how they wanted to just stop it. And instead of realizing they had to change their business and realize that it wasn't going away, they had to adopt it and find a way to work with it, because it didn't push people away. In fact, it helped people hear them and then wanted them to go get more. I want to buy the ticket. I want to buy the t-shirt. I want to do all the stuff.
Aaron Crow (54:19.920): I remember one of my favorite bands, Metallica was like, you know, big time against Napster at the time. Right. And, I, I remember being frustrated as as a, you know, I owned every one of their CDs. And just because I would listen to it on an MP3, I would still go buy their music. Cause I wanted to support the band, um, because I knew I appreciated their art and their, the, work that they put into that and, going on tour and all that type of stuff. And I think more, more people want that. Like, I think there's something, I think that's one of things to kind of close this up here.
Hadi (54:23.005): Wow.
Aaron Crow (54:48.845): I feel that's one of the things that humanity is, bringing to this is yes, there's going to be AI, but people value that, that, that, that artist, that, that hand, that something they know came from that thing, that group, that person, that, that thing. And you, yes, you can recreate music and, and MP3s and, and, and AI, all this stuff. But again, people want that acoustic where I'm sitting in the room.
Aaron Crow (55:13.264): having a coffee and I see the person and I shake their hand afterwards and I had a conversation and I buy their CD and they sign it for me. Like people want that level of thing and I think that's gonna just make that stuff more and more valuable.
Hadi (55:22.213): Exactly.
Aaron Crow (55:26.212): Yeah. Awesome, man. Well, Hey, I appreciate it again. taking the time today. I'm super excited. Definitely go check out his sites. We'll put all that stuff in the show notes. If you're a musician or you know, a musician and they want to get on a record label or maybe create their own, definitely reach out to him. seems like the right guy to do it. Use technology for your advantage, not, not to be against you. So thanks again for your time, sir. It was great talking with you today and, best of luck in, in all the, all the things that you do, sir.
Hadi (55:48.957): Thank you so much. Appreciate it. Have a great one. Thank you.
Aaron Crow (55:54.821): You as well.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.