Shuman Ghosemajumder, Reken | theCUBE + NYSE Wired: Cyber Security Leaders
Watch on YouTubeVideo summary
The video features Shuman Ghosemajumder, CEO and co-founder of Reken, discussing the evolving landscape of cyber security in the age of generative AI. Ghosemajumder explains that while early perceptions of cyber crime involved isolated hackers, modern threats have evolved into sophisticated, organized ecosystems where criminals use automation and stolen credentials to target major institutions. The arrival of generative AI has exacerbated this issue by enabling attackers to perform the "last mile" of social engineering, allowing them to conduct realistic conversations with victims in real-time. This capability makes distinguishing between real humans and AI-generated impersonations increasingly difficult, turning identity verification into a critical challenge for organizations and individuals alike.
To address these threats, Reken has developed a unique product called Northstar, which operates directly on the user's device rather than relying on centralized cloud analysis or traditional email filtering. Ghosemajumder highlights the limitations of current security measures, such as false positives in spam filters that block legitimate emails and the ineffectiveness of phishing awareness training due to human distraction and the inability to simulate high-stakes psychological scenarios. Northstar overcomes these hurdles by analyzing hundreds of contextual characteristics, including user behavior patterns, timing, and message content, to detect anomalies instantly. By processing data locally on the device, the solution ensures real-time protection without compromising privacy or introducing latency that could hinder user productivity.
A key innovation of Reken's approach is its use of positive security indicators to build a trust network, similar to how users instinctively trust blue bubbles in messaging apps over green ones. Instead of overwhelming users with constant alerts that lead to "banner blindness," the system provides subtle cues that help users subconsciously recognize trustworthy communications versus fraudulent ones. This method allows individuals to navigate complex online interactions without needing deep technical expertise or constant vigilance. The technology is designed to be accessible to everyone, from Fortune 500 executives to everyday consumers, offering a guide through an environment where fraud is becoming the norm rather than the exception.
Reken's business model focuses on enterprise and government clients initially, with plans to expand into broader consumer markets in the future. The company emphasizes that its technology is not merely a feature of a larger platform but a standalone solution built on proprietary hardware-optimized AI that does not require powerful GPUs or external cloud processing. Ghosemajumder notes that while cyber crime will never be fully eradicated and will constantly morph into new forms, Reken aims to create an adaptable brand that evolves alongside emerging threats. By combining advanced local processing with a user-centric design, the company seeks to redefine how individuals and organizations secure their digital identities against the relentless advances of AI-driven fraud.
Read the full video transcript
Palo Alto Studio Connection Silicon
Valley and Wall Street. I'm John Fost
here with Dave Vol, my co-host.
Welcome back to the Cube studio here at
the New York Stock Exchange. I'm Jim
Allen, co-host of NYC Wired cyber
security leaders and we know that the
internet used to have a trust problem.
AI might have just turned that into an
identity crisis. Deep face can sound
like your CEO. Fishing emails can be
generated on industrial scale. And
increasingly, the hardest thing online
isn't knowing what's malicious. It's
knowing what's real. My next guest has
spent his career finding exactly this
problem. From Google's battle against
click fraud to shape security, which is
acquired by F5 for $1 billion. And now,
Recken Schuman, CEO and co-founder of
Recken. Welcome to NYC Wired.
>> Thanks so much for having me. Okay, so
let's get straight into it because when
it comes to cyber security and the
challenges of the area era, this is not
your first rodeo. You have been in this
industry a while. You have seen all
sorts of challenges emerge, I am sure.
Talk to me about this moment right now
and the decision to found Reckon.
>> So I think that uh we've seen the world
evolving to this point for more than 20
years now. So when people thought about
cyber crime uh in the '9s or in the
early 2000s, I think that they had a
fairly simplistic view of usually
imagining someone in a hoodie in their
parents' basement trying to hack into
different kinds of servers. And that's
not what cyber crime has looked like for
a couple of decades now. So in the early
2000s at Google, we started to see how
organized cyber crime was getting very
sophisticated and they were creating
click fraud attempts that were using all
kinds of different software and
automation. And that only got more
sophisticated at Shape Security where we
were protecting the largest banks and
airlines and federal agencies against uh
when cyber criminals would take all of
these stolen usernames and passwords
that we read about on a regular basis
from big data breaches and they would
replay them essentially against your
bank and your airline and all of these
other types of big companies that uh had
millions of usernames that uh you know
they needed to manage. And so in those
cases, what we saw was the first sign of
cyber criminals using a very
commoditized and federated kind of
ecosystem where they were collaborating
with different groups that each
specialized in different kinds of tasks
in order to be able to defeat our
security. And so uh you know the the
culmination of this is really reckon
where we've now seen because of
generative AI cyber criminals can
essentially do the last mile of the
attack that they were never able to do
in the past where you can actually carry
on a conversation with a real human
being and you can defraud them even in
real time.
>> I mean we've certainly seen some
alarming examples of this right like
imitations of Jamie Diamond for example
that went out in the Met last summer.
You know, it's pretty scary stuff. But
cyber itself as an industry, I feel like
it gets a lot of press, right? But we
also think of it as a relatively
saturated space from some respects,
right? Like I remember reading some
while back that some CISOs might have 80
different cyber tools or technologies on
their like opics or P&L in any given
month. What how do you build a product
that's unique for this moment though?
like talk me through the competitive
advantage of Recken.
>> Yeah, that that's a great question and I
think that uh it's been evolving in this
direction for quite some time because
every single time there's a cyber
incident uh you look at exactly what the
vulnerability was and in many cases what
people decide is that there was an
attack surface that wasn't actually
protected and so we need to create uh
some kind of new product to be able to
deal with that attack surface. So, this
is the story of the evolution of email
spam protection, of two-factor
authentication, of all of the different
types of security that we use uh in any
kind of complex environment. And over
time, you think that basically every
single attack surface has been covered
in some form or another. But I think
that there are attack surfaces that are
not covered for a variety of different
reasons. So in one case an attack
surface may not be covered because it's
brand new. So if you create uh a new
type of product that has never existed
before and a lot of people start using
it then that creates an attack surface
that you now have to think about how do
I protect it. So AI is in this category.
So we didn't have so many people who
were using AI especially generative AI
um uh three years ago as we do now. And
so the more and more organizations and
people who are using AI, the more new
security products need to be created to
be able to protect against that. But the
other way that you can create a
protection for an attack surface that
has not been protected is to have some
kind of technology breakthrough in the
cyber security area itself. So what if
you could do something to be able to
protect something that you previously
thought it wasn't really possible to
apply technology to. And so in our case,
the breakthrough is being able to use AI
in a context that we were never able to
use previous technologies. And that's
how we communicate online. So when we're
reading a message, whether it's an email
or a text message or we're on a Zoom
call, all of those cases are real time
or near real time or offline
communications where we are trying to
protect what we get there. But we'd
never had the ability to be able to do
that in real time before. And so AI
enables that breakthrough.
>> And am I correct in saying that this is
a product that lives on your device that
travels and works along with you, right?
So from a real-time perspective, it's
happening here and now. It's not
necessarily an alert is being sent to a
security operation center alerting uh
you know somebody who's alerting
somebody who is saying, "Oh, we need to
look at this." This is very
instantaneous. explain to me the user
experience of this. Like say tonight I
get an email from John Furrier
>> telling me, "Hey Gemma, you need to wire
this to this person, right?" How, you
know, and it sounds like John, it looks
like John, it's John's email address.
>> What would this product do to make me
realize, oh crap, there is something not
right here?
>> Yeah. So f first of all, let's talk
about how you're protected against that
right now and why that doesn't always
work. So the the first way that you're
protected against that is by some kind
of uh email filtering. So you've got
various email filtering products that
are analyzing all of the emails that are
sent to you. And Google and Microsoft
are doing the vast majority of this
because they're looking for all of the
spam that's sent all around the world
and they're putting that into your spam
folder instead of delivering it to you
in your inbox. But the problem with any
kind of email filtering product,
including the email filtering that goes
on top of what Google and Microsoft
provide, is that there's a false
positive, false negative tradeoff. So,
if you want to be as aggressive as
possible and say that we don't want to
take any chances, we're going to look at
this message that looks like it's
potentially suspicious because, you
know, maybe John hasn't sent an email
that late before or maybe John hasn't
sent an email on that particular topic
before, then you could be very
aggressive with the filtering and then
end up taking a legitimate message and
putting it in spam. And that's when you
create all kinds of organizational
problems because uh you have uh uh an
executive or a salesperson or you know
anyone that communicates with the
external world uh like journalists on a
regular basis and uh they're going to
wonder where is this important email
that I was expecting and then if they
find out that it was quarantined for 48
hours and then the entire opportunity is
gone then that's completely
unacceptable. And so nobody sets their
email filtering to actually be that
aggressive. And so you accept that there
are a certain number of malicious
messages that are making their way
through to your users right now. And so
then the backup mechanism is fishing
awareness training. And so everyone gets
dragged through fishing awareness
training either uh you know for hours a
year or you know a smaller amount of
time. But the amazing thing about uh
fishing training is that it doesn't seem
to affect any of our security outcomes.
So there's been a number of uh research
studies that have been done on this and
unfortunately what they show is that for
a variety of reasons going through
fishing training regardless of what the
fishing training is doesn't actually
make anyone safer. It doesn't change
their behavior. And and there are a
couple of reasons for this when when you
think about it. So, one reason for it is
that uh people are distracted when
they're reading their email. They're not
always thinking about security. They're
not thinking about uh you know, what are
all of the minute telltale signs that
something could potentially be
malicious. And of course, the the
messages are now AI generated and
they're much more sophisticated than
ever before. So, that's one reason that
you're just not in that mode and most
people aren't tech experts to be able to
identify a very sophisticated fishing
message that's been created. But the
other reason is that you can never
really simulate in a fishing simulation
a scary scenario that uh a cyber
criminal will actually put someone
through. So, uh, you know that there was
this case of, uh, GoDaddy doing, uh, a
fishing awareness exercise a few years
back where they promised all of their
employees a free gift card and then when
they clicked on, uh, the link, they
discovered there's no gift card and it
was a fishing training uh, test that
they just failed. And so that made them
so angry that they actually went public
with it and people complained to the
press about it. And so if you were to
try and do a fishing training exercise
that you know said that here's a message
where we're saying your your family is
in danger or your job is in danger or
the CEO is angry at you that that would
create psychological trauma. And so you
can never simulate the really scary
scenarios that real people have to deal
with. And so what we've created is a
brand new approach because what you need
is protection right at the moment that
you're about to make a mistake. and
something that uses technology to be
able to see what you can't see as a
user. And so that was never possible
before.
>> But that example you gave and first of
all that's fascinating. I did not know
that about GoDaddy. I would probably
click that link. I mean like great a
free gift card, you know, hooray.
>> But from the perspective of what you're
building here, so what you describe,
it's on your device. It has to
understand a lot of context about your
persona. Correct. It understands that
John doesn't typically email me at 11:00
at night or he wouldn't ask me to wire
money to somebody or whatever it might
be. It knows some sort of nuance or it
reads into some sort of nuance about how
I live, how I work, how I play that it
can then detect an anomaly in this
potential engagement. Correct. What is
the signal like? I'm interested to
understand what uniquely is it looking
for.
>> So, so that's part of it. So there are
many different things that you want to
look at. So for example, when you look
at uh what you're supposed to learn in
uh fishing training, uh you're supposed
to look at who is this actually coming
from? Is the domain accurate? Is uh you
know this including a link that looks
like it could be suspicious and uh you
know all of the other uh technical
characteristics that are associated with
email. Then there are the contextual
characteristics that you were talking
about. How does John usually email me?
What are the topics that he usually
emails me about? Is there like an
unusual sense of urgency to this message
that seems anomalous in some way? And
what we can provide is a comprehensive
view of all of the different things that
we're able to detect that are
potentially wrong about this message
that you may be too distracted or may
not be looking closely enough or may not
have the technical expertise to be able
to find. And so if you can take all of
these hundreds of different
characteristics and you can surface them
to the user in a way that presents uh it
with a a very simple kind of user
interface that doesn't get in their way.
That's really the magic of how do we
navigate uh the complexity of the online
world at this point?
>> It might seem like a simple question
here but how do you grab their attention
immediately in that moment? Right?
Because often times you are you know
we're doing like 20 things at once,
right? you're reading an email, you're
feeding your kids, you're, you know, and
your technology is saying, "Holy crap,
you know, this is really dodgy. Don't do
this." How do you engage with them in
real time?
>> Yeah. You know, that's uh one of the the
key secrets here in terms of how we've
built this product and uh you know, now
that we're out of stealth, we're we're
happy to be able to talk about it. But
uh the UX that uh we've employed and
we've done a lot of research on is one
that has a combination of positive and
negative security indicators and I think
that's something which is very
important. So what one of the very first
jobs that I had uh in the early 2000s at
Google was running experiments across
our ad system across millions of
different websites to be able to figure
out how do users actually respond to
different kinds of uh information ads
especially but other types of
information as well. And when do they
start to experience banner blindness? So
if you keep showing the same thing to
the user, if you keep showing them a
whole bunch of alerts, if you keep
showing them uh you know uh a whole
bunch of uh uh indications that are
exactly in the same place all the time,
they begin to learn that that's
something that they should ignore and it
doesn't actually change behavior
anymore. So if you start to tell users
for example that uh you should be
careful this is an external website that
you're talking to or it's an external
domain that you're talking to and you
have it on every single email whenever
they talk to someone who is outside of
their organization they get banner
blindness almost immediately. And so
what you want to have is some kind of
positive security indicators that tell
them when something is trustworthy and
when it's okay. And this is actually a
core part of our approach in terms of
being able to build out a trust network
where if I'm using a product that uses
uh what we call the reckon private core
and you're using a reckon private core
application as well when we communicate
we become part of that trust network and
now we can provide positive trust
indicators that uh allow you to
basically accept this information almost
subconsciously so you don't have to
think as much. So an example of positive
trust indicators is uh TLS. So when
you're visiting a website and you used
to be able to get that lock icon on uh
many different uh uh browsers that gave
you this positive trust indicator that
as soon as it was missing on a site
where you were giving your credit card
information, you would start to feel a
little bit weird about that. You're
like, you know, why is this not an
encrypted connection? And that was just
a very simple kind of trust indicator.
you could have much bigger and uh more
uh obvious trust indicators. So another
example of that is uh the blue bubble
green bubble distinction that Apple has
made in iOS. So if you're communicating
with another iPhone user, you actually
get endto-end encryption built in
>> and that shows up as a really simple
blue bubble.
>> And so the user doesn't have to think as
much whenever they're communicating in
the blue bubble world. blue bubbles are
safe and then when they get SMS spam
they get a weird feeling about that and
because that's always showing up in the
green bubble world.
>> So you've come out of stealth. Am I
correct in assuming that this is design
I'm sure it has mass usage but is it
designed for high net worth individuals
for executives within Fortune 500s like
who is the ideal user for a technology
like this?
>> Yeah. Um, that's a great question and I
think that there are folks that uh have
uh had bad experiences with uh fraud
online. Unfortunately, an increasing
number of people have had such bad
experiences and th this is of course uh
the those are the types of folks that we
had in mind when we founded the company
and we wanted to be able to protect
friends and family members who have
experienced fraud. Um my co-founder and
I both have uh friends and family
members that have had thousands of
dollars uh stolen from them. But of
course large corporations and uh
governments and large organizations and
high netw worth individuals and
executives also have similar kinds of
concerns. So really this is a problem
that is affecting everyone that uses
online communications and all of our
communication media are essentially uh
getting overwhelmed by fraud especially
because of AI now. So, you know, there
was a study that was done a number of
years ago that uh uh had uh an analysis
of where is all of the email spam coming
from. And what it found was that 90% of
the world's email spam at the time was
actually coming from just three sources.
And so that's what automation enables.
And so that's what's now possible with
generative AI as well. So cyber
criminals can use generative AI and
attack millions of people simultaneously
with highly customized messages. And uh
you know this is something that all of
our existing systems were never really
designed to be able to deal with. And
that's why we need to have essentially
some kind of a guide. We we call the
product Northstar because it guides
people in the right direction. And uh it
doesn't matter if you're an executive or
an individual um uh as a consumer. uh
everyone is getting affected by these
types of fraud and scams.
>> So the business is predominantly B2B,
but it certainly has a BTOC usage case.
Am I correct?
>> Well, we want to be able to get to B TOC
in the future. Right now, we've just
come out of stealth and we're
concentrating on uh being able to
protect large enterprises and
governments.
>> And if I'm Jamie Diamond and I have
Reken on my device,
>> Yeah. and I'm talking to somebody at a
hedge fund, does that person also need
to be a reckon user for it to be
validated or you know what's the nexus
>> that that's uh a really important
distinction because if Jaime Diamond is
using uh the Northstar product just by
himself, then he is protected against
all of the spam and fraud and uh uh
social engineering that's directed
against him,
>> but if he is then communicating with
folks in his organization who are also
using the Northstar product, he gets an
additional layer of protection. And so
that's what starts to give the positive
indicators that similar to the blue
bubbles that uh you know, now you've got
uh uh a trusted communication that's
been established.
>> Okay. So, it's fascinating. I mean, it's
a scary time. I see certainly see the
market value or the user value in
something like this. What stage are you
guys at? You're out of stealth.
>> Yeah.
>> You have you PC's in place across
enterprises. Talk me through what sorts
of use cases or proofs of concepts
you've had so far.
>> Yeah, we've been working with Fortune
500 design partners and uh making sure
that uh the technology works really
well. And so that's what gave us the
confidence to now come out of stealth
and make this available to the broader
marketplace. And so that's exactly who
we're engaging with. We're thinking
primarily um organizations that uh are
uh trying to deal with these types of
problems at a large scale. Those are the
folks that we're concentrating on right
now. But ultimately, we want to be a
solution for everyone in the market.
>> And the business case, it's lic based,
usage based. How how's it
commercialized?
>> Yeah, it's seat based.
>> Seat based. Okay. Per user.
>> That's right.
>> Um and I guess last question to you, I
mean, you've been in the industry quite
a while. It is a very interesting time
in cyber. I mean, I think everyone can
see or hear that. We hear a lot about
the world of cyber and how hard it is to
take on some of those incumbents that
have been in the space for a while.
We've had some very high-profile cyber
CEOs on here and say, you know,
everything's going to converge
eventually, right? You've already sold a
company. How do you think about this
time as like, you know, again, a next
time founder, you know, what where do
you see this industry headed? Do you
think that the it's too saturated? I
mean, obviously not if you founded a
company, but how do you fight back
against the challenge of what is
somewhat of a saturated industry at a
noisy time, right? It seems like
everyone's promising to fix all your
problems.
>> Yeah, I I I think that uh it's really
about the market that you pick. So uh
the question that everyone has about
every single startup is is this truly a
standalone company in the long run or is
this more of a feature of a larger
platform and you know could someone else
build this technology and just simply
include it within their larger platform
that already exists and has a whole
bunch of customers or is it really
difficult to be able to uh recreate
that? And so this was one of the reasons
why we were trying to come up with
something that had never existed before.
And we spent 2 years of R&D figuring out
whether or not this technology was even
possible. Because when you think about
using AI in this kind of a context, what
most people think of today, and this is
what the the market looks like, is
putting a wrapper around one of the big
frontier models. So uh you know, having
chat GPT or uh Claude analyze all of
your messages. And there are a couple of
problems with that.
>> I mean, there's some fundamental
problems with that, right? Like, you
know, but please continue.
>> Well, well, I I think what you're
probably alluding to is the privacy
issue.
>> For sure. You don't want
>> It's poacher turned gamekeeper, right?
Like, you know, in if we're talking
frankly here.
>> Exactly. It's basically a non-starter to
have all of this highly confidential
data um being analyzed and potentially
being used to train someone's third
party model. In fact, it's even a
liability from a security perspective
for you to have a security company
analyzing all of that in their own third
party environment. And there are a
number of different uh you know
companies that have you send your most
confidential data to their third party
cloud to analyze. And so the privacy
issue was one of the big things that we
wanted to deal with. And doing that on
device requires us to invent brand new
technology that's never existed before
that's capable of being able to solve
the other problem as well. And the other
problem is that it's simply too slow to
have your device send your data. Even if
it was okay from a privacy perspective,
which it's not, of course, but it's too
slow to send your data to a third party
cloud to have it analyzed. At best, it
would take several seconds to respond
back. And that's way too slow to provide
a just in time protection for users. And
so, we needed to figure out whether or
not it was even possible to have
technology that executes on a device
without a GPU. So, I actually went to
Best Buy and bought the worst laptop
that they sold and that was my testing
device. And if it can run well on that
device without slowing down uh the
experience for users then we knew that
it could run on any Fortune 500 machine.
And so building that technology that is
really the answer in terms of uh you
know can someone else just simply
recreate this. It's not something you
can vibe code. It's not something that
uh is uh trivial to be able to create.
So that's one part of it. The other part
in terms of, you know, being able to
distinguish yourself and grow over time
is whether or not the market is a broad
enough market. And so what we're dealing
with, we think of it as a problem that
not only affects every consumer, every
small business, and every large
enterprise and government in the world.
But it's also a problem that will never
actually be solved. Even if we're highly
successful, the problem will not be
solved. There will always be crime.
Cyber crime is basically the norm now.
in terms of crime when you look at the
amount of dollars that are stolen. And
so it will simply morph into new forms.
And what we want to create is a company
that adapts along the way and becomes,
you know, the uh uh the brand that
builds a variety of different products
and essentially becomes that platform in
a brand new era. Well, it certainly ties
in a lot of topics that we talk about
here in NYC Wired because it's on the
edge, right? Essentially, in terms of
the device management and it's securing
the future of whatever it might be that
the inference generation or era is going
to bring our way, which can certainly
sound a little bit alarming when we
think about it from a bird's eye view.
So, thank you so much for joining us in
NYC Wired.
>> Thank you, Gemma.
>> I'm Gemma Allen here at the Cube studio
at the New York Stock Exchange. This is
Cyber Security Leaders. One of our
programs is NYC Wired where we talk
about all of the threats and all of the
hopeful solutions that will solve for
the problems from tomorrow. Thanks so
much for joining.