Submind YouTube summaries
Thumbnail for Shuman Ghosemajumder, Reken | theCUBE + NYSE Wired: Cyber Security Leaders

Shuman Ghosemajumder, Reken | theCUBE + NYSE Wired: Cyber Security Leaders

Watch on YouTube

Video summary

The video features Shuman Ghosemajumder, CEO and co-founder of Reken, discussing the evolving landscape of cyber security in the age of generative AI. Ghosemajumder explains that while early perceptions of cyber crime involved isolated hackers, modern threats have evolved into sophisticated, organized ecosystems where criminals use automation and stolen credentials to target major institutions. The arrival of generative AI has exacerbated this issue by enabling attackers to perform the "last mile" of social engineering, allowing them to conduct realistic conversations with victims in real-time. This capability makes distinguishing between real humans and AI-generated impersonations increasingly difficult, turning identity verification into a critical challenge for organizations and individuals alike. To address these threats, Reken has developed a unique product called Northstar, which operates directly on the user's device rather than relying on centralized cloud analysis or traditional email filtering. Ghosemajumder highlights the limitations of current security measures, such as false positives in spam filters that block legitimate emails and the ineffectiveness of phishing awareness training due to human distraction and the inability to simulate high-stakes psychological scenarios. Northstar overcomes these hurdles by analyzing hundreds of contextual characteristics, including user behavior patterns, timing, and message content, to detect anomalies instantly. By processing data locally on the device, the solution ensures real-time protection without compromising privacy or introducing latency that could hinder user productivity. A key innovation of Reken's approach is its use of positive security indicators to build a trust network, similar to how users instinctively trust blue bubbles in messaging apps over green ones. Instead of overwhelming users with constant alerts that lead to "banner blindness," the system provides subtle cues that help users subconsciously recognize trustworthy communications versus fraudulent ones. This method allows individuals to navigate complex online interactions without needing deep technical expertise or constant vigilance. The technology is designed to be accessible to everyone, from Fortune 500 executives to everyday consumers, offering a guide through an environment where fraud is becoming the norm rather than the exception. Reken's business model focuses on enterprise and government clients initially, with plans to expand into broader consumer markets in the future. The company emphasizes that its technology is not merely a feature of a larger platform but a standalone solution built on proprietary hardware-optimized AI that does not require powerful GPUs or external cloud processing. Ghosemajumder notes that while cyber crime will never be fully eradicated and will constantly morph into new forms, Reken aims to create an adaptable brand that evolves alongside emerging threats. By combining advanced local processing with a user-centric design, the company seeks to redefine how individuals and organizations secure their digital identities against the relentless advances of AI-driven fraud.
Read the full video transcript
Palo Alto Studio Connection Silicon Valley and Wall Street. I'm John Fost here with Dave Vol, my co-host. Welcome back to the Cube studio here at the New York Stock Exchange. I'm Jim Allen, co-host of NYC Wired cyber security leaders and we know that the internet used to have a trust problem. AI might have just turned that into an identity crisis. Deep face can sound like your CEO. Fishing emails can be generated on industrial scale. And increasingly, the hardest thing online isn't knowing what's malicious. It's knowing what's real. My next guest has spent his career finding exactly this problem. From Google's battle against click fraud to shape security, which is acquired by F5 for $1 billion. And now, Recken Schuman, CEO and co-founder of Recken. Welcome to NYC Wired. >> Thanks so much for having me. Okay, so let's get straight into it because when it comes to cyber security and the challenges of the area era, this is not your first rodeo. You have been in this industry a while. You have seen all sorts of challenges emerge, I am sure. Talk to me about this moment right now and the decision to found Reckon. >> So I think that uh we've seen the world evolving to this point for more than 20 years now. So when people thought about cyber crime uh in the '9s or in the early 2000s, I think that they had a fairly simplistic view of usually imagining someone in a hoodie in their parents' basement trying to hack into different kinds of servers. And that's not what cyber crime has looked like for a couple of decades now. So in the early 2000s at Google, we started to see how organized cyber crime was getting very sophisticated and they were creating click fraud attempts that were using all kinds of different software and automation. And that only got more sophisticated at Shape Security where we were protecting the largest banks and airlines and federal agencies against uh when cyber criminals would take all of these stolen usernames and passwords that we read about on a regular basis from big data breaches and they would replay them essentially against your bank and your airline and all of these other types of big companies that uh had millions of usernames that uh you know they needed to manage. And so in those cases, what we saw was the first sign of cyber criminals using a very commoditized and federated kind of ecosystem where they were collaborating with different groups that each specialized in different kinds of tasks in order to be able to defeat our security. And so uh you know the the culmination of this is really reckon where we've now seen because of generative AI cyber criminals can essentially do the last mile of the attack that they were never able to do in the past where you can actually carry on a conversation with a real human being and you can defraud them even in real time. >> I mean we've certainly seen some alarming examples of this right like imitations of Jamie Diamond for example that went out in the Met last summer. You know, it's pretty scary stuff. But cyber itself as an industry, I feel like it gets a lot of press, right? But we also think of it as a relatively saturated space from some respects, right? Like I remember reading some while back that some CISOs might have 80 different cyber tools or technologies on their like opics or P&L in any given month. What how do you build a product that's unique for this moment though? like talk me through the competitive advantage of Recken. >> Yeah, that that's a great question and I think that uh it's been evolving in this direction for quite some time because every single time there's a cyber incident uh you look at exactly what the vulnerability was and in many cases what people decide is that there was an attack surface that wasn't actually protected and so we need to create uh some kind of new product to be able to deal with that attack surface. So, this is the story of the evolution of email spam protection, of two-factor authentication, of all of the different types of security that we use uh in any kind of complex environment. And over time, you think that basically every single attack surface has been covered in some form or another. But I think that there are attack surfaces that are not covered for a variety of different reasons. So in one case an attack surface may not be covered because it's brand new. So if you create uh a new type of product that has never existed before and a lot of people start using it then that creates an attack surface that you now have to think about how do I protect it. So AI is in this category. So we didn't have so many people who were using AI especially generative AI um uh three years ago as we do now. And so the more and more organizations and people who are using AI, the more new security products need to be created to be able to protect against that. But the other way that you can create a protection for an attack surface that has not been protected is to have some kind of technology breakthrough in the cyber security area itself. So what if you could do something to be able to protect something that you previously thought it wasn't really possible to apply technology to. And so in our case, the breakthrough is being able to use AI in a context that we were never able to use previous technologies. And that's how we communicate online. So when we're reading a message, whether it's an email or a text message or we're on a Zoom call, all of those cases are real time or near real time or offline communications where we are trying to protect what we get there. But we'd never had the ability to be able to do that in real time before. And so AI enables that breakthrough. >> And am I correct in saying that this is a product that lives on your device that travels and works along with you, right? So from a real-time perspective, it's happening here and now. It's not necessarily an alert is being sent to a security operation center alerting uh you know somebody who's alerting somebody who is saying, "Oh, we need to look at this." This is very instantaneous. explain to me the user experience of this. Like say tonight I get an email from John Furrier >> telling me, "Hey Gemma, you need to wire this to this person, right?" How, you know, and it sounds like John, it looks like John, it's John's email address. >> What would this product do to make me realize, oh crap, there is something not right here? >> Yeah. So f first of all, let's talk about how you're protected against that right now and why that doesn't always work. So the the first way that you're protected against that is by some kind of uh email filtering. So you've got various email filtering products that are analyzing all of the emails that are sent to you. And Google and Microsoft are doing the vast majority of this because they're looking for all of the spam that's sent all around the world and they're putting that into your spam folder instead of delivering it to you in your inbox. But the problem with any kind of email filtering product, including the email filtering that goes on top of what Google and Microsoft provide, is that there's a false positive, false negative tradeoff. So, if you want to be as aggressive as possible and say that we don't want to take any chances, we're going to look at this message that looks like it's potentially suspicious because, you know, maybe John hasn't sent an email that late before or maybe John hasn't sent an email on that particular topic before, then you could be very aggressive with the filtering and then end up taking a legitimate message and putting it in spam. And that's when you create all kinds of organizational problems because uh you have uh uh an executive or a salesperson or you know anyone that communicates with the external world uh like journalists on a regular basis and uh they're going to wonder where is this important email that I was expecting and then if they find out that it was quarantined for 48 hours and then the entire opportunity is gone then that's completely unacceptable. And so nobody sets their email filtering to actually be that aggressive. And so you accept that there are a certain number of malicious messages that are making their way through to your users right now. And so then the backup mechanism is fishing awareness training. And so everyone gets dragged through fishing awareness training either uh you know for hours a year or you know a smaller amount of time. But the amazing thing about uh fishing training is that it doesn't seem to affect any of our security outcomes. So there's been a number of uh research studies that have been done on this and unfortunately what they show is that for a variety of reasons going through fishing training regardless of what the fishing training is doesn't actually make anyone safer. It doesn't change their behavior. And and there are a couple of reasons for this when when you think about it. So, one reason for it is that uh people are distracted when they're reading their email. They're not always thinking about security. They're not thinking about uh you know, what are all of the minute telltale signs that something could potentially be malicious. And of course, the the messages are now AI generated and they're much more sophisticated than ever before. So, that's one reason that you're just not in that mode and most people aren't tech experts to be able to identify a very sophisticated fishing message that's been created. But the other reason is that you can never really simulate in a fishing simulation a scary scenario that uh a cyber criminal will actually put someone through. So, uh, you know that there was this case of, uh, GoDaddy doing, uh, a fishing awareness exercise a few years back where they promised all of their employees a free gift card and then when they clicked on, uh, the link, they discovered there's no gift card and it was a fishing training uh, test that they just failed. And so that made them so angry that they actually went public with it and people complained to the press about it. And so if you were to try and do a fishing training exercise that you know said that here's a message where we're saying your your family is in danger or your job is in danger or the CEO is angry at you that that would create psychological trauma. And so you can never simulate the really scary scenarios that real people have to deal with. And so what we've created is a brand new approach because what you need is protection right at the moment that you're about to make a mistake. and something that uses technology to be able to see what you can't see as a user. And so that was never possible before. >> But that example you gave and first of all that's fascinating. I did not know that about GoDaddy. I would probably click that link. I mean like great a free gift card, you know, hooray. >> But from the perspective of what you're building here, so what you describe, it's on your device. It has to understand a lot of context about your persona. Correct. It understands that John doesn't typically email me at 11:00 at night or he wouldn't ask me to wire money to somebody or whatever it might be. It knows some sort of nuance or it reads into some sort of nuance about how I live, how I work, how I play that it can then detect an anomaly in this potential engagement. Correct. What is the signal like? I'm interested to understand what uniquely is it looking for. >> So, so that's part of it. So there are many different things that you want to look at. So for example, when you look at uh what you're supposed to learn in uh fishing training, uh you're supposed to look at who is this actually coming from? Is the domain accurate? Is uh you know this including a link that looks like it could be suspicious and uh you know all of the other uh technical characteristics that are associated with email. Then there are the contextual characteristics that you were talking about. How does John usually email me? What are the topics that he usually emails me about? Is there like an unusual sense of urgency to this message that seems anomalous in some way? And what we can provide is a comprehensive view of all of the different things that we're able to detect that are potentially wrong about this message that you may be too distracted or may not be looking closely enough or may not have the technical expertise to be able to find. And so if you can take all of these hundreds of different characteristics and you can surface them to the user in a way that presents uh it with a a very simple kind of user interface that doesn't get in their way. That's really the magic of how do we navigate uh the complexity of the online world at this point? >> It might seem like a simple question here but how do you grab their attention immediately in that moment? Right? Because often times you are you know we're doing like 20 things at once, right? you're reading an email, you're feeding your kids, you're, you know, and your technology is saying, "Holy crap, you know, this is really dodgy. Don't do this." How do you engage with them in real time? >> Yeah. You know, that's uh one of the the key secrets here in terms of how we've built this product and uh you know, now that we're out of stealth, we're we're happy to be able to talk about it. But uh the UX that uh we've employed and we've done a lot of research on is one that has a combination of positive and negative security indicators and I think that's something which is very important. So what one of the very first jobs that I had uh in the early 2000s at Google was running experiments across our ad system across millions of different websites to be able to figure out how do users actually respond to different kinds of uh information ads especially but other types of information as well. And when do they start to experience banner blindness? So if you keep showing the same thing to the user, if you keep showing them a whole bunch of alerts, if you keep showing them uh you know uh a whole bunch of uh uh indications that are exactly in the same place all the time, they begin to learn that that's something that they should ignore and it doesn't actually change behavior anymore. So if you start to tell users for example that uh you should be careful this is an external website that you're talking to or it's an external domain that you're talking to and you have it on every single email whenever they talk to someone who is outside of their organization they get banner blindness almost immediately. And so what you want to have is some kind of positive security indicators that tell them when something is trustworthy and when it's okay. And this is actually a core part of our approach in terms of being able to build out a trust network where if I'm using a product that uses uh what we call the reckon private core and you're using a reckon private core application as well when we communicate we become part of that trust network and now we can provide positive trust indicators that uh allow you to basically accept this information almost subconsciously so you don't have to think as much. So an example of positive trust indicators is uh TLS. So when you're visiting a website and you used to be able to get that lock icon on uh many different uh uh browsers that gave you this positive trust indicator that as soon as it was missing on a site where you were giving your credit card information, you would start to feel a little bit weird about that. You're like, you know, why is this not an encrypted connection? And that was just a very simple kind of trust indicator. you could have much bigger and uh more uh obvious trust indicators. So another example of that is uh the blue bubble green bubble distinction that Apple has made in iOS. So if you're communicating with another iPhone user, you actually get endto-end encryption built in >> and that shows up as a really simple blue bubble. >> And so the user doesn't have to think as much whenever they're communicating in the blue bubble world. blue bubbles are safe and then when they get SMS spam they get a weird feeling about that and because that's always showing up in the green bubble world. >> So you've come out of stealth. Am I correct in assuming that this is design I'm sure it has mass usage but is it designed for high net worth individuals for executives within Fortune 500s like who is the ideal user for a technology like this? >> Yeah. Um, that's a great question and I think that there are folks that uh have uh had bad experiences with uh fraud online. Unfortunately, an increasing number of people have had such bad experiences and th this is of course uh the those are the types of folks that we had in mind when we founded the company and we wanted to be able to protect friends and family members who have experienced fraud. Um my co-founder and I both have uh friends and family members that have had thousands of dollars uh stolen from them. But of course large corporations and uh governments and large organizations and high netw worth individuals and executives also have similar kinds of concerns. So really this is a problem that is affecting everyone that uses online communications and all of our communication media are essentially uh getting overwhelmed by fraud especially because of AI now. So, you know, there was a study that was done a number of years ago that uh uh had uh an analysis of where is all of the email spam coming from. And what it found was that 90% of the world's email spam at the time was actually coming from just three sources. And so that's what automation enables. And so that's what's now possible with generative AI as well. So cyber criminals can use generative AI and attack millions of people simultaneously with highly customized messages. And uh you know this is something that all of our existing systems were never really designed to be able to deal with. And that's why we need to have essentially some kind of a guide. We we call the product Northstar because it guides people in the right direction. And uh it doesn't matter if you're an executive or an individual um uh as a consumer. uh everyone is getting affected by these types of fraud and scams. >> So the business is predominantly B2B, but it certainly has a BTOC usage case. Am I correct? >> Well, we want to be able to get to B TOC in the future. Right now, we've just come out of stealth and we're concentrating on uh being able to protect large enterprises and governments. >> And if I'm Jamie Diamond and I have Reken on my device, >> Yeah. and I'm talking to somebody at a hedge fund, does that person also need to be a reckon user for it to be validated or you know what's the nexus >> that that's uh a really important distinction because if Jaime Diamond is using uh the Northstar product just by himself, then he is protected against all of the spam and fraud and uh uh social engineering that's directed against him, >> but if he is then communicating with folks in his organization who are also using the Northstar product, he gets an additional layer of protection. And so that's what starts to give the positive indicators that similar to the blue bubbles that uh you know, now you've got uh uh a trusted communication that's been established. >> Okay. So, it's fascinating. I mean, it's a scary time. I see certainly see the market value or the user value in something like this. What stage are you guys at? You're out of stealth. >> Yeah. >> You have you PC's in place across enterprises. Talk me through what sorts of use cases or proofs of concepts you've had so far. >> Yeah, we've been working with Fortune 500 design partners and uh making sure that uh the technology works really well. And so that's what gave us the confidence to now come out of stealth and make this available to the broader marketplace. And so that's exactly who we're engaging with. We're thinking primarily um organizations that uh are uh trying to deal with these types of problems at a large scale. Those are the folks that we're concentrating on right now. But ultimately, we want to be a solution for everyone in the market. >> And the business case, it's lic based, usage based. How how's it commercialized? >> Yeah, it's seat based. >> Seat based. Okay. Per user. >> That's right. >> Um and I guess last question to you, I mean, you've been in the industry quite a while. It is a very interesting time in cyber. I mean, I think everyone can see or hear that. We hear a lot about the world of cyber and how hard it is to take on some of those incumbents that have been in the space for a while. We've had some very high-profile cyber CEOs on here and say, you know, everything's going to converge eventually, right? You've already sold a company. How do you think about this time as like, you know, again, a next time founder, you know, what where do you see this industry headed? Do you think that the it's too saturated? I mean, obviously not if you founded a company, but how do you fight back against the challenge of what is somewhat of a saturated industry at a noisy time, right? It seems like everyone's promising to fix all your problems. >> Yeah, I I I think that uh it's really about the market that you pick. So uh the question that everyone has about every single startup is is this truly a standalone company in the long run or is this more of a feature of a larger platform and you know could someone else build this technology and just simply include it within their larger platform that already exists and has a whole bunch of customers or is it really difficult to be able to uh recreate that? And so this was one of the reasons why we were trying to come up with something that had never existed before. And we spent 2 years of R&D figuring out whether or not this technology was even possible. Because when you think about using AI in this kind of a context, what most people think of today, and this is what the the market looks like, is putting a wrapper around one of the big frontier models. So uh you know, having chat GPT or uh Claude analyze all of your messages. And there are a couple of problems with that. >> I mean, there's some fundamental problems with that, right? Like, you know, but please continue. >> Well, well, I I think what you're probably alluding to is the privacy issue. >> For sure. You don't want >> It's poacher turned gamekeeper, right? Like, you know, in if we're talking frankly here. >> Exactly. It's basically a non-starter to have all of this highly confidential data um being analyzed and potentially being used to train someone's third party model. In fact, it's even a liability from a security perspective for you to have a security company analyzing all of that in their own third party environment. And there are a number of different uh you know companies that have you send your most confidential data to their third party cloud to analyze. And so the privacy issue was one of the big things that we wanted to deal with. And doing that on device requires us to invent brand new technology that's never existed before that's capable of being able to solve the other problem as well. And the other problem is that it's simply too slow to have your device send your data. Even if it was okay from a privacy perspective, which it's not, of course, but it's too slow to send your data to a third party cloud to have it analyzed. At best, it would take several seconds to respond back. And that's way too slow to provide a just in time protection for users. And so, we needed to figure out whether or not it was even possible to have technology that executes on a device without a GPU. So, I actually went to Best Buy and bought the worst laptop that they sold and that was my testing device. And if it can run well on that device without slowing down uh the experience for users then we knew that it could run on any Fortune 500 machine. And so building that technology that is really the answer in terms of uh you know can someone else just simply recreate this. It's not something you can vibe code. It's not something that uh is uh trivial to be able to create. So that's one part of it. The other part in terms of, you know, being able to distinguish yourself and grow over time is whether or not the market is a broad enough market. And so what we're dealing with, we think of it as a problem that not only affects every consumer, every small business, and every large enterprise and government in the world. But it's also a problem that will never actually be solved. Even if we're highly successful, the problem will not be solved. There will always be crime. Cyber crime is basically the norm now. in terms of crime when you look at the amount of dollars that are stolen. And so it will simply morph into new forms. And what we want to create is a company that adapts along the way and becomes, you know, the uh uh the brand that builds a variety of different products and essentially becomes that platform in a brand new era. Well, it certainly ties in a lot of topics that we talk about here in NYC Wired because it's on the edge, right? Essentially, in terms of the device management and it's securing the future of whatever it might be that the inference generation or era is going to bring our way, which can certainly sound a little bit alarming when we think about it from a bird's eye view. So, thank you so much for joining us in NYC Wired. >> Thank you, Gemma. >> I'm Gemma Allen here at the Cube studio at the New York Stock Exchange. This is Cyber Security Leaders. One of our programs is NYC Wired where we talk about all of the threats and all of the hopeful solutions that will solve for the problems from tomorrow. Thanks so much for joining.