On-Demand Webinar

From Alerts to Answers: A Smarter Approach to Cyber Defense

How AI-driven SOC triage runs a forensic-grade investigation on 100% of your alerts in minutes — cutting alert fatigue and surfacing the threats that actually matter.

Presented by Connection · CNXN Helix
Runtime 45 min
Enterprise AI Series
Session overview

Turn security alerts into actionable answers

See how AI-driven SOC triage can investigate alerts at scale, reduce analyst fatigue, and surface the threats that matter so teams can respond with greater speed and confidence.

Presented by: Connection · CNXN Helix.

Full Transcript

Session transcript

Auto-generated captions, merged into readable paragraphs. Jump to any moment via the timestamps.

00:08

We never give up to fight is a must. We going in, we bringing the fire. We about to combust. We ready and willing to do what we gotta do. You can stop it. We put in the time we Hello and welcome. My name is Jeff Mushkin. I'm the Vice President of engineering at the Helix Center for Applied AI and Robotics.

00:40

And I have with me today my friend and a solution partner at Helix Jim McDonough, who's vice president of sales at In Inte Helix. As a full scope AI partner with our customers, operates with a security first approach and mindset. And while there are many aspects to security, a core tenant revolves around observability and monitoring of your processes, your systems, your devices, and your infrastructure.

01:07

It's a critical aspect to augment a zero trust, posture, environment, and mindset that you may have. And from a CISO perspective, cybersecurity is essentially the constant struggle to keep ahead with a myriad of, uh, never ending issues. With the additional system. Complexity introduced by AI workloads has greatly expanded the overall threat landscape that you need to monitor and deal with the compromises and breaches, uh, of your intellectual property, your data and your systems.

01:37

By not acting fast enough, these days will be more catastrophic and costly than ever before. So how do you get timely cost-effective and highly accurate visibility into the many data logs? Uh, the threat events, uh, the system logs all in real time. And that topic is what we're going to discuss here today.

01:59

So let's zero in on the observability and the actioning requirements at a SOC layer and that connection. We offer this capability in the form of services. And with the platform we're gonna discuss today, we can offer it as a standalone solution to our customers. So let's look forward, uh, to discussing the SOC capabilities that, that you offer.

02:21

And really let's begin by talking about where the platform essentially fits in the marketplace. Sounds Good. Thanks Jeff. Um, so at, in, uh, we focus on one of the oldest and really one of the most persistent challenges in cybersecurity. And that's the, uh, the analysis and triage of alerts in the soc.

02:43

Um, this is a challenge that's been around for, for 20 years, right? We're still, teams are still drowning in volume, complexity and, and burnout from these alerts. Um, but you know, what hasn't changed is, is, or what has changed, I should say, is the, the environments that we're dealing with, right?

03:04

So, uh, enterprises are dealing with dozens of security tools. Uh, AI workloads are expanding the attack surfaces. Uh, we're dealing with unprecedented skills and resource gaps, right? So, uh, what we address really is the core analysis phase of the, uh, security operations. And, uh, companies have really, especially enterprise companies, have reached a tipping point where they've been trying to solve this challenge for years, and it's not enough anymore to just throw bodies at the problem.

03:42

Um, and so, you know, that can be in-house soc resources, it can be managed detection and response services that you outsource to. The reality is, is that humans just, they, they can't keep up, right? There's just, they're, there's too much for them to deal with. So enterprises are out actively looking for a new capability, um, that can give them accuracy, speed, and coverage at scale.

04:07

And so this is where intas are comes in. Um, so we're solving this by performing a forensic grade investigation on a hundred percent of your alerts across all your tools within minutes. Um, and this doesn't require more people or process in terms of overhead. Uh, so for large enterprises in our, our our current customers today, you know, we've really solved that problem of the alert overload.

04:36

And they can now start to take their resources and use them for more proactive security measures, the things that they want to be working on. And I think we're gonna dig into the details, uh, in a moment. 'cause you, you've touched a lot of talking points that actually matter, but, um, what you're describing is not just important to regulated type industries.

04:58

This really cuts across as a universal problem. Absolutely. Um, you know, if you're operating a soc, you have, you're dealing with alerts from sim, EDR, identity Cloud. Um, your, your team is overwhelmed. You're absolutely a fit for, for what we're we're talking about. But I think with, with any new technology, you're going to see an adoption curve.

05:22

So what we've seen with our customer base in the last probably two years, the early adopters are large Fortune 500 companies, right? These are ones that have invested a lot of time, resources, money into building out the soc, the people, the process, the systems, uh, and as I mentioned, right? They've, they've, they've reached this tipping point of they're being asked to do more with less.

05:49

And the things that they've tried over the last decade haven't really resolved that problem. So, um, they're turning to, to AI as a potential solution. But that doesn't mean like we've seen recently, especially medium to smaller sized companies that are coming to us looking to solve the same problem.

06:08

So it's absolutely, it's a universal, it's a universal issue With regard to the system itself. A lot of customers will think in terms of what they already have in place, that the rapid sevens and the CrowdStrike and, uh, Splunk and so forth. But how do you migrate all of that capability up another level?

06:30

And that's the uniqueness that your platform is bringing to the table. So let's talk about where you're, where you are unique and how you bridge some of this capability that our customers may already have. Yeah. Yeah. So there's a couple things there, right? So one in terms of like your, your existing ecosystem, we just plug right in, right?

06:49

Um, it's, it's all driven through API connection. So instantly we can be connected to those, those different alert sources and, and be triaging. Um, but the reality is, is, you know, everybody is out there applying AI to the problem. Uh, where instances is unique is in the depth of analysis that we've built into our AI analyst.

07:14

So what I mean by that is we aren't just relying on LLMs to, to solve the problem, right? We know that it takes more steps in depth to get to the right conclusions. And so we've layered in AI deterministic methods plus security tools that mimic like the most elite tier three analysts in the world. And what that gives you is a, you know, on day one, what looks like in the most elite SOC team that you could possibly have, because you have that depth of analysis through our technology.

07:55

Jim, what you're saying resonates with me. Um, because my days at the National Security Agency, we were dealing with threats on a daily basis, and your system genetically, but also with human in the loop, um, is proactive with, uh, searching for these threats. And there's low latency in the moment of capturing that threat to delivering it to all of our end customers. Can you talk about that?

08:20

Yeah, absolutely. So, um, to go maybe a little bit further into like what that means in terms of the depth of investigation and what, what the system is doing. So it's going to enrich every signal. Um, it traces behavior inspects code analyzes processes and cloud events, uh, to produce a clear evidence backed verdict in under two minutes, right?

08:47

So, um, it's, we aren't just relying on the surface level, um, data and investigation that an LLM can do. Like I said, we, we, we have the deterministic methods, we have the security tools built into the platform that are going to mimic exactly what an elite analyst would do during that investigation, right?

09:13

Um, so it really does give you the depth that you need to feel like you have the right answer that's accurate and fast. Yeah. And for you as our customers, when you're dealing with a, a platform that can handle nation state level capabilities in real time, that's not something typically a commercial environment has the capability or prowess really to stay on top of, uh, in a real time, uh, manner.

09:44

So this becomes critically important. Yeah. You just mentioned, uh, the timeframe mm-hmm. Uh, that you're redu and is really a reduction in timeframe to get to a solution. So we, we were starting by talking at a high level about the technical benefits, but, uh, let's talk about the core operating benefits, uh, that, uh, the customer will see by utilizing the system.

10:06

Absolutely. So I think this is where, um, you know, customers feel the impact the most, uh, and, and then the fastest, right? Um, so you, there's, there's a few areas. One is time savings, right? Like the average investigation that an analyst will spend 20 to 40 minutes, um, fun average can be much longer than that, uh, on a single alert.

10:31

And so in, are gonna resolve that in under two minutes, sometimes faster, but, you know, never over two minutes at a massive scale, right? We, we can handle thousands lower alerts. We don't care if it's high critical, low informational, we're gonna treat them all the same, and we're gonna do that in under two minutes.

10:49

Uh, the burnout, right? That, that teams deal with, uh, on a, on a daily basis. So we're gonna reduce that burnout most. So cite that they're, uh, you know, they're experiencing 60 to 70% burnout rates, um, which is, you know, it's, that's significant. And so when an analyst no longer has to go and work on the low value things that are, that they, they typically deal with in the soc with this such high volume of alerts, uh, you know, now they can, they can focus their time on the things that a security analyst wants to focus their time on reducing risk threat hunting, detection, engineering, um, which significantly boosts the morale of the team

11:33

and makes them so much more effective. Um, I think one of the most important things is the accuracy and getting it right in the consistency, right? So, um, if you're gonna turn to automation, you wanna make sure that it's getting it right, right? And, um, it's one thing to be fast, but it's another thing to, to be accurate.

11:55

Uh, and even some of the best human based teams aren't gonna get it right all the time. Um, so when you layer in the speed plus the accuracy of the system, there's an immediate benefit there operationally. Um, and then the last thing I think, which is really important is the coverage model, right? Because the volume is so high in the soc, the reality is, is that most organizations are focusing on the highest priority alerts and to either putting something in a backlog or just forgetting about the medium to low informational alerts, it's just too hard to get to them.

12:36

And most of the time there's nothing in there, but we see over and over again that there are, uh, you know, a low percentage of time, but serious threats within those, those, uh, those low and informational alerts, right? And so having that coverage across 100% of the alerts that come in with the speed and the accuracy allows us to, you know, find things like nation state actors that, that are hiding in those loan information alerts.

13:08

So, um, you know, I think it's, it's time savings. It's, it's, it's reducing the burnout, it's providing the accuracy and the alert coverage that are, are critical. And, and you're getting that in a incredibly fast time. Yeah. You were talking about burnout, and that has multiple ramifications. Um, one from a security posture standpoint that causes concern mm-hmm.

13:30

If they're not paying attention. But the platform itself actually does something for those, uh, users of the information. And that is, you not only identify critical alerts to focus on, but the platform provides enough of the detailed background information so that that high value, uh, security analyst then not only has the alert, but they actually have a lot of the reconnaissance, again, reducing not just time, but accuracy in remediating the particular event at hand, right? Yeah, Absolutely. So we, you know, we're not just triaging and investigating closing things out when we escalate something.

14:09

It comes with complete context, right? Around exactly all the steps that we took to get to the verdict, the actual verdict, the classification, and next steps. And if possible, if you need it to be remediated automatically, you can do that as well. So we have this platform and now we need to allow our customers to operate and manage it effectively.

14:31

So if I was, let's start with a, an example of a, a large custom. Sure. Let's think about the, the size scope, and what is the typical implementation process look like? Yeah. Yeah. So, um, you know, large customers, we have like some of the most notable Fortune 500 companies in the world, right? Like Nvidia, Hearst, Equifax, Salesforce, tetrapak, they're all using our platform today.

14:58

These are sophisticated. So they, they, you know, when you think about they have people, they have process, they've invested in security tools across the board for detection, for remediation, for case management. Um, so, you know, our, our goal is to plug right into that ecosystem seamlessly. Um, it's all driven through APIs, right?

15:23

So we're, we're connected into EDR SIM reported phishing. All of those alerts now will flow instead of to, whether it's their in-house SOC team or, you know, potentially an outsourced service. It'll first go into the inci platform for, for triaging investigation. Uh, and for the larger organizations, they want, uh, they already have a workflows and systems built up, right?

15:52

So they, they want not only for us to be able to do the triage and investigation in a timely fashion with higher accuracy, they want us to also be able to plug right into remediation workflows into case management and creating tickets, right? Because they've already invested in things like SOAR and, uh, you know, case management tools.

16:13

So we, we will plug right into the detection systems, do the triage and investigation, and then understand their exact workflows, um, and plug right into those, right? So we're only escalating on average, about 4% of the alerts that come through in an enterprise system. We'll then send that to wherever the team typically will receive an escalation.

16:39

Uh, that could be the soar, could be the case management, could be something like PagerDuty, it doesn't matter to us, we're just gonna send it where they need it. Um, and so it really, from an efficiency standpoint, it goes beyond just that triage and investigation. And in the large organizations, it's all about plugging into what, what they had today and, and fitting seamlessly into those workflows For our larger customers, that 4% number is profound because, uh, in some of the examples you just gave, they're dealing with hundreds of thousands, if not millions of alerts on a monthly basis, given the complexity of the systems and the integration, right?

17:16

Of those solutions. So dropping down human interactions to 4% is significant in cost savings and time, but most likely probably in catching real world critical events. First getting lost in the noise, Right? Yeah, yeah, exactly. Because, um, you know, you think about that, the numbers that you just put out there, like, we see that in, in real time every day with these customers, right?

17:41

Thousands of alerts coming in, and, you know, even the largest organizations in the world that we work with, like, you know, they we're not talking about hundreds of analysts that are, you know, working around the clock working on these, these, these alerts, right? And so it's, it's a real problem from a resource perspective.

18:00

And like, you just can't, humans cannot get to that volume. Um, and, and so automatically right outta the gate, you have 100% coverage of that, right? And it's reducing it down to the things that matter most so that, you know, those limited resources, all of the, the, all of their time is diverted to obviously the things that, that are escalated and need to be looked at.

18:27

But then they can go and be proactive, right? And start to do things that reduce risk that, you know, help the organization become more secure, do the threat hunting, do the detection, engineering, the things that all security teams are striving to, to get to you. So focusing on large enterprise, we run into a myriad of issues.

18:50

Um, but this actually, I'm going to talk to you about smaller, uh, enterprises in a second. But before we do that, the larger enterprises naturally already have a lot of systems in place. Um, the sims, the source, and the authentication capability, uh, within this platform, we have over 50 connectors, essentially to disparate solutions.

19:14

So a lot of our customers, uh, have Rapid seven and Splunk, um, on one side of the house, we have Mimecast and a whole host of capabilities on the email and, uh, authentication servers. You have a whole host of connectors. Just talk a little bit, not in detail, but a little bit about how we think through the connectors and how many there, there really are, there's quite a bit for large medium, and then we'll talk about small companies in A moment. Yeah, of course.

19:41

Um, so there, there are the, the connectors that we just have out of the box, they're API driven plug and play. You, you, you just get the API key, you put it into our UI alerts start flowing, and you know, there the alert triage investigations happening. Um, that being said, if there are sources, which the, the longer we go on, there's very few that we don't have something natively built already.

20:09

But if there are sources that, um, our customers have, uh, would like us to ingest, that's, that's relatively easy for us, right? Because we can just connect, uh, via webhook and ingest those alerts. Um, the, the, the actual time to, to triage and investigate. That may be a couple more days because the system needs to learn it.

20:33

Um, the data model, the, just the overall, um, you know, processes that go on within that company. Uh, but it's, it's, it's very seamless. So if there's something that we may not have as a connector today, it's, that's something we can, we can add very easily This, this concept of integrating quickly with connectors, and by quickly we're talking about a matter of potentially minutes to hours.

21:00

But, uh, this is not days, weeks, months, uh, to get you from having no implementation to getting full alerts in a matter of hours. Literally, uh, for smaller customers, they may not, they might not have this infrastructure already in place. And, uh, clearly at, uh, he connection Helix, uh, we spend a lot of time on all aspects of security.

21:24

And so we implement those systems and bring them into our large, medium small customers. So rapid sevens and, and, uh, Splunks and so forth. So once we have that infrastructure, your platform sits perfectly regardless of size going down to even the smallest a thousand endpoints, uh, and, and below and below, Yeah. Yeah, yeah, yeah.

21:46

And like what we see with the smaller customers is, um, yeah, they typically, maybe they don't have all of the, the, the systems in place. Like they may not have a SOAR or a case management system. Um, and, and so there's, there's more maybe, uh, custom workflows that we might do for them, or we have remediation capabilities, right?

22:11

So like a large organization that's spent the last 10 years implementing a SOAR and has playbooks built out, we're just gonna plug right into those. But if you're a smaller organization and, you know, you, maybe you only have three security analysts, and you don't necessarily want somebody to be woken up in the middle of the night for something, we can build an auto remediation even without them having a soar, as an example, to isolate a host if we escalate something, right?

22:41

So it, it absolutely can fit within a smaller organization as well. Um, it's, it's really just about kind of understanding exactly where they are in their, their maturity of, of, of building out the soc. And I think that's a natural reason for our partnership in general, is that, uh, connection has the ability to take that customer without any of that infrastructure and get them started on the platform to start solving a critical set of features, but also, uh, maturing that infrastructure capability and bringing in those solutions that are well designed, uh, to be hooked into your connectors and your API Yep.

23:19

Uh, to continue the, uh, the build out of the NOx. So capability, uh, or just observability in general of their platform, the network and their, all the threat vector within. And so that, that kind of leads into a customer thinking about the time to value, which is critical in today's market, right?

23:38

Without that, we don't have much, and we just touched on one piece of it, which is, it kind of happens quickly if we, as we implement, uh, from a concept and a demo straight into live integration. So let's talk about the, uh, the time to value. What are the key metrics that a customer should be thinking about, uh, and expecting, uh, through an implementation?

23:59

Absolutely. So like, let's, let's think about like the traditional model and, and where I think most companies still are today, right? Is like, if you're going to solve this problem, it's typically going to be through, through humans, right? And that just in itself is, it takes time, right? Whether you're gonna go out and look to hire those people, train those people, get them ramped up and understanding the systems that you have or you out, and you, you hire an outsource service, uh, that in inevitably will take time to onboard as well.

24:30

Uh, the nice part about using AI and connectors is that, you know, we can, if you came to us tomorrow with a customer, said they're very interested, they want to see how this works. All we need to do is get API keys, set it up, and we are literally, it's like you have a sock ready to go within hours.

24:58

Um, there is a process of, you know, every environment is different. So our system will learn those environments to make sure, um, you know, we're getting the most accurate verdicts as we possibly can, but then again, we're talking days, uh, versus months, sometimes quarters to get humans up and running.

25:21

So the time to value is in incredibly fast. Um, and so all the things that we talked about earlier around, uh, you know, speed, accuracy, uh, a coverage, a hundred percent alert coverage, you're getting that within really a two week timeframe. Yeah. You, you mentioned, uh, that every environment is unique potentially, and you'll find within your own environment that, uh, there are particular events that are gonna continually trigger that might not affect other enterprises.

25:55

And so your system actually is well aware of that problem, and you have a solution to that. Uh, the individual enterprises can update their particular instance, uh, in a way that it provides the right amount of alerting, right. Criticality, uh, awareness. Um, but it could remove the noise of typical events that Yeah.

26:18

Might, uh, reject in, in a different organization, but are perfectly acceptable in yours. Yeah. Yeah. Absolutely. And, and that's part of like the, the onboarding process that, that happens through AI and in actual humans on the inor side. So like you mentioned, every every organization we work with is, is definitely unique.

26:40

Yes. And so we will, um, usually within that first two weeks, we're what we'll call more of like a reactive mode. We aren't turning on necessarily auto closure and, um, es automated escalations and, and those types of things. It's, it's really getting to the point where we completely understand your environment, process, systems, uh, procedures, so that once it is a go live proactive, we're closing false positives.

27:16

We're escalating things here, team, we've got, we completely understand it. Either our, our team of solutions engineers, uh, but mostly the AI in the system, And there is an automated feedback mechanism so that literally they can, you can literally button Go in, there's like a thumbs up, thumbs down, you can click it, you can provide feedback.

27:37

Um, so you don't even necessarily always have to interact with our team, Right? And for more complex issues, uh, we can script it away mm-hmm. Essentially, yep. Uh, create the right prompting in some respects, uh, from an AI perspective, but also traditional, uh, scripting to resolve. So it gives them not just more observability, but much more flexibility in controlling their environment, auditing their environment, managing, uh, the risk and critical nature of the Events. That's right.

28:07

So we talked about who would qualify, we'll use that term loosely, who qualifies for the platform. And there really two answers to that. Uh, one would be they're already up and running and mature in a particular set of infrastructure. So talk about, if I was to self-qualify mm-hmm. To just use the platform right outta the gate, uh, without requiring connection to integrate any further capabilities, how, how would you define that? Yeah.

28:32

So if you're self qualifying, I think it's, you know, you're, regardless of the size of the organization you work for it, it's, you know, are you, are you at a point where you are experiencing the, um, the, the overwhelm of, of, of alerts, right? Are, is your team doing too much manual review? They're in a completely reactive mode.

28:58

You can't get to a point where you are in a proactive mode that you are able to do the things that help you reduce the risk of your organization. Um, you know, and that, that typically comes with, you know, you've got the, the systems in place that are, that are pro, that are actually sending those alerts to the team, right?

29:17

So you've gotta assume you have an EDR, your employees are reporting phishing maybe to, to, to your team. Um, but you know, it really, it comes down to like, this sock is overwhelmed. You've tried to, to solve this maybe through automation, hiring, more people outsourcing, and you're still in the same spot, and you, you're, you know, a lot of times you're being asked to do more with us, right?

29:45

And so this is a way to come in and, and solve that problem almost immediately. Yeah. We also see, uh, mostly in, uh, regulated industries where even if they're not overwhelmed mm-hmm. With the amount of alerts, um, they still want that trusted layer of visibility into their platform. And this, this dashboard provides that, that this, uh, entire platform gives another level of assurance and capability so that all of their teams have an understanding of what's going on in the infrastructure, just to catch those anomalies that, uh, might slip through.

30:22

Yeah. Um, so it's not just size of endpoints that we're thinking about or size of alert logging that's coming through and how to handle it. Um, but also from a regulatory standpoint, uh, are you finding that as well as we are? Uh, yeah, definitely. Um, so the, one of the things that we see, uh, on a daily basis is that you, the detection systems are great, right?

30:46

But they're not always gonna get it. Right? And so you, let's talk about EDR, right? You may get alerts that will fire that show as a medium or low or informational. Those are, whether you're overwhelmed or not, those are typically not ones that you're going to prioritize and look, look at right away, right?

31:08

Because everybody's busy. And, but the reality is, is that the detection systems aren't gonna always get it right. And by having those alerts go to iner, we don't care if it's high critical or lower medium, we'll treat it the same way. And because we have that depth of forensics capabilities to go and do the investigation, um, we find many times that in those low to medium alerts, that there are real threats in there.

31:44

And, you know, so we can, the AI will take a look at the context of the alert, why, um, why was the alert fired? What's happening? Um, and then we'll go and do things like deploy a memory scanner on a host that will do a full memory dump and forensic analysis of that host. We've had some of our large Fortune 100 customers that, um, you know, uh, the EDR says this is lower informational, and that, you know, basically it's not something to, to really look at.

32:18

Um, and we've founded Chinese a PT on that host Yeah. Right? Within a matter of a minute and 30 seconds. Like, so Yeah. It's not always just alert fatigue and overwhelm. It's, it's, you know, the, these things can't happen, right? And every system can miss things. And so it's, it's that, it's that extra layer of, uh, detection and eyes on what's happening.

32:47

This is, this is critical because in the marketplace, the traditional threat vectors were always obvious from a signature basis. Like there was an anomaly, the anomaly was detected, uh, and then we thought about it and did something. Uh, but today it's much more sophisticated. Um, with AI workloads, it's even more sophisticated.

33:07

We're talking about malware capabilities that sit below the noise instead of above the noise. And so, without digging into memory dumps and, and really looking at what's going on at a processor level, uh, you're gonna miss quite a bit of, of new nation state level activity going on, like the China threats you were just alluding to.

33:26

And with this platform, we're not only going into the memory state, um, but we're doing it on every single alert coming through. Humans could not possibly do that. It's impossible with the level of volume, uh, that we're talking about. And this capability crosses every customer that we sign up, uh, to the, uh, the platform as it stands today, even without all of the disparate, uh, connectors, we can sit there with a SIM or SOAR integration alone, and you're immediately gonna start capturing probably new events that you weren't even aware were in your network. Definitely.

34:03

Yeah. And we'll, you know, this stuff happens even pre customer, right? Like this could happen in, uh, in a proof of concept. Like, I mean, I, this morning, you know, because we monitor everything that's going on, we have slack threads. I, I get alerted when something like that happens and, you know, this is like a daily occurrence.

34:25

Um, and, you know, so this is something that we even find before you're even a customer. It could be in a p uh, a proof of concept. And, and because you've, you just never had somebody looking at those alerts, all of a sudden, we'll surface something. Are there any particular top challenges that your customers are bringing back today?

34:46

And, you know, what are we doing to help resolve them? Yeah. Um, Yeah, there's, there's, there are a lot of challenges. Uh, but the, you know, I think one of the things that, that we can continually hear, um, I think especially lately is that, and I've said this, but I'll, I'll repeat it as like so many executives, CISOs, VPs are being told to do more with less, like, it's like a mandate.

35:22

And, um, that is not something that any security leader wants to hear, right? Because they all need more, right? Like, they need more people, they need better detection. They need, they need things that are, are going to help them make their organization more secure. But it's just the state that we're in.

35:43

Um, and so that's can be very overwhelming for a security leader to think about, like, well, how do I go, how do I go solve this problem when I can't go ask for more headcount next year? Right? Like, it's just, it's not even something that we, that is even a possibility, right? Um, we're already outsourcing some of this, so like, where do we go to try to solve this, this challenge?

36:09

And, um, and, and so that's like, I think a huge relief to, to the CISOs we work with is like, okay, we can go and really solve the challenge with AI. A lot of them are being told by the board, go, go try to figure out how to leverage AI to solve these problems. Right? We can't keep throwing more people at it.

36:35

Um, and so that, that for us is great because it's, it, you know, we can come with an immediate solution and prove that, that, that it works. Um, you know, and then I, I think the other, the other thing is just, um, just the noise that, that is in the market around, um, AI and, you know, the, the, all the different products and solutions that are out there today, right?

37:02

Like, um, I think we're uniquely positioned in that, like right now, one of the best places to turn and have a use case for AI is the soc, right? And so, um, and we, we have an answer to both of those challenges, do more with less, go figure out, go figure out where we could or should leverage AI. Um, and, you know, we're proving over and over again, SOC is the place to, to do it.

37:33

And I think, I think what's important to understand is that, uh, it's not AI for AI's sake. You're actually very specifically using the benefits of what AI brings to the table from an analysis standpoint, the share mass volumes of analysis. Uh, but we still have a, a lot of human in the loop behind the scenes sorting out these threats.

37:54

Mm-hmm. Um, not necessarily processing them, but ensuring that we have a hundred percent accuracy internally, um, that translates to 97 plus percent accuracy externally. Um, but when we think of, uh, hallucinations and, and real world events that are a big problem in the security mindset mm-hmm. Um, catastrophic in, in what you do, um, you eliminate that capability because of how the models are trained, how it's specifically brought in internally, how there's always a human in the loop in that training to verify Yeah.

38:29

Um, that we're not making things up, uh, in real time. Yeah. Yeah. We, we consider ourselves a security company, not an AI company. Right. Um, and I, I really think that that is important and a huge distinction, right? We apply AI to solve a security problem, but we are a security company first, right?

38:47

Like our founders are our, you know, our CEO is a commander and the IDF of the incident response team, deep, deep security knowledge. Um, we have a research team, like a world class research team that collaborates with some of the best out there, Mandy and SentinelOne. Like they're, and they are all tasked with making sure that the models, that we are getting it right.

39:12

Right. So yes, the majority of the things that are handled are through the system, through AI, through our deterministic methods and our security tools. But there is a human in the loop. There always will be. 'cause like I said, we are a security company first, um, AI second, and, you know, we put the world class teams behind it.

39:32

And you, you touched on kind of the trend going on right now in cybersecurity, which is looking at nation state level and blending it with commercial level and dealing with anomalies as we normally would. And I think that is what makes the platform special today, because that's not necessarily how any other solution on the market would typically work, right?

39:57

Right. Yeah. Yeah. It, it really is about, you know, that that depth, the depth in the forensic capabilities that we have, um, not just relying on LLMs, uh, that's part of the chain of how we will triage and, and analyze something. But, um, we will continue to go down all the way to, you know, a memory dump in forensics, if that's what's it takes to get to, to the truth, to, to the verdict that we need.

40:28

So I think as, uh, the interactions get more complex over time, uh, the value that your team is really bringing to the platform is how you triage the knowledge, get that into the training system, get that learned by your platform. Um, and that is on a daily basis at this point, uh, yeah, that's how you're dealing with threats.

40:49

I think that that's important from a security posture. Um, and then so what happens with the unknowns? Hmm. Yeah. Um, well, you know, I think the, there's always gonna be, right? And so the way that, that our platform handles it is, is really through, um, our ability to, to go beyond the surface level, right?

41:17

Um, we do everything from static dynamic analysis code, genetic code analysis. Um, we will run things through sandboxing, um, like all the things that, that an elite security analyst would do, both from a skills perspective and tools that's built right into the platform, right? So we're gonna go through every single detail of what, what is happening.

41:45

We have a repository of, of binaries of known, malicious and known good that will we'll run through. And, and, and we could find the smallest little code snippet, um, of malware that's been reused as an example, right? That, that our system will pick up, could be a threat that's never been found before.

42:09

Um, and it's constantly monitoring and updating on a daily basis, right? So we're able to find those, those unknown threats, uh, with, with all the different techniques that the, that the platform uses. It's fascinating, Jim. Uh, we can talk so much about, uh, lower levels of, yeah, capability sets and, and how this works and how it actually impacts our customers.

42:32

But, uh, we're gonna leave it there for this session. And I think what you really heard from Jim in our conversation today is that saving time and gaining accuracy and lowering your human resource utilization, that really is the key in capturing a hundred percent observability and dealing with remediation.

42:53

It's critical to your process to protect your organization and that connection helix, uh, this capability exists in the form of managed service offerings, as well as, uh, reselling of, uh, standalone offerings with our partners, uh, that provide to you directly, um, this capability as one of our customers.

43:12

And our team works very hard to provide the best security protections across the ecosystem, whether you're, uh, mature or you're just getting, uh, started with, uh, protecting the infrastructure all the way up to a sock knock, uh, capability. And we do that in an unequal, uh, level of, uh, service and, uh, support.

43:34

So what makes our partnership, uh, unique is that, uh, within, uh, helix, uh, we look at the in, uh, core platform, but, uh, we're working together in the long term as a strategy to integrate, uh, helix AI capabilities, specific capabilities, um, to the core platform. And this is gonna deliver even more value and security, uh, to our customers in particular.

43:59

So with the mindset of us always being a security first, uh, approach and mindset to AI implementation, that is the core, uh, ethos within, uh, helix. So if you have any questions, uh, are you ready to engage in, uh, securing or enhancing your security around the infrastructure you have in place today, your traditional IT infrastructure or securing, uh, the AI workloads and infrastructure?

44:26

Um, you can reach out to, uh, your connection representative that you have today. You could also reach us directly at the Helix, uh, website, and that's connection helix.com. That's CNXN helix one word.com. So thank you, Jim, for, uh, joining me today. I appreciate that. Thank you, Jeff. This is great.

Get Started

Ready to put this into practice?

Book a call with our team to map applied AI to your operations — no pitch, just a working conversation about what’s possible.

More From The Series

Keep exploring