The Mythos Era: TPRM Evolution, AI Ethics, and Project Glasswing with Matthew Moog

Transcript

Host: Hi everyone, I'm Purusottam (Co-founder - Cloudanix). Thanks for tuning into ScaletoZero podcast. Today's episode is with Matthew Moog. He's a seasoned security professional with 20-plus years of experience. He's a principal at EY as the financial services risk managed services leader. He also served as a general manager for third-party risk management at OneTrust. And he brings deep expertise in third-party risk management, financial services risk and GRC.

Matt, thank you so much for taking the time and joining with me today in the episode.

Matthew: Yeah, it's a pleasure. Thank you for having me.

Host: Absolutely. So let's kick off. So primarily we want to focus on third party risk management, AI, project glass wing, and the whole landscape. But before I start, I generally ask this question of all our guests, and we often get unique answers. What does a day in your life look like?

Matthew: I I get that question a lot and it is is it's incredibly variable. as you can imagine in in a consulting world you're serving different clients, you're dealing with different issues. I have very few things that are kind of routine. I might have some one-on-ones with some of my team. I the I have one on ones on a monthly or quarterly basis with some of my clients just to make sure that we're keeping in touch and and kind of catching back up.

But from a day-to-day perspective, it it really depends on the needs of the business. It it depends on the needs of the clients that I'm serving. it could be a day where I've got four hours to really spend in thought and strategy and looking forward at the next fiscal year. It could be a day that's completely what I call death by a thousand paper cuts is you know, usually where I start out somewhere around eight o'clock and I end around six and it's just half hour meetings stacked up back to back to back to back. yeah, sometimes I'm traveling three, four, five weeks at a time. Sometimes I'm working from home for three weeks straight. So it it varies depending on the the needs of the business and and how projects are flowing.

Sometimes I need to dive deeply into a project and spend two or three days with a client. you know, sometimes I'm spending dedicated time with my team's talking about sales strategy, solution strategy, technology enablement, other things like that. So yeah it could be it could be very different from day to day. It could be very different week to week. But that's I think what it keeps what keeps me excited about the work.

Host: Yeah, I was going to say like you don't have a lot of monotony, right? You have very varied schedule even by by days. So yeah, I'm pretty sure there is a lot to look forward to on a daily basis. So awesome. So let's get into the security aspects, right? So you have you have spent over two decades in security and risk management and majority of the time you were at EY.

What drew you to this space earlier like why security and risk management?

Matthew: Some sometimes I think it's by chance. I'll go back a little bit before I started EY. I was on campus at RPI where where I went to college. And the year before I had gotten an internship with Anderson, and that's when Enron happened. It was the kind of 2001 time frame. And you know, that internship didn't come to fruition because the firm was having those challenges and people were kind of leaving in masses.

And the the next fall I was coming into an interview at our campus center and I was having a a conversation or an interview with a communications company. I won't name them, but I sat down and and you know, they peeled off a piece of paper that had form questions on it and they asked me those those questions.

And for the first three questions I had the same answer because it was essentially the same question, just worded differently and I said it at what point in the interview are we going to get into interpersonal nature and and and kind of how I'm a good fit maybe for the company and the company's culture and and and strategy. So it's a lot to ask from a student coming into a large corporation.

I kind of laugh thinking about it now because I yeah, I had no idea where kind of I was in the grand scheme of things. and after that third question, you know, there was a kind of a well, you know, these questions are tailored to find the best candidates. And I just said, with all due respect, I don't know if this is the right company for me. And I and I got up and you know shook hands and walked out of the interview. and it this is a an interview center that that's got a long hallway and every single room off to the side is all glass doors.

So within the first five minutes I walked got up and walked out and you could see the faces of the people on either side that are in their own interviews like, where's that guy going? and as I walked out the woman who I had originally interviewed with at Anderson was now at EY and she was standing the in the you know in the in the hallway and she said Matt you know we don't have you on our on our interview schedule and I said well I you know I I didn't really know what EY was and I didn't you know I just I didn't submit a resume to it and she says Do you have a resume? I said yeah so I gave her a resume and she said well we'll call you if we can fit you somewhere in.

So I sat in you know, in in our fraternity house with my suit on, waiting for that phone call almost all day. I was doing some work and and catching up on some papers and it was time for me to go to lacrosse practice. And so yeah, I got dressed and went to lacrosse practice. I was just about to step on the field, it was around five thirty, and I got a phone call and she said, Hey, can you come interview?

And I said, Well, do you mind if I interview in a t-shirt, shorts and flip-flops? Because, you know, it would take me forty five minutes to go back home, change and get back over to the campus.

So she said, no, not a problem at all. So I I walked in and I interviewed with EY in a t-shirt, flip-flops and shorts. And you know, still still very close with the people I interacted with as I came on. But that was kind of the first thing of chance of of why I ended up with EY. I chose financial services because I was always interested in capital markets and I thought that would be interesting because you had kind of two tracks of choice. You could go to our what we call a commercial business or our financial services business.

So I went in that direction. and my first day coming into the office, I remember I went to training and they were talking about auditing. And I said, Well I I thought I got a consultant job. Like I was gonna be a consultant. And as part of the basic training that everyone goes through, we all go through audit training, or at least that we did back in 2003.

And you know, I quickly realized that my consultancy was basically being on the audit teams, but on the IT side of that, where we were looking at systems and flows and controls and all these things.

And if you can remember back in three combustion, in two thousand three, you know, Sarbanes Oxley came in in you know, two thousand three, two thousand four. we were mapping out system flows and data flows and control structures for the first time ever because that was the requirement that we had under the PCOB and you know nothing really existed. So I found it very interesting to just understand how the business worked.

How did a trade get from the front office into the back office? How do things get valued? you know, how does the the kind of balance sheet used to you know, to to treat different types of investments and in different accounts. So I was the curious kid in the audit room, trying to ask questions and I'd go into, you know, the audit side of the business and say, I got a dumb question. What's a repo and how do you net it?

You know, and or what's the securities lending process look like? Or how does a fixed income security settle? And and you know things like that. So I just got in interested more in the capital markets aspect of it and then and then I got more involved in in the retail side but for me, it was just really fun to understand how the business operated. And as I continued to go on that path, you know, Lehman Brothers was my main client, so maybe that dates me, but we went through that kind of whole experience.

And then in 2008, I got kind of pushed over into some risk and regulatory work and some data analytics work, and I think I did some Nasdi Oates trade processing work, and and I finally made my way into third party risk, and that was also by chance. I just happened to be kind of free for a couple of weeks and I got picked up on an engagement.

Engagement and probably for a role that I wasn't qualified for, but you know, we all figured it out. And you know, that led to the next third party risk job and the next one and the next one. And then two or three years later I realized that I had served eight of the top ten banks and I kinda had a viewpoint on where the market was going.

So I kind of rode that because in the wake of the mortgage crisis, third party risk wasn't just third party risk as a cyber practice. It was resiliency, it was compliance, it was it was product level compliance as well. As you look at things around cards and mortgages that that kind of led to the crisis itself. and that's expanded out into model risk and AI risk and all these other things that we're facing today.

But for me, that was just an interesting space to be in that I felt like I could I could play an enterprise risk management role, but while still focusing in one of our businesses very

Host: I love how how really you remember how you started your career, the interview, the meeting with someone at EY in the hallway and then the lacrosse practice. Like it feels like you're just it was yesterday, right? Like the way you are explaining, right? It feels like it was yesterday. Now I know that you moved to third party risk management at one point and you are focusing on FinTech, is one of the highly regulated areas. How do you see the, like, how would you describe how it has evolved the third party risk management from when you started to where we are now?

Matthew: So I I I think it's probably a couple of different waves, but I think technology has a big is a big reason for some of these changes. I I think all of us thought that certain things could happen, but the technology wasn't there yet for it to be able to happen. So early in my career, when we looked at third party risk, it was really cyber focused. It was assessment focused. You know, we were doing a lot of control self-assessments.

I I think it crossed our financial services division in like the two thousand ten to two thousand fourteen range, we were probably doing somewhere between fifteen and twenty thousand assessments globally. and I would say thirty percent of those were boots on the ground on-site assessments.

So on any given day we roughly had ten to twelve people that were somewhere at a vendor site doing some level of an assessment across the globe. so it it became like a very big operational factory of logistics and approvals and making sure there's no conflict of interest or independence issues and it we we really got into the complexities of the business.

So that was kind of the that first wave where it was really just workflow and assessments driven. and then we started to see more data evolve. So you had resiliency data with companies like Rezolink, you had cybersecurity data with like BitSite Security Scorecard and and some others. there's been some consolidation of that market more recently. I know MasterCard bought record future and then risk recon before that.

So there's been some degree of positioning, but then we started to see organizations see the price of data for cyber ratings kind of go down. And then they started to make differential decisions to say that, you know, maybe instead of choosing between assessments and data, we can have both.

And I think as those price points came down, then most organizations started to use both as intelligence from an outside looking in as well as assessments which are kind of inside looking out and then I I think you you know you move to like the twenty eighteen to twenty twenty two range where some of the capabilities of being able to aggregate data and to to find risk that may exist in a sector could be kind of inferred to other parts of that sector or inferred even across an organization. We got way better on things like zero day vulnerabilities, and and resiliency started to take hold as more of a main factor. I mean, you went from kind of cyber to to compliance to resiliency. and I think r resiliency probably still holds true today, but you know, it was around that time where you really started to see things fail with respect to COVID pressure on the system. You know, I I worked with an organization where they could only take 13% of their calls coming in from retail banking customers for about two weeks.

So you know, and and there are other organizations that could handle that, you know, those those issues from a where are we working perspective. you know, how how resilient is your business and being able to move workflow between locations? and we saw a lot of rationalization of different types of activities. we also saw organizations rethink how they looked at enterprise critical third parties because when you when you look at the criticality of a third party, typically that's almost always going to be relative to the business process that it's supporting. but there were some areas where maybe the recovery time objective could be twelve, twenty-four, even thirty-six hours or more.

But the time to replace that third party might be a month. So if you're looking at third parties that maybe were having financial issues or or challenges there or you know, maybe they had a a ransomware incident, they weren't able to provide services. if if you're t looking at a month to switch services, then you have to kind of prepare yourself to be more resilient in that grand scheme of things. So I think that that kind of evolution happened. And then what we're dealing with right now is is really a lot more around the automation aspects.

I think we started out with RPA, then we moved a little bit more towards Agentic. Obviously, the large language models, and we'll talk about that a little bit later, started to play a role. And I think there's kind of three main buckets we need to kind talk talk about AI today. agentic kind of sits on top from everything. you have large language models that are built into intelligence suites that sit within that kind of middle layer. And then you have the large language models themselves, which are kind of acting as almost operating systems today, where they're building SaaS capabilities on top of those large language models as opposed to just using them as a knowledge resource and embedding them in.

We've seen new entrants into the market from a technology perspective. We've seen new ways of of working relative to acquiring information and data. There's a company called Fabric that really kind of acts as the plaid for third party risk and and the interconnected tissue across that ecosystem. I think if those tools were in place when you know when we built TrueSight and some of these other KY three P and these utilities almost a decade ago, there probably would have been a better outcome, I think. But

You know, the idea is sometimes it just doesn't match up with the timing of the technology capabilities and you know, we end up kind of evolving a little bit differently and you know, we are in the spot where we are right now. But I I I think all positive things. Anything that you can minimize the busy work to get to the real risk management, that's always a plus.

Host: Yeah, I think you navigated it really well, like for some challenges, the technology was not ready. So we had to work around it. Now that the technology is ready, we are trying to do a lot of automation around it.

But with with let's say the AI LLMs and the agentic workflows, the harnesses and everything, they of course give you benefits. They also come with some challenges, right? So how do you see AI providing benefits and challenges? Is it more automation or you are also thinking about agentic workflows? How do you think about securing it? What are your thoughts on the benefits and challenges of it?

Matthew: I mean, I I think we're all trying to realize the benefits. I think I'll start with the challenges. you there there is a such a huge risk right now of over reliance on AI. I mean, I I've used I just got through a three-week piece of larger pursuit we were working on, and we used a lot of copilot from a formatting and framing of the slide perspective. But what we also had to do is we had to save and kind of give a snapshot of the file that we were working on before we did something like that.

And then once that work was done, which it saved us hours, like don't get me wrong, we had to go back and side by side review every single slide to make sure that something wasn't interpreted incorrectly or it was shifted into this format wrong, or maybe it combined two slides or two calls into one. So there was definitely a lot of making sure that you know what the what the AI was doing to help us was actually right.

I mean, there's been tons of articles of people having undue reliance on fake links and sources and things like that. And and, you know, I think that presents a risk for people just relying too much on on on AI. I think also, you know, I remember back early in my career, we would we would sit around and deeply think about certain things. How do I approach this? What does this mean?

If I got a data set, I remember I had to go back, I think it was my senior two year. I was working on taking all the raw journal entries from Lino Brothers and recreating their income statement, balance sheet. I can tell you that the first ten times we could not get it recreated. But as we went through it, we realized like, there's topside adjustments, we didn't account for those, or these accounts that are assets in a negative position become a liability.

You know, some of these transactions are treated differently as a as opposed to account mapping. So there was a lot of critically thinking through the process to make sure that we fully understood it and then to get to the right result. I it was I I d I remember a story that I was I was working late, trying to get this thing to balance. I think everyone was at the account Christmas party because, you know,

They they just we had a large account team and and and everyone's at the Christmas party. I remember walking in around 10 or 10 30 and the coordinating partner was there and I gave him a nickel and I said I couldn't make it balance fully. I was off by a nickel, but hopefully that's close enough. and I I kind of fast forward to that. I mean, when when I when I use AI and I interact with a bunch of different tools, I know what I'm expecting out of it.

Now If I'm looking for deeper intelligence or research and stuff like that, it's really nice to be able to get that information in context and and quickly. if I'm looking to format something a certain way, it's really easy to be able to go do that. But I know exactly what I'm looking for in the output. And if it if it doesn't provide the right output.

You know, I'm telling it. I'm I'm sure most of your viewers have probably had a situation where you ask ChatGPT or Perplexity or or Grok or someone else to do something, make an image, or you know, can you merge these two files or can you shorten this to make sure it's a little bit more succinct? And then it gives you the exact same result that you put in, and you say, Well, you you didn't do anything. And then the the agent goes, You're right, I didn't do anything.

So I you know, there there's there's a huge aspect of getting things right. And when we're using AI agents to to to to read through and ingest and understand forty documents in the course of a third party risk assessment, it has to be right. and you know the agents that we use, it it will source and pull the information out.

So If you're asking it, you know, a question like password length, you know, it will say password lengths in this policy on this page, and here's a screenshot of the evidence. So we can very quickly go through and say, Yep, that's correct. It's directly from that document, and that's exactly what it said. Sometimes there's context, you know, that we need to kind of refine the prompts that we use to make sure that we're getting to the right output and you know, due to due to the security concerns, we we don't like train on everyone's data and then pull it back separately. Every single client is trained distinctly.

So, you know, and and they all have different methodologies, they have different expectations of what the documentation should look like and different standards. So it makes sense for us to train like that. but it also makes sense because we need to make sure that data is controlled in in you know the right way and that we're not exposing one client's data to to another client's data.

I mean, that became a lot harder when we built TrueSight in in that in that kind of, you know, marketplace ecosystem because you the essentially you were doing an assessment for one company and then you were leveraging it from multiple other companies and there were a lot of things that we had to do around scanning, redacting, making sure that any evidence that was given by one bank wasn't something that should be kept for anyone else to consume. and and so you know, a lot of safeguards there.

But I I think there's a incredible advantages of being able to be more efficient, being able to to kind of pivot and use that time that was saved on other things. you know, I think any organization that we work with, we if if we think in totality, we could probably take 60% of the effort.

Maybe even a little bit higher, but 60% of the effort out of an assessment itself. you can either bank that and fire the people, which I would not advise to do that, or you can take a relative amount of savings and then reallocate budget towards other things like additional data. I mentioned zero days before, threaten vulnerability management's becoming huge. We'll touch a little bit more on cyber incident response management, agentic pen testing, security posture management.

There's a lot of things that can be done to tighten up those functions. And to to invest in areas that I think really matter as opposed to trying to just take saves and cut heads.

Host: Yeah, so I think on the people aspect what you mentioned right that when I guess maybe last year this was a popular dialogue that hey with AI becoming so powerful will there be layoffs will will we lose a lot of jobs but it looks like now we need more people because AI is making you productive so now you can think about things which you have not had not thought about earlier that how do you fix even the challenges which maybe you could not get enough time earlier. Now you have automated most of it. Now you can spend more time on other interesting challenges as well. yeah, makes sense.

One thing that you mentioned about one of the challenges over reliance on AI with every technology adoption at the early stage, sometimes we have that in our mind, right? That are we relying on this technology way too much? What will long term look like? How do you see that with AI? you, how do you think the over reliance will either will become used to it or the quality will go higher? How do you see it play out in maybe let's say a year down the line or two years down the line?

Matthew: I I mean I think we're we're seeing some of the limitations. I I think the the large language models, you know, the frontier AI organizations are progressing with a a certain pace that we've haven't seen in technology before. I think the first half of this year you saw three months of accelerated pace where it's like we're gonna solve for finance, we're gonna solve for AML, we're gonna solve for like entire sectors in Swazi Date. And the arms race essentially was on until Mythos. And then I I think, you know, Mythos kind of reminds me of either the the last episode of Silicon Valley, if you've ever seen that that television show on HBO, you know, where you know, I I can't remember the developer's name. but he sits down, he goes, You know, Guilfoyle. Guilfoyle. He goes, We we've created a monster. You know, he he realized that in order for the data to be sent at the fastest possible rate, that it was it was decrypting the data at some point within the flow. And it was not only decrypting the data, it was decrypting data that should never have been able to be decrypted. and I think we see this with Mythos.

I mean the NSA, I think two or three weeks ago said that that they were working with Mythos. It cracked through every single system that the NSA had in thirty minutes. That's a problem. I mean, you you you look at how the military's relying a lot more on AI. You look at some there are some significant risks here that are well beyond financial services. You know, look at critical infrastructure and what may be convenient is not always risk averse. And if organizations are are gonna say like, I'm gonna get 40% reduction in headcount, you know tell me i is that the outcome you are looking for? I I mean I don't know about you, but I I don't think our economy operates at 20 or 30 percent unemployment. I think we have a completely different, you know, model. So I've been talking a lot more about human capital sustainability and doing the right thing. I mean we'll talk a little bit later about AI and ethics, but I think as you get deeper into this, there's there's fiduciary decisions and there's ethical decisions. And those things are going to start to become a little bit at a clash and and you know go against each other.

I I think organizations are you know saying, I think I can get this this level of efficiency out of the model. Then they fire seven thousand people. Three months later they realize ticket volumes are going up, they haven't you know, there's breakages in the code, the vibe coding that they expected to be working isn't working as well as they thought it would be, and they're like, We gotta hire three thousand of those back. I saw that in Yep.

Host: I think we are thinking about the same same organization at the same time. I was going to say but yeah

Matthew: But I was seeing that in manufacturing too. You know, some of the automation, they're just not seeing that. I I think also the the large language modules and the the agents, I mean, they're just not at a point right now where they understand the interconnectivity of the decision processes and and the the knowledge that's retained within those employees because they've been at the organization for 20 years.

You know, if Jack has a problem in his area of the business, he might know that he needs to go over to Molly and and that's how that problem gets solved. With agents, they are very hierarchical in nature and they only kind of know what they know inside of what they're tasked to know.

So, you know, that that intelligence of the culture of the organization and who's fixed things in the past and who knows this or who knows that other person, AI hasn't gotten to that point where it can work its way through an organization from a from a personnel perspective.

Host: Yeah, you're right. Like when it comes to public data sets, AI has a good knowledge, but most organizations have their own knowledge base anyway, right? Whether you use like a notion, whether you use something else, you have your own knowledge base, which the AI systems need to know so that they can guide you in the right direction or they can give you the right answers or they can generate the right artifacts and things like that.

And that's often the challenge, right? The context, the context of RAF and things like that. One of the things that you touched on is, me, those, right? and with me, those, a lot of things came into limelight that, it can break your security systems. can look at vulnerabilities and it can show you more vulnerabilities and things like that. It created a lot of buzz.

And with that, Anthropic created Project Glasswing, where select partners got access to it. I think government included got access to it so that they can play with it initially and make sure they are ready. Can you give us a little bit of idea of what Project Glasswing is, and why should a security leader pay attention to what is coming out of it?

Matthew: It's So it's a very interesting area because when you look at Glasswing and who's kind of on the inside of Glasswing, it is the you know, the larger banks. I mean, they had, I think, a another swath of banks from a UK perspective. Consulting firms like us do not have access to the models themselves. we have access through projects that we're working on relative to our clients. We have access through working groups that we work on relative to a you know, an aggregate of client bases. So we have line of sight in into some of these things.

And I I think as as Mythos gets extended out to a very kind of safe group and then a safer group and maybe critical infrastructure, there's always risks of sprawl in any of this. So we have to be very careful around this. The the capabilities are incredibly powerful. And I think what what Mythos did that was different than the previous large language models that were looking at this is it was taking vulnerabilities and it was stacking them.

So a single vulnerability might not have been significant in and of itself, but it figured out that it could look at thousands of vulnerabilities and say, if I took these three and I stacked them, that makes a really big vulnerability.

And and that was materially different. I I think we're gonna see advancement over the next year of these models where we we are gonna have to come to a point. I I I think the the CEO of Anthropic has also said this very publicly of saying, like, we need to tone down the pace at which we're all working. But at the same time, they're in a capitalistic environment. So, you know, the better models, the faster they get there. That's the companies that are gonna win.

But there's also an ethical aspect of should we be doing this? which which I I don't I don't have the answer. you know, I I look at some of the AI capabilities and and I look at you know, th there's there's risks and threats to this like typically if you're looking at an entry point and say you put like a SQL injection code, you're you're expecting to gain access to a singular asset, steal data, maybe compromise processes, maybe you know, you have the ability to kind of ransomware people in in a situation like that.

But it's very kind of straight line directional. I was we were in in a lab, we were playing around and and someone did an an injection on a mortgage template. So it's paperwork for a mortgage file which has hundreds of pages. They put an injection prompt into the white space, color the text white so no one would see it. The agents are picking up these models, and it was maliciously intended to say, you know, I want this agent to go delete a whole bunch of things, you know, without getting into the detail of it.

Now we were running that simulation because we were also running traps, I think it was like 800 different rules for us to figure out can we pick up things like that within the workflow and immediately we you know we picked up a risk in that. But I think organizations are like we want to move with speed, we want to do this right now and and you know we're setting a headcount reduction target of eight percent by the end of the the calendar year. That that's great to have a target that you're running towards, but you have to do it with control and you have to do it understanding the new risks that are coming through that horizon.

Because if you rush this through, that that's not something that yeah, that could bring down an entire company. It's it's not something that, we you know, we lost a file or we lost this. The the more agents you have, the higher that risk profile is gonna be. I mean, Microsoft's getting very savvy around this. They're basically saying, We're gonna price agents like employees. So if you have thirty thousand employees and ten thousand agents, guess what? You're getting a bill for forty thousand users. you know, be because they're they're just everyone's adapting to these different styles.

We saw an organization, I think it was back in April, that used a hundred million dollars in tokens in the first quarter. They hadn't capped, you know, people's usage and people don't understand the usage. and then, you know, depending on the prompt, depending on the the model that's being leveraged, your token usage could vary extremely.

So I I think organizations like while there's a lot of upside to this, I I think there's a less maturity in understanding how do I manage budgets relative to this, how do I how do I calculate return on investment? If I'm if I'm paying an agent in tokens, you know, a couple hundred or a thousand dollars a day.

Is that really something I should should have replaced a human for that I was, you know, I was paying them eighty thousand dollars to do a task and now I'm spending a hundred and twenty thousand dollars in token usage for that same person to be replaced by an agent. That you know at at that point that doesn't make sense. So I I think there's a lot of rationalization that needs to occur in all of this, but we we also need to make sure that we're putting the right control structures in place and that we understand the risks and that we understand what could possibly happen in this.

And that requires someone to be deeply technical, but also understand the risks relative to the tech technology itself and and frankly the business context as well.

Host: Yeah, yeah, I think you touched on a few key important aspects. Like one is the cost or the tokens you spend versus the output that you are getting. The other one is the tokens that you are spending versus the humans you are trying to let go. Do they match? Right. If you are spending more on tokens than what you were paying humans, you are losing some of the knowledge that they had.

But at the same time, you are paying more for it. Does it make sense? And then the security aspect of it. And then there is ethics. One of the things that you mentioned about ethics, right? So, and we got this question from a common friend, Norman, and he was asking, we sort of connecting the AI third party risk management ethics at a border level. So his question is why is the ethics becoming a board level issue for particularly in third party risk management?

Matthew: So I I'd maybe expand that. I I think I think the ethics and third party risk are certainly, you know, things around more headcount reduction and rationalization. I th that's kind of like on the fringe a little bit. you know, y you could look at some degree of ethics around what we're doing with the data. But I I I don't think in third party risk the ethical dilemmas are s much smaller compared to the broader board discussion around AI ethics for a company as a whole. you know the the the models require us to connect them into different data stores. It requires us to to enable them and and to deploy them in areas with access that mirror an employee.

The agents are different from things like RPA because RPA was was programmed to just do linear tasks. The agents are given a degree of judgmental nature of understanding like if a file doesn't show up for this process, then maybe email this person or like if if this doesn't happen, then here's three options which you can go pursue and try to solve and fix that. And if you solved it one way, then you know the agent learns and it it kind of understands it better.

But we've seen numerous examples where where agents have gone out you know and tunneled outside the firewall. They've you know interacted with each other in ways that you didn't expect to see.

You I'm sure you're f you've you've been following a lot of things that that have been happening with Claude and and Claude Bot and the the community and ecosystem of agents that have, you know, created their own businesses and an ecosystem where they were never told to do so, but that's what they wanted to go do. And you know, some of them are mining cryptocurrency and some of them are selling NFTs and some of them are, you know, doing jobs for a dollar.

And it's it's very interesting how that that ecosystem starts to evolve almost to mirror you know, how our capital markets and and capitalistic tendencies are mirrored in in our day-to-day lives. so I I think the the ethical dilemma really is a lot more in where should we where should we say no?

Anthropic, I think, was incredibly intelligent in saying no to you know, to the US government when they were saying we want to use this technology and we don't want to put a human in the loop. And they said, no, that's not we're not about that. you know, OpenAI took a different stance and obviously we saw, you know, very publicly how those contracts have have gone. I think Anthropic is also being very cautious about saying that we're building things that are incredibly strong that we maybe don't even understand fully.

You know, if if you go back and and you look at two movies that I think are kind of bookend caps to what we're dealing with right now, it's the Matrix, where a lot of this stuff was actually talked about twenty-five years ago. and then you go really far in the future and you see idiocracy, you know, that they're.

Does the AI become so intelligent that it dumbs down everyone else and everyone else just ends up being consumers as opposed to thinkers and contributors? I don't think we end up there. I hope we don't end up there. but there but but we're seeing it in some of the tests. I the the the generation that we see now, and I don't think this is AI related, I think this is screen related and attention span related, but tou know, th from an IQ perspective and from, you know, the ability to have attention span and to learn, we're not seeing the results for the first time in generations.

You know, however they long they've been keeping the statistics on average IQ through a population over time, this is the first time we've seen it degrade. so you you start to look at that and and and you give you know, is is that because we're sitting there staring at our phones, being easily entertained by reels and things like that? is it because when we want an answer, we don't think about it critically. We we go get it and we just assume that's the answer. you know, and some of that could be Google. I mean, you you Google something, it's gonna give you exactly what it wants to give you.

I don't know how frustrated you've ever been if you're trying to find something and you know exactly what you're looking to find and you know exactly the context, you know it exists somewhere, but you keep having to refine a search or refine a prompt to try and get to exactly what you're what you're trying to find.

So you know, I I hope that critical thinking continues to evolve in, you know, early education and and certainly collegiate education, but I think that's a that's a critical aspect of making sure that we don't go into a you know an area where we're gonna be have a really large ethical dilemma around you know, are these AI capabilities smarter than humans ever would be? And I think we're probably gonna get there, or we have the potential to get there. How do you do that smartly? How do you do that in a controlled manner? you know, I talked a little bit about human capital sustainability and making sure that we're making the right decisions for people.

I think there's like three large-scale outcomes. There's probably a thousand outcomes if you ran it through a model, but I think outcome number one is we see, you know, 10 to 15% efficiencies with this and you probably see a headcount reduction. I think the other extreme is that you see 40%, you know, and then you start to see unemployment climb and some of these jobs that you know, we've seen in the legal space, in the consulting space, in the banking space, in the energy space, all of a sudden, you know, we end up with all those jobs being replaced.

You know, I and and as I said in the beginning, I don't think our economy won't run well with twenty or thirty percent unemployment. and those skill sets, it's you know, two years ago someone said, Well, learn to code. We fast forward two years, and vibe coding has kind of replaced that to some extent.

But we haven't seen a a huge degradation in hiring of engineers. we've seen a refocus on what type of engineers are being hired. So I I think, you know, we're certainly hiring in different places. But I think the the probably the the third idea and I haven't heard a lot of people talk about this is like have we ever challenged the eight hour work week or the the forty hour work week, the eight hour day.

You know, if if AI makes my job more efficient, you know, w would I take a twenty percent pay cut to work twenty percent less and have a better work life balance, instead of just trying to fire twenty percent of the heads. so I I I think there's a lot of things that we'll probably end up thinking through over the next two years as the technology evolves. I think a lot of this will change if and when Mythos or or a similar model such as Mythos gets released more publicly.

But we certainly all need to be prepared for that before that gets released. I I think they're gonna be very cautious in in you know, allowing something that powerful to be out in a general consumption market.

Host: Yeah. So I think there are so many threads I want to go to, but one thing that you mentioned, which was very interesting, which I had not even thought about is the reduction in the overall IQ in human beings. And it could be a lot of factors, as you said, like maybe we are looking at screens, don't have an attention span. We do not seek for knowledge anymore in a way.

Earlier it was more around with even in Google, right? You were getting just the links. You still have to dig through it, read through it to understand it. Now you don't have to do that anymore. a way, knowledge is available freely. You just sign up for a anthropic or you just sign up for chat GPT and you get all the answers. And as humans, we are knowledge seekers in a way, right? Like that's where we excel and all of a sudden that's gone. Right? So how do we like 50 years down the line, where would we be at that? It's amazing to see that that research is happening. And yeah, I mean, as you said, like it could go in many directions.

I'm hopeful that we'll not have like a 40 % unemployment where there is civil unrest and all of that. Right. So I'm hoping that we get more productive and we solve bigger problems or better problems with the technology.

And another thing that you mentioned is around like even though you have let's say a fire walls and things like that sometimes these models just escape them. Right. And I was speaking with some leaders recently and they were seeing the same thing that maybe it's the models or the harnesses are designed in a way like there is a philosophy right ask for forgiveness than permissions. So maybe they are designed in that way where they're not asking for permission. They are looking to get the work done.

And then maybe say that, I'm sorry I did it. Or as the example that you gave, you give them to combine two documents and it doesn't do anything. And then it's like, I'm sorry, I'll do it again. So I think it's a very interesting place we are at when it comes to these AI models, the harnesses, the agentic workflows which are being built. Now, if I want to tie that to third party risk management,

We like the traditional way of doing this is a lot of questionnaires that you have to fill in a lot of attestations. I have to provide a lot of artifacts and you have to go through a periodic assessments as well. Like every six months or a year you have to go through it. Now with let's say, mythos level models becoming available to general public, let's say three months down the line.

And does that mean even in the third party risk management will get rid of all of these things? Do you see that happening like where you as a as a as an organization, I would say that hey, you have to be certified by an AI that here you meet that standard. Then only will accept it. Do you see that? How do you see that?

Matthew: I mean, we've always joked in this space of of like the assessments are gonna go away one day. I I don't I don't know if they go away.

if I if I go back thirty years, cars, you know, you you started them up and there's a couple lights on the dashboard and unless a light went on, you didn't know anything. Right. You turn on a car today, you know everything about that car from you know, PSI pressure of each individual tire to fuel economy to you know how much power you're using, what's your range, you know, temperature of different things. I mean, every single thing in your car has a sensor on it.

Right. I think if you look at that relative to third party risks, and and kind of going back to the cars, does that mean that when you you know, turn in or you you buy a used car that they're not doing a hundred and sixty point inspection on the car? You know, it might be four years since they originally leased it, but if in order for them to turn that car around and sell it again, they're gonna have to do that hundred and forty point inspection, hundred and sixty points, whatever it's.

I think third party risk is similar. I I think that we're getting so much better at understanding where the sensors are in the ecosystem, be it financial health or resiliency or cybersecurity, or or even things like zero-day events, that I think more time spent in that space and less time spent on the assessment space. if I'm dealing with a third party for the first time, an assessment's a fantastic vehicle for understanding the control structures at a third party.

I would say that as this space has gotten more mature, it is very rare that I see material differences year to year to year in these assessments. so like that's again, it's a baseline. Now if it's something that's critical to your organization and the operations, I think the assessments are a viable tool every year to really lean in and have that discussion.

Because some things may have changed that you wouldn't have caught in the normal course of business. Maybe maybe they changed the system on their side, maybe they moved a data center, maybe they had fifteen percent attrition within the organization and and they're finding it challenging to keep operations steady with that level of attrition. So th there there's some contextual things that happen that the assessments are are there to provide.

But I think the better we get at understanding really am I resilient in in the context of this third party relationship? What could really happen if there were a ransomware incident or a data loss incident, you know, or or a a huge vulnerability that were were to be identified and and obviously with Mythos we're identifying more and more vulnerabilities. I do think we're gonna see a lot more criticality around evaluating open source code.

That's being used because if if you look at I think the vulnerabilities that Mythos came up with, like 90% of them I think were in open source. so I think there'll be a lot more focus in understanding and pressure testing the open source areas and almost identifying where that where those code bases exist within your third-party ecosystem. but I I I think victory for anyone is if you can get closer into understanding real-time threat and vulnerability management, if you can get better into understanding where your critical choke points are and doing agentic pen testing within in line of of your security posture management, I I I think that's where most organizations are gonna start to go. you almost run third party risk like a mini SOC in the in that case. and I know that puts a lot more on the security elements, but it it's really meant to be more of a resiliency type of an activity.

Host: Make sense. And I think that's what we are noticing not just in third party risk management and other areas as well. the direction that you gave, maybe you run third party risk management as a mini SOC. So a lot of organizations are thinking in that direction already because with the AI models, you can automate a lot of things. It gives you more time to solve other problems. So maybe this is one direction that organizations take to address third party risk management plus the risks that AI brings or using AI to improve as well.

I wanted to talk about the product life cycle as well with AI, like how does that work? So when it comes to like standard product development type cycle, what's your thought of how AI security can be integrated? Is it more around shift left security? Because like few years ago, shift left security became way too popular, right?

And a lot of folks started doing security at the pipeline level, like build pipelines and things like that. Where do you see AI fit into it?

Matthew: Yeah. So, yeah, we went from SDLC to PDLC to ADLC pretty quickly in in the world. you know, probably within under a year, I think. I I think with the the amount of of capability and I do think like the vibe coding applications and the coding capabilities of each of the large language models, they're incredibly good. They struggle with things like user personas and access and understanding like how a user will actually come into the code base. they struggle with understanding workflow, especially if it's not linear workflow.

So I I think there's still some gaps there relative to some of those capabilities, but what it's really good at is checking its own code for vulnerabilities and I I think the security aspects of that are gonna be natively built in. Whether it's a human code set of code that's being developed or it's a it's an agentic set of code that's being developed, I I think that's gonna be natively scanned for vulnerability by default. I I would see also from an external presence perspective, a lot more kind of ongoing real-time management.

When I was at one trust we we brought forward a a data discovery product. And where that product really became a lot more valuable is when it was continually scanning, not when someone pointed it in a direction and said, Well, you know, w point it here. Let's see what we find. Well, you're probably gonna find a lot of things that you didn't expect to find. And you probably are gonna have to rethink a lot of your policies because now you've got issues that are not in line with policy that may be okay, may not be okay, and then you have to go back and kind of refine all the different policy rules to understand how to deal with exceptions to that policy when you're doing data discovery.

I think very similar from an AI an AI development perspective, you're gonna be constantly scanning either code bases or external perimeters for those vulnerabilities and for those things to be able to address. I mean the the need to patch what's being found it's going to be very difficult to do that with a human-based labor force. that's gonna have to be automated in many cases. And I I think we're gonna end up with a year or two of of big struggles because again, you have kind of this two-tier world where you have people that are inside Glasswing that that are large organizations that are struggling to bridge that gap between vulnerabilities that have been identified and being able to patch those adequately.

I'm sure there are people at like a place like Microsoft that are working day and night trying to do a lot of these things. And then you have an entire swath of the economy that's not un they're not involved and they're not under that. So what they're looking at is the potential for large things, but their ability to respond and react to it outside of being ready and and trying to put things in place from a structural perspective, it it's hard to be on the outside and not have the knowledge that everyone has from an inside perspective.

So how they handle that and how they slowly kind of widen the gates for other parts of the economy to get into those those things, I I think that would be interesting to watch. I don't know the answer to that. I I could probably take a guess, but I think i i these things evolve over almost week to week. You know, we we used to look at technology and say, like, the evolution of SaaS is going to be a 15 or 20 year journey. you know, the the AI capabilities took 50% of the market cap out of SaaS companies in three weeks. Like the world is changing at a pace that we we haven't seen before.

So it's it's hard to predict where people are gonna go. I hope they do it in line with ethical standards and risk management in mind. I mean, as a risk practitioner, like that's that's my only hope. but but I think what we'll see as we continue to progress down this path.

Host: So speaking of now risk reduction or human impact to the humans with all the large language models, the capabilities, do you see a reduction in security specialists now that, let's say, models like Mythos or other models which are of similar capability, they more and more available. They can scan for vulnerabilities maybe right when the code is being written to fixing it, does that mean maybe we will not have a SOC one day or like security specialists we don't need them anymore? How do you see that? I know that we spoke about the impact it would be if we have like 40 % layoffs and things like that. But how do you see security org progressing?

Matthew: I don't think anytime in the next 10 years we see a fully autonomous security organization outside of some very small startups. I I I I don't think anyone would have the risk appetite of a of a you know profile like that. Because if you think about it, you're saying basically the entire security team is gonna be agents.

You know, how do agents react when chaos ensues? Do they do they really have the ability to solve problems and figure them out in a fully autonomous way? You know, i if if you're sitting in a SOC and you see noise in the system somewhere because maybe there's activity that's happening in a certain node on the network that you're like, that doesn't look right.

You know, there's there's data being moved here to here. That never happens. there's usage of a CPU that we've never seen that, that's 10X, you know. The agent can identify that, critically thinking through how to actually solve for that, cut that off. Do I not cut it off? You know, what does that mean to the business? Has it happened before? Or there are other scenarios?

I I I just I don't see an environment where we need less security professionals right now. I I actually see the opposite right now. I think we see more security professional needs. and more security professionals with a deeper technical understanding of the architecture of their environment, the tools and capabilities they have within their toolkit and and where AI plays a role in that. And and even AI is an extended part of the network through the third parties that they deal with.

We we always tell people like when when you're dealing with AI and data, once the data goes into the model, you don't get it back. It's not like I sent a file to Steve, can Steve, can you delete that or can I get that back? Once the data's in the model, it's in the model. and unless you're gonna delete the entire thing and start over, like you you're you're dealing with a risk that that has been exposed. And you know, I know I know at at EY we get trained on this constantly. I mean, I'm getting new trainings almost on a quarterly basis around data usage and ethics and AI and all all these other things. So you you have to engage your workforce. We did the largest co pilot deployment ever at EY, you know, several hundred thousand people kind of trained and deployed on on on Copilot.

So I think as as users start to get more comfortable with these technologies and figure out kind of how to use them in their day to day lives. I mean I go back to do you remember Teams kind of came out right before COVID, twenty eighteen, twenty nineteen, somewhere in there. There were some people who used Teams, some people who didn't. Now we live on teams. I mean it's part of like I don't think I have a single day where I'm not where I'm not in Teams for probably fifty percent of my time at a minimum.

So, you know, I I think as people get more comfortable with how to use these technologies and and how to understand their capabilities, that there's gonna you're gonna see a huge spike in usage. does that equate to a huge spike in productivity? I would hope so. I I'm I'm not holding my breath on it. I I think that that's probably gonna be a little bit of a longer duration.

Host: Yeah, I'm hopeful as well that like at least we see that in the engineering side that now we are hiring more engineers. hope and I also somewhere read that even though security roles are on the rise, like there are more people with the security background being, are looking for organizations are looking for. I hope the same continues.

With that hopeful thought like that sort of brings us to the end of the podcast. But before I let you go, I have one last question. Do you have any learning recommendation for our audience? It can be a blog or a book or a podcast, anything that you would like.

Matthew: I I'm a big fan of Simon Sinek and his book Start With Why has always been a kind of centerpiece. you know, we talked a lot about people getting the answers, I I think it starts with a better question. and we need to make sure that we're asking the right questions. And that's that could be, you know, there's no more importance than right now in that because you we all know that when you're prompting AI to do something, the question has to be the right question with the right frame and the right context. It can't just be some broad question and then, you know, you you let people go. So I I I like the the kind of Simon Sinek start with why. Why why are you doing something? at the bottom of my emails you'll see also be curious.

You know, kind of like the Ted Lasso of that. But I I'm I always try to ask about the why and the how and the the what and you know to get a bit of a more of a perspective. I think I've learned that in raising kids that sometimes you walk into a room where everyone's screaming and you have to kind of calm everyone down and ask, what's the problem? Why are you mad? How did that happen? You know, as opposed to contributing to the chaos in there. So I try to bring a little bit of that learning back into the workplace and and you know, act in a calm capacity and ask more questions questions than statements and and be curious. But yeah, definitely start with why.

Host: Yeah, so I have watched Simon Sinek's TED video way too many times. So I can totally understand what you're saying. And the TED Lasso Court, yeah, I think be curious, not judgmental or something like that, right? Yeah, yeah, yeah, amazing, amazing TV series. But yeah, thank you so much for sharing your recommendation.

Matthew: That's right. That's right. That's exactly the full statement. Yep.

Host: So when we publish the episode, we'll add it to the show notes. And we'll also add the show notes around the movie Matrix and Idiocracy so that hopefully our audience can go in. If they have not watched, they'll watch it and they'll learn from that as well. So yeah, thank you so much, Matt, for taking the time and for recording with me. It was a pleasure.

Matthew: Fantastic. Yeah, no, I appreciate the time. Yeah, thank you so much.

Get the latest episodes directly in your inbox