Threat Talks - Your Gateway to Cybersecurity Insights

Running a SOC was always hard. With AI in attackers' hands, hard becomes impossible, unless you change how you work. Rob Maas, Field CTO at ON2IT, sits down with Lieuwe Jan Koning, Co-founder & CTO at ON2IT, on why detection and response no longer buys you time. Open-source AI now finds a way into a portal in about 15 minutes, no pentester required. The fix is preemptive cybersecurity: prevention first, automated countermeasures, and a zero trust culture that turns your SOC from analyst-driven to software-driven, with the analyst still in the driver's seat.

Timestamps: 
00:00:00 When hard becomes impossible 
00:01:37 The biggest change in SOC history 
00:05:16 What attackers can now do with AI 
00:08:13 Why patching can't be your core defense 
00:11:58 The analyst becomes the quality gate 
00:13:11 Preemptive cybersecurity, explained 
00:24:33 Advice for SOC managers

What is Threat Talks - Your Gateway to Cybersecurity Insights?

Threat Talks is your cybersecurity knowledge hub. Unpack the latest threats and explore industry trends with top experts as they break down the complexities of cyber threats.

We make complex cybersecurity topics accessible and engaging for everyone, from IT professionals to every day internet users by providing in-depth and first-hand experiences from leading cybersecurity professionals.

Join us for monthly deep dives into the dynamic world of cybersecurity, so you can stay informed, and stay secure!

Running a SOC has always been hard,
but with AI in the hands of attackers,

hard becomes impossible
if we don't change our way of working.

In today's episode, we discuss how

a SOC can cope with
these evolving changes.

Let's get on to it. Welcome to Threat Talks.

Let's delve deep into the dynamic world
of cybersecurity.

With me today is Lieuwe Jan Koning.

Welcome to the other side.

Yeah. Thank you.

I'm a different side of the table today.

I like it so far.

So Lieuwe Jan is one of
the founders of ON2IT.

So he knows everything

about building a SOC
and currently holds the position of CTO.

So welcome again.

And my name is Rob Maas, Field CTO.

Before we dive into the topic,
what was the reason

that you were so passionate
about diving into cybersecurity?

Back 20 years ago, you mean?

Yeah. So, honestly, it's,

I wanted to do

something hard, and cyber is quite hard
if you if you want to do it.

Well, it's not the reason
why I stayed in cybersecurity.

And that's because there's so much to do.

There's so much things that can be better.

And there's also a lot.

I'm quite optimistic, actually.

There's so many things that organizations
can do

to increase their security posture.

And there's so there's a lot of work
and there's a big mission to accomplish.

Okay.

You already mentioned
that cybersecurity is hard.

One of the topics, the topic of today
is also a very difficult topic.

I assume the change of the SOC.

Can you give us a brief summary

on what's happening right at right now?

Sure.

So I think we are in

the biggest change in the history of,
or at least in our history,

the most fundamental change in what a sock
is, what it does, how it operates.

And that's for one reason.

That's the right of AI.

AI has quickly become something
that's of well, if you still correctly

and if you create your agents
correctly of high quality and quick

speed of doing things.

First of all,
because attackers have many new tools

that are exposed,
we have had numerous recordings already

about prompt injection
and and how to secure the server.

The amount of attack vectors
is increasing.

Amazing in an amazing rate.

So there needs to be an answer to that.

That's one thing.

It's much quicker,
so we also need to respond much quicker.

But I think the most fundamental change
in the biggest assignment

that we have as a community,
I think, is that we need to move

towards prevention
because it's going so quickly.

And, I mean, detection and response,

what most stocks are just about detection
and response.

It assumes that you have time to respond
and that's no longer valid.

So we really need to make sure
that prevention is a thing

and that we automatically respond
to changes super quick.

Okay.

That's quite some topics I think we will
discuss during this, this talk.

But before we go to the current change,
can you take us through

how the SOC has changed

over the past 20 years and then maybe also
look back on ten years ago?

What was how did it all started?

Yeah. Well, SOC 20 years ago didn't exist.

I mean, I don't even know
if the term is said

maybe in a few smaller organizations,
but not many people have had heard of it.

So what we how we started with
cybersecurity is managing

firewalls,
making sure they are in the right spot

in the organization

that are not just at the perimeter,
but also in the core due to.

Such trust,

principles dictate that you should do it
like that.

Segmentation, endpoint protection.

Make sure that that's everywhere.

Authentication, all those aspects.

So more managing the controls,
making sure that they are properly done

and actually towards prevention.

And we're now back at
at that even gardeners acesso now.

So that was
that was initially what happened.

And customers would find us
because they needed that skill.

And then let's say indeed ten years ago

or so, SOC became a more common thing
to do.

Part of it was driven by compliance.

I mean, there are many frameworks
that say, look at your log files,

respond to threats, etc.

make sure you have a remediation plan
that more organizations needed.

And of course, a lot of events

that that get
certainly get into a database somehow.

And what is the actual single
one out of those millions

that we need to act upon
that was that were drivers.

But most of it was actually, oh,
we bought a firewall

or an endpoint protection solution,
and now there's log files to help.

And of course breaches happened, happen
more and more.

And that's also a reason to realize
we could have seen this.

Let's now make sure that we next time
know what's what's hitting us.

Yeah, I heard someone say

never waste a good incident.

That is certainly true.
That's certainly true. Yeah.

If you need a
if you need a reason to to do better.

Incident is,

well,
the very little upside of being breached.

So. Good. Good driver indeed. Yeah.

You mentioned AI is one of the big drivers
for the current change.

I think there are both sides
of two sides on AI.

We have the attackers and the defenders.

Let's start with the attackers.

How did it drive their landscape
or the way of working?

Yeah. So we see a lot of developments.

We have a couple of thread
talks about how that works.

There's one

is that there's so much knowledge
available that's usually just in the head

of a pen tester, for example,
or a state actor that knows all this.

And this is especially if the latest
models that knowledge is in the model.

So that means that if you didn't

get trained for weeks and years
in experience on how to hack a system,

you can actually have a an
AI do it for you.

Strix is one of those open source projects
that tries this.

The only thing you need to give
is a URL of your portal.

Hopefully if you have it
a username and password that works,

and then it will try to figure out
all kinds of nasty things and

but in minutes like 15 minutes or so,
then typically it has found a breach.

If it's not super hard,
a super hardened application.

That means that many more

people have access to it
and that the speed is higher.

So you get attacked by more people
at a quicker rate.

That's a lot.

But there's much more things.

For example,

software, the

AI revolution, in my view, started
when software was discovered.

Business completely changed.

I mean, to be developer
today is completely different

from a year ago
from two years ago in our company.

I don't know any people
in more that right.

Their code actually,
that's all that's all the labs.

So it's really good at it.

But also

but they're also good at analysis of code
and also security analysis of code.

So it is today much easier to figure out
flaws in your if you have the source code.

And that's also a very good thing
because then you can fix them.

But in I mean the kernel of Linux
is publicly available.

It's open source log forge that we had
that source code is there.

Everybody is using it.
We know that. Right?

That means that everybody
you have access to current state LLM.

So that is literally everybody
with an internet connection now

can find flaws in software
and then construct a a countermeasure.

Do it. And that means that,

that we didn't know before.

Now certainly the servers
and get exploited that that's big.

I mean the whole reason
why mythos by Anthropic was delayed

is so they claimed
because it's too dangerous.

So the first thing they wanted to do
is go to the big software.

Things in open source like open source DNS
servers, like the kernel of Linux,

analyze them, make sure those books
get fixed that they find

and only then released to the public. So.

So at least we give a head
start to the defenders.

Okay, nature makes sense if you say

that are way easier to find
and also much quicker.

Does it also mean that we should change
our patching process?

The short

answer must be yes,
but I'll put some nuance to it.

I've never been

a fan of patching.

Keep doing it, please,

because we depend on it, but the fact
that we depend on it is really bad news.

Actually, it to me, patching
should be a last resort

for the simple reason
that even if you installed all the latest

updates, the ones that have not been fixed
but are known and

but specially the ones that are not known
yet have not been fixed.

So by default, every piece of software
almost is flawed.

I mean, for example, if every software

company would not have in their

user license
a line written like you're on your own

for for your own use
or for your own use at your own risk.

Microsoft, for example, wouldn't exist
because if you take a responsibility

for the flaws you put in a system,
if you think of it as a bit bit weird,

imagine you have a car and says, hey,
if it suddenly explodes,

yeah, it's your fault.
I mean, that wouldn't happen.

I mean, we would sue the car company,
right?

But in software, that's not the case.

And, and but and it's full of flaws.

So patching if you have to
if that's your only measure,

that's not good news
because you know you've already lost.

And there are some areas
where you have to do it.

So if you're talking

about your processing process
I think you need a patching machine.

Really that's highly automated as possible
for anything where

where it is really important
as a last resort, such as,

your endpoints like your

phones and and and laptops etc.

and also the surface that you expose
to the public, like your VPN concentrator.

We've seen numerous problems
there, and it's of the essence that you

fix really quickly.

Okay. Yeah.

We also had some episodes of well,
we had an episode on patching,

but also on the VPN problems
you just described.

Yeah.

And there's not just one vendor,

so patching is, well,
not at least not the whole solution.

Then what can we do on the defender side
with AI?

Yeah. Luckily a lot.

First of all, that's
the speed thing that I was talking about

and needs to be much better.

So the circle list is really changing.

The job of the list is really changing.

Because as long as you put

a lot of effort as we did, into making
agents, making soap agents, making skills,

etc., that codified the groundwork
of of analyst.

And then, I mean, triaging items
that get in local entries,

doing correlation between many,
figuring out put in context in

coming up with a battle plan,
figuring out what countermeasures

you could take
in this particular situation.

I don't think that typically
a user now a user is take

a couple

of hours
to do is now done in minutes, really.

So that that is super important
to be to be super quick at it.

So what I, what you see happening
is that instead of,

throwing more people

at the problem,
if so, twice the amount of events

means twice the amount of people,
if you're not careful enough,

that is no longer necessary.

But it's now all a game

about your software quality, the software
and AI, the behavior of your SoC.

So, and that scales much better
and it's much faster.

So every shock needs to move,
make that transition

to make sure that there's almost
no humans.

Humans are there to be the quality gates,
to be the the orchestrator,

the new things that we haven't seen,
the new playbooks that we see

happening of attackers, that we make sure
that our ecosystem actually

adheres to this, this new threat.

So you're much more on a higher, more,

more tactical and more strategic level
working on your job actually.

And that's, that's
that's of great benefit.

I also mentioned the capability
of the software models that can

that can scan for, for floating software.

If you have a development department
or DevOps teams that create software,

it's great news because what you need to
do is in every CI, CD pipeline,

make sure that there's an AI reviewing
your code specifically for security flaws.

And it takes out a lot,

especially if if your focus
hasn't really been security but features.

And let's be honest,
for most organizations that is the case.

Okay, that's all very good to hear that.

There are also positive sides.

And that's not only the attackers
that gets the benefit.

You also already mentioned
in the beginning

that Gardner has a good term for this,
this change and what we need to do.

And you mentioned some of the I think the
technologies that we will use for that,

especially on the defender side, and
they call that preemptive cyber security.

Can you elaborate on the on the term,
what it is and how it works?

Yeah, and I'm really happy
that that is finally now

recognized as something mainstream
that needs to be picked up.

Preemptive is in two ways.

One, it's
the it's the prevention part of it.

And the other one is if you get attacked

and you see something
happening immediately response.

Those are two, two aspects of it.

On the prevent part,

like I said in the beginning,

detect and respond.

I mean, many of our focus in stocks

and many organizations
has been in detecting something is wrong

and then fixing it once it happens, but

it assumes that you have time to do so.

And yeah, sometimes you do get hacked.

And then the problem has already been

been executed by the attacker,
and then you're too late.

And that's a waste.

And I see many organizations today,

but I mean, it's been my mission
for the last 20 years already

to to always put prevention first
because this is the only way.

I mean, I don't want to look at events
and then solve them.

I don't
I want those events never to happen.

So if you make it impossible
for an attacker to do a lot of things.

Yeah, then it's so much less easy.

Today's far too easy for most of us.

This is also why you mentioned
that patching is not

should not be the core solution.

No to cybersecurity.

No. IT for example segmentation,

multi-factor authentication everywhere.

If you have a container farm,
you need to make sure that you are

constantly that you're resilient.

So if something breaks down
that it can easily build up.

That also makes the library patching
much faster, supply chain problems, etc.

we need to focus on those things.

90% of our budget
should be in those kind of measures that

that actually make your security posture
better.

Prevention.

That's not the reality today
because many organizations have a sock,

have an MDR solution,

but that registers the lack of security
instead of making it better.

So preemptive security
means that we are recognizing this

and that we every event that happens,
everything that we see in the SOC

should lead to an improvement somewhere.

That's what the standard operating

thinking model has to be.

And we call this zero
trust culture, actually.

So the principle of your trust
still valid today, even if it will survive

the age of AI in the way of thinking,
it has to be applied everywhere.

And that I think is
is the prevention part of of.

Yeah.

So the first part you now
mentioned, prevention part is nothing new,

but it is
what the current change is becoming.

More and more it was already important,

but it's becoming more and more important
if we want to renew in a sense.

I mean, it's easy for me to say
I'm in the middle of everything

and see things are happening.

So in my mind, prevention
is so much more important that I

than I see in regularly in organization.

Let me give you one example,
which is as old as our company.

There's an IPS.

You can put it in blocking mode
or in detection mode.

Which one do you choose?

For me, it's a no brainer
to put it in blocking mode.

But still today
there are many organizations.

For example, in e-commerce,
let's say if I put it in blocking mode,

it may cost me money
because my website could be down

for a couple of minutes
and I don't want that.

So I'll do it in detection mode.

And you guys alert if something's wrong.

Now, I do recognize that
there is a small risk associated,

but it's you can actually calculate it
and plan for it.

A risk that a security measure,
applying a security measure

may cause downtime or cost somewhere.
That is very true.

But you cannot
measure is the vast amount of money

it costs if something goes wrong
because you didn't do it.

And this is true
everywhere in cybersecurity.

And also in this case
I think so. Is it new?

Is prevention new?

No. In itself not.

But is it knew that it needs
to be much more front and center.

I think for many organizations
it is. Okay.

So you mentioned preemptive cybersecurity
consists of two major topics.

One was the prevention part.

What is the second one?

Yeah, the preemptive part in the sense
that when you're being shot at

you can shoot back more or less, right.

Not literally.

Like you're going to hack the attacker.

But the idea is that
if you see someone happening, someone

moving around, or weird behavior
in a user account, logging in in

different places, or constantly failing
logins, doing an attack

happening from inside, for example,
you need to like right now or right?

Actually, not today, not anymore.

But before we would have an analyst
look at it

and then we found out the customer
and say, listen,

we might want to shut down this account,

or we might want to shut down this server
for we now don't have that time anymore.

Preemptive
means that we are in an automated way,

are going to take those counter measures.

Now this is more difficult.

It's always been more difficult.

There are a couple of things that work

almost out of the box, like shutting down
an account, for example.

That should be super easy,
blocking IP addresses.

If someone is attacking you from outside,
you see it block block that guy

so it can lock in internal house,
isolated immediately those kind of things.

But we need many of those things.

And that's actually something that

is broader than the

SoC or a service provider.

This is something that should go
and get into the culture of organizations.

Countermeasures
need to be in an automated way, deployable

the scary for many organizations,
but it's highly necessary

because modern source like us,
we can provide

countermeasures per second.

But if on the other, on the receiving end
of those counter measures,

there's a human reconfiguring a firewall
or phoning up users

to shut down their machine,
that's not going to work.

So it means that IT departments
functional owners of software.

They need to be ready for this,
and they need to have a receiving end

of this actionable things
that need to be done.

And there are many ways of doing this,
for example, MC and MCP server

provider.

But this is not only a technical shift
and it's also a cultural

it's it's it's
technically we have solved this.

That's not the we can make APIs.

We can make MCP serve,
we can wipe code them.

If you have little

development knowledge,
that's not the issue.

The issue is a mindset, a thing.

We call this the zero trust culture.

That needs to be in there
every every time you touch a system,

you need to think of
how is an attacker going to.

Influence this in a bad way?

And how do what kind of thing can I do
to stop him there?

Blocking a feature,
I don't know, disabling access to a file?

Share all those you need to think of that,
and then expose those features and

make sure that your security center
can interact with it in an automated way.

This is the journey ahead
for the next for the coming years.

I think that organizations
have to go to okay, so in order for SoCs

to implement
this preemptive cybersecurity,

they have a great help
by using AI for using agent skills, etc..

What, what?

So you mentioned briefly already that the
the role of an analyst will change.

Can you elaborate a bit more on that?
What.

Yeah, it's going to be even more fun job
if you ask me.

I'm biased. Sorry.

So the the groundwork, the hunting work
and all that,

that will be fully automated. What we see.

So what we see, we've seen with developers
to to implement a change, to implement

a whole feature these days can be done

at the level of an average developer.

At least it's working in safe, etc..

So we have achieved that.

So we see that
the quality of what AI systems

can do approaches the human capability.

There will always be people that.

Same with text writing.

For example, an original text writer
human is still better, right?

And there's whole

philosophical discussions
whether AI can become better than humans.

Very interesting.

Let's see. To go there. Yeah,
that's another deep dive. Maybe.

But, assuming that you are at, let's say,

90% of the quality of the best person
there is, there's one big difference.

It's so much quicker.

I mean, we see that what I already
mentioned do hours of work for an analyst

is now reduced to under a minute
of a digital analysis of the same quality

of consistent quality. 24.7 always there.

They don't really need less and less than.

Well,

I'm not planning on letting anybody go.

Actually, no.

I think the, the, the we need to grow

less quickly in terms of people

because there's also a lot more to do.

The same with,

any other revolutionary technology
that I mean, initially people think

our jobs are going to be taken
over by machines or by whatever.

And in the end there, I mean, we had

when the Industrial Revolution was there,
there were debates among economists.

How are we going to in a fair way?

Divide the

available
labor that's still there to people.

So it's fair to everybody.

So it's not like one person

worked for 40 hours or fixed 50 hours
a week, and others don't have a job.

So they were thinking of mechanisms.

Maybe we should have like a maximum
of two hour, two day work week, etc.

it was that people really believe
that back then it turned out that way.

I mean.

It's become more challenging in many ways,

so I don't see why today.

Ask me again next year, I don't know.

But today why?

Why that wouldn't be the case here as well

because I have so much more to do.

Detection is of course

a big thing, and it's needed
and it's required by compliance, etc.

but if we can put all our efforts
into prevention,

that so much better,
so much more worthwhile work in the sense

that it prevents hackers

from getting in in the first place,
or make at least super, super difficult.

So the role of the analyst is more from

a being
the quality gate of the analyst work,

and making sure that all the new playbooks
that are, that are that attackers

execute are properly codified and all
that, and the agents are being better, and

that whole ecosystem needs to be managed,
but you need to feel fewer people for it,

and it scales tremendously.

Of course, that's one part of it.

The other part of it is we're now going to
more than we already do.

We are actually
we are already doing this today.

About 5050 or so.

50% is looking in the mirror
and 50% is looking forward

and making sure
the security process is better.

I hope we get to the 99
to 1 ratio for that,

so that we're focusing constantly
on making sure security posture is better.

Another reason I don't think

that humans are going to go away
is because customers do want a human.

If things escalate,

if we are going to bigger changes,
strategic advice,

all those kind of things, that is
a human job, at least for now to do.

But I don't see that happening
changing soon at the moment.

Yeah, yeah.

We're still not managed to make
a good chat bot for customer support.

At least if I try to ask customer support
something with a chatbot.

Many people hate
AI for that reason, and I understand

I understand that, but that's AI.

I also understand that if you are,
if you are

on a help-desk for a low cost product
and you're the manager there,

then the first thing you do is try to to
to at least have

the basic questions answered by an AI,
because it's a cost saving thing.

Because to many organizations,
the help-desk is a cost

cost center.

We don't see it like that for to to for us
it's a it's

a it's a value creator
especially different different thing.

Yeah yeah yeah.

Okay.

Before we are going to wrap up,

what would be your advice
to a sock manager

to make sure that, yeah, to cope

with this, this change that is coming
or that's already happening.

Yeah.

It depends on
how far your sock is in this transition.

At the beginning,

I would say make sure that every analyst,
they are technical people already.

And I think the whole AI revolution
is easier for technical people

because they know they can learn
how to build skills, what they are.

Make sure you know the technology,
what an LLM is, what the limitations are,

what how you write a skill, how you write
an agent, how all that works.

Play around with it. Make time for that.

I mean, that's really the first step
because then you, you, you in your mind,

you can unlock the tremendous value
that's there.

I mean, and then you start

figuring out which processes
take a lot of time.

That and can be replaced
by, by and do that.

Also, I think it is worth to take a look

at how you can help

moving towards this prevention
and preemptive response of your sock.

I think a sock sock that is only reactive,
there's no future for it.

So make sure that you can do
the next step.

Execute the next step.

Every time there is something happening
in your organization and it is escalated,

or a countermeasure needs to be taken,
it actually means that somewhere else.

There's a security problem, right?

Think of that.

There are millions of events
that every organization

gets thrown at themselves
every day, each and every one of them.

The fact that it is there is bad news,

some problem somewhere
that needs to be fixed at its core.

That's what we need to be doing.

I've been trying to do this
for the last 20 years.

I intend to do it much longer.

Yeah, but we all need to focus on that
because that's the only way,

I think that we will stop hackers
instead of wiping amount

after they went away with our money.

Okay, well thank you.

And as I heard, just with AI,

we also have a good a good chance
on the defender side to do this.

So that brings us to the closing.

So first of all prevention first we mentioned a couple of times hasn't changed.

The other thing is

we are going from an analyst driven
if I say correctly,

to a software driven SoC, but then still
with the analyst in the driver's seat.

And the last one is we should make
preemptive cybersecurity, meaning that

we can just adjust our security controls
directly when we see something happening.

So with that, thank you for all
the insights and thanks to you, listener.

If you like what you saw,

please like and subscribe
and I hope to see you next time.

Thank you for listening to Threat Talks,
a podcast by ON2IT cybersecurity and AMS-IX.

Did you like what you heard?
Do you want to learn more?

Follow Threat Talks to stay up to date
on the topic of cybersecurity.