AIDR — AI Detection and Response — is the operating model that defines how modern security operations work with AI.
It covers three things at once: using AI to detect and respond, defending against attacks that are themselves AI-driven, and protecting the AI systems an organization now depends on.
AIDR is grounded in full-fidelity data, designed for real-time defense, and capable of supporting both analyst-driven and increasingly autonomous operations. At Mitiga, it is delivered by Helios, the AI-native engine behind Agentic Runtime Security for the Modern Infrastructure — cloud, SaaS, identity, AI, and third-party services.
AIDR is all three pillars, not one of them. A product that only secures AI applications, or only adds an AI assistant to an existing console, is doing one part of the job and calling it the whole category.
The Three Pillars of AIDR
Built with AI, to defend with it, from it, and the AI itself.
Defend with AI — AI for detection and response.
An automated SOC agent runs AI triage, agentic investigation and hunting, and agentic containment and remediation end to end, integrated into the agentic SOC over API and MCP.
Defend from AI — AIDR for AI-centric and AI-scaled attacks.
Purpose-built for adversaries moving at AI speed: runtime AI triage, investigation and hunting, paired with AI-attack detection, automated detection engineering, and fast, automated, reversible containment.
Defend your AI — AIDR for AI resources and SaaS apps.
Detects and stops attacks across workforce AI (ChatGPT, Copilot, Agentforce) and AI infrastructure (Bedrock, Claude) — shutting down AI abuse, compromised identities, and threats to AI SaaS apps and services.
The foundation: built with AI.
Underneath all three, Mitiga is built with AI — able to create, test, and continuously improve detections and runtime capabilities at AI-native speed and scale.
The changing direction of cybersecurity
In this episode of Mitiga Mic, Mitiga co-founder and CTO Ofer Maor returns to talk with host Brian Contos about a term the industry is using three different ways at once: AIDR.
Ofer offers his own classification — three distinct pillars that people routinely collapse into one acronym — and explains why the distinction is not academic. Along the way: why attacker AI will be commoditized within a few years, why dwell time is really reconnaissance time and what happens when an agent can do it in minutes, why reversible containment is the unlock for autonomous response, and how to tell a durable AI security product from a two-week demo.
Whether you're a CISO, a SOC leader, or a cloud practitioner, this conversation is a practical map of a crowded term.
Frequently asked questions about AIDR
What does AIDR stand for?
AIDR stands for AI Detection and Response.
What is AIDR in cybersecurity?
AIDR is an operating model for security operations in which AI is used to detect and respond to threats, defend against AI-driven attacks, and protect the organization's own AI systems. It assumes attacks move faster than human triage can keep up with, and is built to act in runtime rather than after the fact.
What is AIDR in incident response?
In incident response, AIDR shifts the work from reconstructing what happened to interrupting it while it happens. Investigation, triage, and containment run continuously against full-fidelity data instead of starting after an alert is escalated.
How does AIDR improve incident response times?
Three ways. Full-fidelity data is already collected and queryable, so investigation does not wait on log retrieval. AI triage and agentic investigation run automatically rather than queueing for an analyst. And containment is automated and reversible, so a responder can act immediately without risking an outage they cannot undo.
How do you evaluate the effectiveness of an AIDR platform?
Ask whether it covers all three pillars or only one. Then ask three questions about evidence: does it retain full-fidelity data across cloud, SaaS, identity and AI, or only alerts? Can it investigate without you first building the query? And can it contain an attack in runtime — reversibly — rather than recommending a manual action?
Which AIDR solutions integrate with cloud workloads and containers?
Mitiga's Helios AIDR covers cloud, SaaS, identity, AI, and third-party services and deploys alongside existing CNAPP and endpoint tooling rather than replacing it. EDR protects the endpoint; Mitiga protects everything else.
What does an effective AIDR workflow look like from alert to containment?
Panoramic Awareness across the whole modern infrastructure, Attack Decoding to establish what is actually happening, then Attack Containment to stop it — anticipate, detect, interrupt, stop.
The Transcript
Brian Contos: Ofer, welcome back to Mitiga Mic.
Ofer Maor: Hi, thanks for having me again.
Brian: No, it's a real pleasure to have you on board. You're our first repeat, which makes a lot of sense being our CTO and you have a lot to add. But I want to jump right into today's discussion. There's been a lot of talk about AI, in particular, AI as it relates to detection and response or what people are calling AIDR. So first off, what is AIDR? What's all this about?
Ofer: So, that's a great question. Because what I've learned in the last few months is that a lot of people use the same term to describe completely different things. And it's not new, of course, right? Because people like the buzzwords, right? XDR, CDR, AIDR and and all that. But really they think about different things.
So before we dive into that, I'd like to suggest my own classification into three things. And like, you know, everything good in life is divided into three things. And these are very broad strokes, right? Because we can break it up to 50 things, but I want to start with those big three pillars that I think distinguish between different aspects of detection and response and AI intersection, right?
Ofer: And so the first intersection of AI and detection and response is using AI for detection and response. And I think that's probably the most discussed right now, probably the most implemented right now. We've seen millions of startups going into this space and basically it says look, we have this problem, detection response, trying to detect when a threat actor, somebody malicious, does bad things in our, you know, endpoint EDR, network MDR, cloud CDR.
Brian: Not necessarily an attack that's AI-centric. Just no, good guys using AI to detect bad things.
Ofer: Exactly, yeah, right. And we can use AI to help triage, we can use AI to better detect anomalies. I mean, we've been using AI for many years, right? But when now people say AI they mean gen AI, right? But it's really about leveraging this, you know, transformative, spectacular technology of AI to do the work. And, you know, if you look at this space of detection response, right, it's probably what a lot of people who start their career in security is the first thing they learn, right? It's the most entry-level job as a SOC analyst. And you know that's where we know that's where AI shines, in taking those things that are repetitive and tedious and done by people with starting skills, and letting AI do that, right? And so AI for detection and response is just, it's great.
Brian: And you made a really subtle comment there and I just want to double click on that. You said leveraging generative AI, but we use that in conjunction, well, we use it at Mitiga, but organizations, security companies use it in general. Other things that have been maybe classified wrongly or correctly as AI or first-gen, things like anomaly detection, pattern discovery, volumetric analysis, temporal analysis, all all these great things that we've had for decades, that's still part of the equation, right? When we when we look, of course.
Ofer: Yeah. I mean, you know, machine learning. Somebody smart told me the other day that at some point you stop talking about the new technology with the name of the new technology and you start talking about what it does, right? So, detecting malicious behavior with anomaly detection is a use of AI, right? But you don't say AI anymore because you say what it does, right? And so, I think, you know, right now Gen AI is all the new buzz. Everybody's excited. Over time, we'll just get used to the applications that it gives us. But it's transformative. Using Gen AI for detection and response is transformative.
There's still an ongoing discussion. You know, the whole autonomous SOC notion. Is it going to be fully autonomous? Is it going to be, you know, people augmented with AI? I've seen opinions here and there, but either way, we're going to take a big chunk of what historically only people could do and let AI do it and make us much better at detection and response.
Brian: Okay. So, that's one of the pillars that you mentioned, leveraging. Okay, got it. What's number two?
Ofer: That pillar is super important to help us deal with the second pillar. So the second pillar is detecting, again still not detecting abuse of AI, but detecting these attacks on endpoints and cloud and so on where the attacker is an AI, right? So just like in our space of detection and response we're leveraging AI to be much better, the other side, the attacking side, is also leveraging AI to become better attackers.
And I've seen some fantastic startups in this space recently. You know, again, startups are looking at this from the enterprise side. So, penetration testing, red teaming, apps testing, all that stuff with AI. But the results are amazing. You can see the type of capture-the-flags that AI can do today. And it's mind-blowing. And when this technology will become commoditized two, three years out, the attackers will be using that all the time.
Brian: And so what's going to happen that quickly? Wow. No, you just kind of floated past that. But two to three years. I mean, I guess I'm not surprised because we're further along now than we thought we were going to be a couple years ago. So two to three years actually, I guess it sounds about right.
Ofer: Yeah. I mean, you know, maybe it's going to be four, but the reality is that generally speaking, hacker organizations don't invest in the most cutting edge R&D like startups do. But once enough startups, and there's probably a good couple dozens at least, who's already doing automated AI red teaming, pentesting with AI. And so when these startups start to mature, some, you know, some will do some open source, some will do that. The tech is going to get commoditized. Maybe not the best tech, but the basic tech is going to get commoditized. That's how every tech thing. And so at that point, it will land in the hand of attackers.
And so what's going to happen is that we're going to see this immense increase in volume of attacks because now AI is doing that, right? So instead of doing one phishing campaign, I can do 6,000 phishing campaigns, right? And so what does that mean? It means that all the tech that I built for AI helping detection that response is no longer going to be nice and optional to reduce some of the cost of the talent that I can't recruit. It's going to be necessary because people just won't be able to keep up with the pace in which AI is attacking. And we're going to see AI attacking and AI defending. And we're going to see this, you know, craze. And both of these are super important, right?
And so building not just the detection and the AI to help my current detection response, but building AI that can detect and response to AI speed attacks. Okay? And that can respond in the sense of remediating, blocking, containing because otherwise won't be fast enough.
Brian: So leveraging AI to, as part of my overall security strategy, then looking, then pillar two kind of shifting to the fact that now I have to look at AI specific enabled, enriched, whatever term you want to use, level attacks. Yes. Okay. Got it. And then we're getting to the third.
Ofer: Okay, the third is, and I think that's where most people today are concerned about because this attack stuff we still have two three years until it's coming up. But the third is attackers attacking, whether manually or with AI, my new AI infrastructure.
Brian: Exactly.
Ofer: So if I'm an enterprise today, I'm probably starting to use AI. At the very least, I'm using, you know, SaaS AI, right? I'm using ChatGPT. I'm using Anthropic, you know, Claude. I use Claude for coding and stuff like that. But a lot of organizations go beyond that. They're building new applications that leverage AI, right? I'm using Amazon Bedrock to integrate AI into my applications. I'm building MCPs that do all kinds of things. I'm building agentic AI. I'm building all these new services, applications, and so on that rely on AI and AI infrastructure.
And if I was an attacker today, I would target those. You know why? Because whenever people start building a lot of new things with new technology, there are a lot of misconfiguration and new vulnerabilities and things people didn't, we still don't have good practices for securing all that. And especially with AI being so, you know, willing, trying to please and giving you the data that it has access to, then we're going to see a lot of interesting attacks in this space.
Brian: Yeah. You know, I was just at a conference in Pittsburgh a couple weeks ago, BSides Pittsburgh, and there was several talks on vibe coding and people approaching writing relatively complex code with relatively basic or sometimes no coding expertise, certainly no security expertise as it relates to code. And they were just talking about this currently logarithmic increase in the amount of code that's getting sort of produced out there. And it's turning into an exponential increase because people are saying, oh, look what I can create. The security holes in that and the gaps, I think you're going to be able to drive a truck through them in the beginning, you know, and we'll adapt and we'll create better ways for folks to do that. But man, that onslaught is going to be like a kid in the candy store for attackers for sure.
Ofer: You know, I've been through this, this is, let's call it, the third technological wave I've been through from a security perspective. So I got into AppSec when AppSec was a new thing in 2000. And then I got into cloud security right a decade ago. And now this. And what's in common with all of these is that when some new technology or a new security concept comes in, in the first few years, there's tons of innovation, new attacks, new defenses, a lot of stuff, and then, you know, it stabilizes, right? Because the technology matures. And so these years are the most fun years as a technologist, right?
Brian: Yeah.
Ofer: Because there's so many opportunities to do new things, to come up with new things, to make up new attacks and build new defenses. And so we're at this point, but at the same time, the adoption is just infinitely faster than before. So when cloud was new, cloud adoption was amazing, but nothing like AI adoption right now.
Brian: No, for sure. I am 100% with you. So let me just recap your pillars. So the first one, I'm an organization, I want to use AI to improve our processes, our technology, our people, etc. I want, it's just to us it's another tool to improve. Two, we've got bad guys using AI against us and we want to be able to prevent and detect and respond to those types of attacks. And the third one is my organization uses AI for a whole bunch of cool stuff and chances are that stuff is going to be targeted as well and I want to be able to prevent, detect and respond to issues in there. So those are at a high level your three pillars. Is that about right? Did I capture that?
Ofer: Yes. And even though you can call all of them AIDR, they're completely three different things.
Brian: Exactly. Yeah. Yeah. The way you spelled that is I think very coherent approach to understand that. Well, let's take one idea. So, you mentioned AIDR specifically. Autonomous SOC, right? We're all hearing about that. We've been hearing about it for a while. Some people say it's good, bad. Usually folks are kind of in the middle. Where does that fall in this conversation?
Ofer: Right. So, so that's the first pillar, right? Well, it's the first and then it goes into the second pillar, right? So, let's look at the SOC industry, right? SOC is probably the most overworked group in any security organization, right? Even before AI came into our lives, SOC couldn't handle the amount of data, volume, alerts and noise they have to deal with. It's very hard to create a good detection engine that can really understand all the context and will always know on some weird behavior if it's malicious or legitimate. And so in favor of non-missing attacks, vendors generally err for showing more and that creates a lot of volume.
And so, you know, for a decade or more, we've all been building automations and contextualization and triaging and all that, but still SOCs are overworked. There's just not enough people in the world for all the software that we need. And so one of the results of this, we've all seen in the last few years, there's this huge growth in MDRs, right? Managed detection response. Why? Because most organizations just don't have enough SOC. So they outsource the problem to an MDR vendor and they've been working diligently on better automations, better context, you know, using the same team for multiple customers. It's a great thing, but even they are overworked and struggling with that.
Brian: Yeah. Yeah.
Ofer: And so when AI came and especially as some of the new models, the reasoning models started coming in, it became very apparent that a lot of this work can be done with AI, right? Because at the end of the day, especially at the tier one, right, the tier one, maybe the tier two SOC analysts, it's an entry-level job. The depth of knowledge is not huge usually, right? Again, people build their knowledge through that. So that's another issue we have to talk about. But when they come in and there's a lot of context, like human context, right? Is this this type of user, that type of user? Maybe I send an email and ask a question. Those are all things that LLM is really really good at, right? And so taking this and letting AI now do the work of a SOC tier one analyst, it's here, right? It's already here. It's not a matter of the future.
And so is it going to be perfect and never do a mistake? No. But let's be honest, nobody who works in a SOC is perfect and never does a mistake. You try not to do a mistake on a shift work with repetitive mundane work. And you see, you know, humans do mistakes. It's fine. So LLM will do probably less mistakes, right? And so now can they do tier two? Can they do tier three? Can they do tier four? Can it be fully autonomous? Right? And I'm not sure I buy into the fully autonomous, but I'm also not sure I don't. I think we're still, you know, waiting to see where the qualities of AI and, you know, AGI may get to, but I think everybody's confident at this point that you can replace a lot of the manual labor with people.
Brian: Yeah.
Ofer: And let the people that can do the more advanced stuff focus on that. Granted, just like with anything else, right? Replacing junior developers with cursor, replacing junior analysts with AI. So, how do we train the juniors to be seniors? It's a big problem, but we'll put that aside from today's discussion.
Brian: Great. Yeah. I mean, I think you spelled it out perfectly there. It's not a question of replacing people right now. It's certainly an augmentation capability, right? People do some things better and AI does some things better, and the two working together, it's just a great combination. We'll see where the future takes that and how things evolve.
Ofer: And honestly I think, you know, it's replacing people in the type of task that people don't want to do. I mean, we have, you know, Mitiga offers, it CDR is a managed offering as well, and we were already using those AI triage capabilities internally. And the team is super ecstatic because they don't have to do now all the grunt work of, you know, triaging the same alerts that maybe, you know, you can't get rid of, but they're noisy and so on. And they get to focus on investigating more interesting things, putting some more time into the more, you know, contentious alerts and figuring out if it's a real issue or not. And so, you know, it's a win-win. And we have such a big shortage in talent anyway. So, you know, I wouldn't have been worried about that.
Brian: My very first startup was an MSSP and we used to tell people the folks that are smart enough to tell the difference when looking at millions of logs between a false positive and a real attack, you can't pay enough to look at logs to tell the difference between a false positive and a real attack. They don't want to do that job. But let's put the Mitiga hat on. And, you know, I've already got it on, but let's put your Mitiga hat on for a second here. And let's talk about AI for detection and response and how we approach that and maybe even share a little bit how that's different from some of the other organizations, maybe competitors, but maybe even partners, but other people in the space that are trying to address this area as well.
Ofer: So again I think, you know, we're trying to leverage what's out there for, you know, the best models and best capabilities. I think most people agree that it's right to use the best models rather than train your own model and tune them and help them to work right in your context. And that's what we do, right? And so one of the benefits that we have though is that our platform was built from day one with a lot of context. And so this context and all the data that we have available because we collect all your cloud telemetry makes the AI very efficient, right?
So if I'm building a generic autonomous SOC startup, right, and I'm taking alerts from millions of products and I only have the alert, then it's harder, I'm not saying it's impossible, it's harder to be able to get the right data and the context I need for triage. And that's where the challenge, you know, some of these startups have raised tens of millions of dollars to just this. And it's a big challenge for us. We already have all your cloud data and we've contextualized it and we have all our understanding and we have everything around that and your user profile and, you know, all the old AI stuff, the machine learning knowledge and all that in. And so that allows an LLM to very easily do the work with the context that we have. And so again we take a standard model but we have a lot of wrapping around it, we have a lot of instructions around it and guidance and all the data and that makes it very efficient and we get amazing results with it.
Brian: Yeah. And one of the things that's so special about this and I've spoken with hundreds of customers now is that it's not predicated on alerts, building out your LLMs based on alert data. It's, I'm not saying alerts are bad. Alerts are fine. We pull in plenty of alerts, if we get alerts from CrowdStrike and others, but doing it on logs across cloud infrastructure, across SaaS, across identity and, you know, all the other cazillion of SaaS application types out there, it's really hard. It's really a difficult thing, but once you kind of crack that nut, you solve that equation of how to do that in a scalable way, man, that's a really really powerful LLM capability, I would think.
Ofer: Yeah. And, you know, especially when you try to trace threat actors through different cloud services. Every cloud service has a different way to showing their logs, different way to providing, you know, context. Who is the user? Is it one will show the username, one will show the email, one will show an ID, one will show an internal ID or an internal user string and so on and so on, right? Even just something like who is the threat actor or the compromised user. And so, you know, maybe five years from now, AGI will be so good it can just figure out everything on its own from the logs like this, but we're not there yet. And AI really works better when you help it get the context, right?
Brian: Yeah.
Ofer: So because of what we do in Mitiga, because we normalize all the data from all the different clouds into something that's more uniform, into something where all the identities, the entities are normalized and we provide additional context around them and additional checks that we do and profiles. This really gives the LLM everything it needs to be able to perform at its best.
Brian: Yeah. Yeah. Well, and you wrote a piece recently on social media about AWS changing their log schema and everybody does it and not everyone's ready for it. In fact, I would argue most people unless you live in this world, you're probably not aware of it at all. But these things are always changing. You know, we truncated fields 20 through 50 into one now and we move this over here and drop that out of this, is happening all the time. So, it's not like a set and forget. This stuff is like constant, you know, constantly staying on top of it, right?
Ofer: And, you know, I have to hand it to AWS. They were great about it in the sense that they notified about it months ahead and provided good documentation. And I wish all vendors would be as forthcoming and diligent about changes in the logs. Some of the vendors just changed the log one day.
Brian: Yeah, that's right.
Ofer: So, you know, part of what we have, we build a schema. So one of the monitoring that we have every morning we check that all the logs are as we expect them to be and then every few days, you know, one log has something new, a new field which is, you know, easy, or a removed field or a changed field or change structure or whatever, right? So yeah, this is a whole big challenge.
Brian: Yeah. Well, it can be easy to forget that the people that are in charge of writing the logging systems for these types of SaaS applications, identity, cloud infrastructure, whatever, they don't really love doing this. This isn't the thing that everybody, oh I really want to write our logging mechanism. So it's sometimes it gets kind of kicked down the road till the 11th hour and it's not as good as you'd like. That's a whole another conversation we can get to.
Ofer: Yeah, it's another, but I just want to know that I think that logging is an engineering task, right? It's like you said, nobody cares about, but there's also usually no product management around it. So, you don't think about it as if it's a product that somebody's using, you know, it's something that you need to do.
Brian: Yeah. Anyway, okay. Well, let's go back to, well that's another question. So we kind of covered pillar one then, right? We talked about how Mitiga will go ahead and leveraging AI for better D and R, right? So for detection and response. Let's go to your second pillar now where we're talking about stopping these AI attackers. So first off, what's really different about them and maybe kind of an add-on to what's different about them is from our perspective how does that manifest into how we do detection and response?
Ofer: So, you know, for many many years there's this saying that the average lurk time of an attacker is 200 days, right? So, you know, maybe it's a little bit overdone this number, but generally when we see threat actors, right, there's the technical attack, but there is, you know, you want to get money out of that at the end of the day. So sensitive data, ransom, whatever. And so usually what happens, there's the first phase of the attack, people get access and then it takes time until with that access somebody actually looks at that, finds the relevant data, right?
If I want to do a business email compromise, I need to wait for the right email, I need to find the right mailbox, the right thread, right? If I want to do ransomware and I want to do it right, I need to understand the organization, where's the sensitive data, where are the backups, how do I get rid of them before I do the ransom, right? All these things are the lurk time. It's not really lurk, it's reconnaissance. It's understanding. It's figuring out how to execute the attack.
And part of the value that solutions like Mitiga give, right, and, you know, in other detection response spaces if they're done well, is that if I'm able to catch the threat actor during that phase I am able to block them before they get to do damage, right? And so the whole notion of detection and response is, you know, you can't prevent everything, it's just not realistic, but I can stop attacks very early and prevent their impact, prevent them from materializing into a real breach, right? And so this is the detection response. Now, is it weeks, days, hours? I don't know. But it takes time, right? It depends on the attack, but it takes time.
Where's the problem with AI? AI is very diligent. It's very fast. It doesn't rest. And you can run 5,000 agents in parallel, right? And so I can have an agentic AI platform run through the entire reconnaissance phase and figuring out and getting the context, not just technical reconnaissance but oh this is a financial transaction, it's interesting, oh this is sensitive data, that's where they do backup, that's who the admin is. They can do all that in minutes, right? And so that means that once we see more of these attacks, the detection and response piece has to be really fast. I have to detect the first AI agent starting their reconnaissance and blocking it in a minute instead of in two hours.
Brian: Mhm.
Ofer: Right. And so it doesn't change the actual work, the actual work is similar, but it just, you know, it shortens the time. And one thing that it introduces that today is very contentious is the notion of autonomous or, you know, non-human in the loop remediation. So today still, even though a lot of our prospects are looking to see that Mitiga can remediate and we can of course, but still in the day-to-day deployment most people want a human in the loop, like okay I'll see that, you know, somebody's going to approve on that change and then we'll block that user because it's compromised, right? If we want to do it in a minute, there's no time for people in the loop. And so I think that's going to be the biggest change in this second pillar.
Brian: I feel, people, a number of CISOs I've spoken with and this is maybe just like even in the last quarter have said they're being much more cavalier about this now and not because they want to necessarily but they think they have to and this is a self-preservation thing in the role of the CISO where they need that in case of emergency, yes do this, do this thing now. Now they're asking hey when you go ahead and do this remediation if a mistake was made I want to be able to roll that back, do a non-destructive approach to this, but they're saying I need to react fast and sometimes I'm going to make a mistake, but sometimes it's going to be needed to be that quick reaction. I think that the gauge is starting to go a little bit more to that, a little bit more quickly. So, this conversation a few quarters from now or late this year, maybe even at Black Hat in a few weeks here, I think we're going to start finding people are going to be taking that approach more and more often.
Ofer: Yeah. And I think finding more and more non-destructive or, and even more than non-destructive, reversible remediation actions is key. We are 100% focused and committed to that because if it's reversible then I can do a few things. One, I can always reverse, right? But two, I can make the reversal as easy as like, oh, some human is now triaging that. If the human decided that this wasn't actually a threat, then you can, you know, immediately reverse without even talking to anybody.
And I'll go now deeper. If an AI decided, so let's say I saw a threat or I thought it was a threat. I did something to the user, but two minutes later, I realized, oh, it wasn't really a threat because I got more data, more context. It's like, oh, okay, now I get it. Could be a human. It could be an AI, right? Oh, now I get it. It's not a real threat. Okay, I can reverse. And maybe the user will never have even noticed that they were blocked because I just disabled them for two minutes and then re-enabled them. Same password, same everything. Didn't do a password reset. So, it's completely reversible. No problem. Maybe I contained a machine, took it back in a minute, you know, with load balancing, everything. Nobody noticed. So, that's I think is where, you know, where we should see the future.
Brian: Yeah. No, that makes good sense. So, to kind of recap before we go into my final question here, we've talked about two of the three pillars. We've talked about how Mitiga uses AI for better detection response. Great. We've talked about how the bad guys are using AI or it's an AI-centric attack and how that's a little bit different and how that could be detected and responded to. So now let's talk about attacks on AI. And what, first of all what does that really mean? Attacks on AI is, is AI part of the cloud, is it, you know, where does that fall? But there seems to be this cavalcade of AI security startups out there today talking about securing AI and it's model protection and inline blocking and, you know, maybe it's detection response. But there's a lot of AI security companies out there and if anybody walked around RSA earlier this year and certainly Black Hat again in a few weeks there's going to be a lot of talk about that. So first of all what exactly does this mean? What are attacks on AI and kind of what's the back end and how can organizations like Mitiga help?
Ofer: So I will say this, we could probably divide that into 10 subcategories, right? Okay. AI is so big and, again, there's a difference between attacking ChatGPT or your instance of ChatGPT versus attacking an AI model that you're training on your own, right? And so on. So we probably don't have time to dive into all of this spectrum.
I think one of the things we see with the AI startups, and that's very, again that's how we see things in new spaces, is people look at the vertical, right? I'm looking at cloud or SaaS or AI and they're trying to build a security step that solves all the problem for it. Whereas what we see in security that in later stage you start breaking it up, in that, you know, there's the posture, there's the prevention, there's the detection response. Why? Because those are different personas in the organization and they need different things, right? And so if I'm, you know, building an AI security that does governance and secures your AI, I'm probably not an expert in detection response and in making that accessible to the SOC, right? And so on. So, you know, there's always the horizontal versus vertical approach.
But I think it's such a huge space. We're going to need a lot of things in here to deal with all of that. And again, even in that perspective, right? There's again prompt injection is one problem. Permissions is a big problem. Like how do I verify that AI only gets in the response the data that I'm supposed to get versus somebody else, right? And it's not necessarily even a prompt injection. It could be just, you know, a mistake, right?
And so it's a really really huge space, but I want to for a minute, even though I always love to talk about the really really cutting edge stuff, but I want to talk about the most simplistic thing, right? If an attacker now compromised an identity, which is 70% of what we see in the cloud, and they use that compromised identity to start exfiltrating data from one of your AI services, that's not really a very sophisticated attack, but it's an attack that most organizations today are not going to be able to see, right? And so for me, AI detection response is starting in that very very simple thing and going all the way up to detecting more advanced and complicated things.
And in that perspective, I think it's very much cloud, right? So again I had this really intriguing discussion today about people building AI for on-prem, but probably 90% of the organizations are going to build their AI services in the cloud, right? On Bedrock, on Vertex, on Azure OpenAI. That's where most people are going to build it. It's part of their cloud infrastructure. It's another service like, you know, S3, like their key management, like their database. Only it's a service that in the coming years we're going to see a lot more interesting types of attacks. But it's still a service that suffers from everything the cloud suffers from, right? The identity compromise, the abuse, just abuse, the misconfigurations, all that stuff that we still haven't completely solved for the cloud is for AI and then all the extra stuff on top of it.
And this part of the reason, you know, I'm a big believer obviously that detection and response can't be siloed. You can't do just detection response for SaaS or just detection response for cloud infrastructure or just for identity or just for AI because the threat actors don't work in silos. They will come in, they will hack through your environment, they will get in through an identity or a misconfigured service or whatever, through an AI service and they will use that to go everywhere else. What if I leverage your AI internally because it has permissions to go into your S3 buckets and give me data from there? Is that an attack on AI or attack on S3?
Brian: Yeah, it's, that's such a critical point because you know this whole notion of mesh and that everything is interconnected and to your point attackers don't care that the sales team cares about Salesforce and HR cares about Workday and only developers care about GitHub. It's all interconnected. They're all tied together. And if you get in through one, you get into all of them essentially, right? And, you know, secrets can be compromised in different areas and leveraged to get into other areas. And it's just everything that makes the cloud wonderful and is makes people want to approach it is also the weakness that attackers use to exploit it is probably the best way to put that.
Last thing I'll just ask you as we wrap up here. You know, Mitiga is unique, I think, in that we're an AI-first company. We've been doing this for a long time, whether it's gen one or gen two, whatever you want to call it for AI. There's a lot of me-too companies out there bolting things on, which makes a lot of confusion for, you know, organizations looking to invest in controls. And let's just be very specific. We'll talk about detection, response, leveraging AI. What are maybe some of the things customers should be asking when they're looking at, you know, detection and response capabilities in the cloud around AI? What are some ways for them to sort of separate, you know, reality from, you know, PowerPoint and vaporware?
Ofer: So I think, you know, there's a lot of discussions on that right now. Part of the challenge of, again, the greatness of what you can do today with AI is that it doesn't introduce a big moat, right? So, you can build a very cool app with AI in two days of vibe coding. What's the problem is if you could do it in two days, a bunch of other people can do it in two days, right? And so, and the challenge is these things look really great. They don't necessarily scale well. They don't necessarily offer the depth. But people may buy into them because they look really great.
And so I think when you want to look is like what is the value on top of somebody who just wrote a bunch of prompts around one of the big models to create something that seems to give value, right? So I know where it is in Mitiga. In Mitiga it's the data lake. We have all this data that without it the value of building products like this is substantially lower. We have the context, the normalization, all the stuff I mentioned before which makes our ability to give value with AI, for AI, for when AI will attack us, all these things are fundamentally lying on the data and the context, right?
Brian: Yeah.
Ofer: And so if somebody else now will build something that demos great with some problems, sure maybe they can do it, but it won't give you the depth and fidelity that you need over time because it lacks that fundamental.
Brian: Yeah.
Ofer: And so, you know, whenever I see, and I get to see a lot of startups, whenever I see those startups, the first thing I'm trying to see is like, okay, did they just build something that I can build as well? Like, they just worked on, I get these like, oh, we can build a startup now in two weeks without developers. Like, okay, so you're just really good at writing some good prompts. Amazing. Kudos for you. But this is not going to be a lasting edge or value.
Brian: Yeah.
Ofer: Over time. Yeah. Whereas some of these things have really complicated tech, but that means it took them longer than that to build it, right?
Brian: Yeah. Yeah. Yeah. Just putting AI on top of vapor isn't like putting it on top of a massive curated contextualized data lake that's, you know, three years of scale and all the other complexities that go into it.
Ofer: And also I think it's super important to realize that in a lot of cases this guidance that people give to AI to make, you know, one of the generic models give them value, they might discover that tomorrow's model, you know, the GPT-5 or six will already know that guidance anyway and you won't need it anymore, right? So again, the fundamentals, the value, making sure that you bring real value on top of it, you bake in real knowledge that's not, you know, just a bunch of reading of articles online. So for instance, again, part of what comes into our AI is all our IR and research knowledge.
Brian: Yeah.
Ofer: Right. And I mentioned this before, we have our MDR. So we run managed detection response for our customers. We use our own AI for that. And whenever we see where this AI could do better, we leverage our experience and the depth of investigation that we did to improve that guidance, right? And so it's baking in a lot of this knowledge and capabilities.
Brian: Yeah. Yeah. Much more so than a two week startup saying, hey, we're good at prompts. For sure. But no, that's that's good advice. Thank you for that, Ofer. And again, hey man, thanks for being a guest again on Mitiga Mic.
Ofer: Thank you for having me. We'll probably meet again in the future.
Brian: Absolutely.