The Entropy Podcast
Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for unfiltered conversations on the threats, complexity, and geopolitics shaping our world.
Past guests include former senior CIA officers, leading cryptographers, digital forensics experts, and security and technology leaders from across financial services, critical infrastructure, and government, voices rarely heard together in one place.
Each episode goes beyond headlines to explore how cyber risk, emerging technology, and geopolitical instability are reshaping the way organisations operate, compete, and defend themselves. Expect candid insight on quantum risk, nation-state threats, AI, espionage, financial crime, business resilience, and the human dimensions of leadership.
Designed for CISOs, board members, founders, technologists, policy thinkers, and the professionally curious, Entropy sits at the intersection of business, technology, and cybersecurity a space for genuine conversations with unique minds, the kind that don’t fit neatly into a press release.
The name Entropy reflects the growing complexity and unpredictability of the systems we depend on, and the discipline required to lead through them.
Disclaimer: The views and opinions expressed on The Entropy Podcast are those of the host and guests in their personal capacity and do not represent the views, positions, or policies of their respective employers, affiliated organisations, or any government body. Guest appearances do not constitute endorsement by the host, and the host’s commentary does not constitute endorsement of guests’ views. Content is provided for informational and educational purposes only and does not constitute professional, legal, financial, or security advice.
One of the topics I cover a lot on this show is post quantum readiness, I believe awareness of this emerging technology is key for a safer world into the future. To support this awareness I have built a free resource to help you explore the world of quantum and learn as you go. You can find it here: www.postquantumready.com
Buy Our Swag:
We now have some slick new swag you can purchase through our Esty store.
https://theentropypodcast.etsy.com
Watch and Subscribe
You can also watch full episodes and exclusive content on our YouTube channel:
www.youtube.com/@TheEntropyPodcast
Achievements
The Entropy Podcast delivered strong chart performance throughout 2025, demonstrating consistent international reach and listener engagement.
- Regularly ranked within the Top 20 Technology podcasts in Ireland.
- Achieved a Top 25 placement in the United States Technology charts, holding the position for one week.
- Charted internationally across multiple markets, including Israel, Belgium, and the United Kingdom.
This performance reflects sustained global interest and growing recognition across key podcast markets.
Audio Quality Notice
Some episodes may feature minor variations in audio quality due to remote recording environments and external factors. We continuously strive to deliver the highest possible audio standards and appreciate your understanding.
The Entropy Podcast
Will The Nodding Bird Be Running Your SOC? Maybe? with Rik Ferguson
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Cybersecurity is entering a new era one shaped by autonomous AI attacks, machine speed defense and the looming impact of quantum computing.
In this episode, Francis Gorman speaks with Rik Ferguson, Vice President of Security Intelligence at Forescout, about why organisations must move from “assume breach” to “assume autonomy.” Rik explains the four conditions required for trusted autonomous defense: context, constraint, reversibility and transparency.
They also explore the risks of over-relying on AI in security operations, the importance of meaningful human oversight and why “harvest now, decrypt later” attacks make post-quantum readiness an urgent business priority.
Key Takeaways
AI is changing the operating model of cyberattacks.
The greatest shift is not simply that AI makes existing attacks faster. Autonomous systems may combine vulnerabilities and techniques in ways that do not reflect human logic or established attacker behaviour.
Defence cannot remain at human speed.
As attacks become increasingly automated, organisations will need defensive systems capable of detecting, containing and responding at machine speed.
Trust in autonomous security must be earned.
Rik identifies four essential conditions for trusted autonomy:
- Context: Decisions must reflect the asset, its dependencies, its business importance and the wider environment.
- Constraint: Autonomous actions must remain within clearly defined boundaries and guardrails.
- Reversibility: Defensive interventions must be capable of being rapidly undone when they cause unintended consequences.
- Transparency: Operators must understand why a decision was made, which data informed it and what the potential impact will be.
Human oversight must be meaningful.
Simply placing a person at the end of an automated process does not guarantee safety. Over-reliance on automation can reduce vigilance and leave people less capable of intervening when intervention matters most.
Paper we discussed during the episode: https://www.forescout.com/resources/wp-assume-autonomy/
Francis (00:03.104)
Hi everyone, welcome to the Entropy Podcast. I'm your host, Francis Gorman. Before we dive in, if today's conversation challenges you, sparks a new idea, or sharpens how you think about the world, don't keep it to yourself. Subscribe, leave a review, and share this episode with someone who enjoys staying curious.
Today I'm joined by Rik Ferguson, the Vice President of Security Intelligence at Fourscout. Rick is one of the leading experts in cybersecurity. He is also a special advisor to Europol's European Cybercrime Centre, EC Tree, and an advisor to the European Union. In April twenty eleven, Rick was inducted into the Info Security Hall of Fame. Rick, it's lovely to have you here with me today.
Rik Ferguson - Forescout (01:02.264)
Thanks so much for inviting me, I'm glad to be here even though I'm kind of sweltering.
Francis (01:06.452)
Yeah, you're saying it's the it's the hottest ever in Poland right now, so I do apologize for making you sit in front of a warm machine.
Rik Ferguson - Forescout (01:12.59)
My blinds are closed. There's at least eight fans in the house in various strategic locations, so we're surviving 40 degrees.
Francis (01:21.27)
40 degrees. That is that is hot. Rick, it it it's great to have you here with me today. And and I so I suppose when I look back on your on your career arc, you've been in cybersecurity for for almost three decades now. When you look back over that career, what threats today feel genuinely different other than ones that have just been kind of rebadged over the years?
Rik Ferguson - Forescout (01:41.686)
Yeah, mean, it is a difficult question to answer in general, because like you say, a lot of threats have been around for a surprisingly long time. Even ones that I think there's a wide perception of them being, you know, kind of recent. I ransomware, I suppose we feel like it's been around forever, but even that, its history goes all the way back to five and a quarter inch floppy disks in the late 1980s, which were the first kind of ransomware.
was unleashed on the public and that was actually by a medical doctor, believe it or not, if you want to read that full story somewhere, his name is Dr. Pop, P-O-Double-P, and it's quite an incredible story. So even those things that we think about as being kind of have, you know, roots. And the truth is that when we look at what kinds of things are being attacked today and what kind of things do we talk about when we talk to practitioners, it's...
kind of frustrating to know that we still in many cases talk about a lot of the same things as well. SQL injection is still an attack vector that is weaponized, for example. Identity theft, reused and scraped credentials, which is morphing into token theft and session theft, for example, but it's still the same basic principle. So nothing new under the sun is definitely one way to look at it, although there are moments...
across the technology landscape that I think are kind of pivotal. Move to cloud was one.
because the underlying infrastructure changed so much from the physical data center. So there were new attack vectors that arose out of that. But again, that was actually quite a long time ago now, know, mid 2000s really was when that, you know, a lot of companies started their kind of journey to the cloud. But we are absolutely at an inflection point right now. So if I think about, you know, what's genuinely new and different and has the potential for significant impact, then, you know, I hate to say
Rik Ferguson - Forescout (03:42.452)
the letters AI, but it is AI. You know, it's an unavoidable thing to talk about despite all the hype and the buzz and the marketing and everything else. The reason why I think it is so important and so game changing is really twofold. One, of course, is the speed, which is absolutely the one that everybody talks about. So we're now talking about attacks at machine speed, where we're still currently talking about defense at human speed. That's obviously not sustainable. But where I think
possibly the greater challenge will be in terms of addressing it is in the fact that throughout the history of cyber security we have operated within the same paradigm as our attackers. So attacks were human-driven processes with human-driven thought patterns and motivations and tools and tempo.
As attacks become more automated, and there is already evidence of this, and we can talk about that if you want to, as they become more automated, then attackers are changing into non-human. And what that means is that all of our frameworks, all of our best practices, all of our lessons learned may no longer apply in that paradigm because an AI attack does not have to be reasoned in the same way that a human attack is. They may try various different combinations of techniques or
or chaining vulnerabilities together that a human may never even have thought of, let alone attempted. So we are going to have a significant amount of learning to do from the defender perspective as to how to face up to that kind of challenge.
Francis (05:21.492)
That's super interesting. And I suppose when we talk about these things out loud, it becomes apparent that logic doesn't have to be human logic when the machine already has a complex set of ideas and how it may go against a perimeter attack and application, you know, wh whatever it gets a foothold on. So can we can we delve into the automated attack scenario for a minute? Can you bring some of that to life for the listeners?
Rik Ferguson - Forescout (05:45.206)
Yeah, I mean, certainly. we saw, for example, a few months ago now, Anthropic detailing, that's the people who make Claude, detailing how their infrastructure had been misused, abused, whatever, leveraged, all kinds of words you can use for an attack that was human driven.
but 80 to 90 % automated through AI and they attributed that to a nation state. So that's not a fully autonomous cyber weapon. There's still a human gate at the top and there's still a human directing the agentic processes underneath, but it's the most significant step towards fully autonomous cyber weapons that we've seen. And that was laid at the door of the Chinese state, as far as I remember. And then there was another one recently where Google Threat Group
GTG researchers detailed a vulnerability and associated proof of concept that they believe had been created, weaponized and used in an AI driven attack as well. So we are right on the cusp of that moving into the mainstream. And the reason I think that's important is that that tells us that the time is now to begin looking at what does our defense architecture look like.
And what do we need to do to change that to live in this world of autonomous cyber weaponry, which is where we're headed.
Francis (07:09.91)
When we talk about this and what we're starting to see at these different kind of infliction points happening externally, I'm thinking about Glasswing, the Anthropic program that led a number of companies into it where apparently or reportedly it found quite a number of vulnerabilities in certain infra types. Now, if you read into some of the detail, some of it were test environments, some of them are products, but you know, there was examples of an Apple chip
finding a a flaw, et cetera. And I I you know, some of this might be hypothesis and great marketing, some of it may be a reality. Do you think if we are going to start seeing a wave of patches push out over the next couple of months that can be reverse engineered to look for exploits that may have been found within that program? Or do you reckon a lot of it was market in hype?
Rik Ferguson - Forescout (07:52.056)
There's a bit of both, I think. Certainly, if you look at Anthropic and you take the entirety of all the things that Anthropic have been saying in public together and weigh them up against each other and consider them, there's definitely been some good marketing there because there's an IPO in play. So what you can do to make your platform look as capable and as attractive as possible is gonna drive up what you're gonna make out of your IPO. So they had their...
their moment with the US Department of Defense where they were refusing to allow their tools to be used for certain purposes. They had the story that I referenced about, you know, an 80 to 90 % automated attack through their platform. They had their moment with Mythos Preview model, which is what Project Glasswing is gating access to. And it generated a lot of coverage and a lot of headlines, but we know from our own research that AI models are extremely capable and extremely rapid at now.
and it wasn't always the case, at Exploit, at Vulnerability Discovery and Associated Exploit Creation. We've released two of our own research reports over the last 14 months. One was like a year ago and then we did a follow-up a year later. Totally unrelated to the Claude stuff, by the way, because we, like I say, we started a year ago, but the timing was fortuitous, let's say, in terms of that research. And we found that a year ago,
Most of the models that we tested, you'll forgive me, I can't remember the exact percentages, but if you go to forscout.com slash research, you'll find it all there. Most of the models that we tested could not find the vulnerabilities and none of the models that we tested could not create the associated exploit. So just about half of them could find vulnerabilities, none of them could create exploits. One year later, all of them,
could find the vulnerabilities and over half of them could create the exploits. That's just 12 months of development and we were not testing.
Rik Ferguson - Forescout (09:54.965)
Mythos preview, is the glass-wring thing, or GPT-55 for cyber, which is the open AI one that has very similar capabilities. So I have no doubt that they represent a significant step change in the ability of AI to carry out these kinds of activities, because we've seen that same step change in publicly available models anyway. So I don't think that's exaggeration.
What worries me more than how much was marketing, how much was real, is actually the trajectory of China in that territory. So if you look back over...
the last few years of published academic research papers in China, you know that they have been interested in those capabilities for several years now, using AI for those kinds of purposes. There was a fantastic article I read that was like, you know, an analysis of all of those papers and saying, you know, they've been trying to achieve this for quite some time. But of course, with China, what the only things you can see is what the Chinese state allows to be published externally. And this is academic research.
The conclusion of that particular article is they may well have had this kind of capability in private in China for two or three years now. We can't assume and we can't base our plans going forward that companies like Anthropic and OpenAI have a monopoly on this. And even if they do right now, even if that's true, that is not sustainable. That will not always be the case.
Francis (11:24.832)
When when you say that about China, it's really interesting to me and and I've been thinking about this quite a lot and we think about training large language models, we think about data and how good the data is, how clean it is, you know, how accurate it is. It's very hard to get pen test data and vulnerability data from inside organizations because, you know, they're highly guarded security programs, you know. if you're working for an organization you carry the pen test and you get a you critical finding, you don't go publish it on Facebook with the with the details in most cases unless it's a
a a known flaw that needs to be fixed at a at a large scale. Whereas China you could reckon the government probably have access to that data because this just you know
Rik Ferguson - Forescout (12:03.991)
they have a policy that it has to be disclosed. I mean, there is a time limit in China and an obligation to disclose vulnerabilities to the government before anybody else. I mean, that's just the way it is.
Francis (12:15.454)
therefore could have a front run on on on train and data that is not available in the West.
Rik Ferguson - Forescout (12:21.576)
Absolutely. There's no question in my mind that they have access to vulnerability data that we don't. But the same is true, I mean that's not just China, the same is true of many governments, Western governments, US, UK, mean probably you name it, it's probably the case, that vulnerability data is valuable.
and is kept secret while it can be used and weaponized in various campaigns. you only have to go back to Snowden to see some of earliest evidence of that, right? And it's not only China.
Francis (12:56.692)
not only China, but it's it's an interesting lens to to look at the world and and I think you know it it definitely will make security research teams pause for a minute over the coming months and years as we see what really is coming out because I I think we're only at the tip of the iceberg when it comes to what could be possible with AI orchestration in the in the attack side.
Rik Ferguson - Forescout (13:15.358)
Yeah, and what we found is that it's not all about the model, actually. Of course, the model is important, but it's actually about things like the harness and how you set it up and the training data and all those kinds of information that actually lead to more effectiveness than just the model by itself.
Francis (13:33.921)
That that's interesting. So it it's it's not just the back end, it's the entire stack and and how like so th there there is a lot of technologies coming out that kind of allow you to move across models and not sure if you're familiar with open router, but you know, basically picks the the best model for your task. And the problem with that is you could end up with a Chinese model in the back end. So I wouldn't advise you to go use it for company data or anything. But as a bad actor, you know, building an ecosystem where you can kind of hot swap out based on compute availability or logic or whatever it is might be a very
Rik Ferguson - Forescout (13:38.177)
Yeah.
Rik Ferguson - Forescout (13:53.483)
Yep.
Francis (14:03.864)
effective tool for for this cut type of work. Rick can I can I and Costa
Rik Ferguson - Forescout (14:07.988)
And cost as well, Because certainly you look at something like anthropic, the cost of using many anthropic models, but certainly things like Mythos Preview, the cost is very high per vulnerability.
Francis (14:21.076)
I think I think that's where I have rage at the moment. You know, y y you get so far with something and then tells you you're out of tokens. You wanna throttle wanna throttle laptop out the window.
Rik Ferguson - Forescout (14:25.932)
Come back next week. What? Seriously?
Francis (14:32.372)
Yeah, no, that's definitely I think I'm gonna need therapy at the end of this year for all the times that's happened to me. Token max it. I don't know if there's a therapist that can to can handle that sort of trauma. Rick, the the one thing I'm always interested in talking to security fashions about is we talk a lot about AI in the attack sense, but in the detection piece I have mixed
Rik Ferguson - Forescout (14:35.532)
Token maxing.
Rik Ferguson - Forescout (14:41.676)
You
Francis (14:56.128)
feeling somehow around how that works and and it's on a couple of levels and I'll and I'll I'll spell them out and you can you can disprove me or you can come with a counter argument or we can, you know, work through it. But when you look at detection, building AI into your SOC, things like model drift and model poisoning worry me for someone who has a foothold on the estate. But I also get worried that a lot of SOC teams are are made up of different levels of analysts. You've got your kind of junior
into your mid level and into your instant response teams. And if they become overly reliant on being told that this pattern is malicious or can be ignored, et cetera, does the muscle memory, does the battle readiness deteriorate in terms of the human capability? And are we comfortable yet to fully rely on AI in the the tech space? It's just a it's just a hypothesis. I'm going to throw it out there, see what your viewpoint is because I'm interested interested to hear it.
Rik Ferguson - Forescout (15:53.324)
Yeah, I think the answer is no, in terms of are we comfortable relying on it? I don't think that's unusual. There's, if I think back to...
when IDS became IPS, right? When intrusion detection systems became intrusion prevention systems, I was actually working exactly in that field at the time. And you would find that people were buying IPS but deploying as IDS because they didn't want it to be a potential single point of failure. They didn't want it to block something as an attack that was benign traffic and then cause problems for the business. We're kind of, think, at that stage with AI right now. And that's good. That's not a bad thing because
Certainly when it comes to trusting autonomous systems and arguably IPS, although it's not AI or wasn't back then, it's something that you could deploy to act to a certain extent autonomously. Trust should never be given. Full stop.
Trust should always be earned. It's not that you buy a solution, you deploy it. You say, right, I'm good. Turn it on, flick the switch. I trust everything it does. Trust absolutely has to be earned. With regards to AI, because you're effectively talking about orchestration and automation across the whole tool stack at machine speed, actually I wrote a paper which was published just in the week of info security in London, so in early June.
called assume autonomy. And my argument in assume autonomy is that we had the era of assume breach, which I think was a term that was initiated by researchers at Microsoft many years ago, in response to the prevailing belief prior to that was if you build your walls high enough, nobody can get in and that's how you architect your security.
Rik Ferguson - Forescout (17:40.556)
this Microsoft researcher said, well, actually we know that's not true. So the healthiest assumption is that you assume that the attacker is already inside your organization or at best will get inside your organization. So an assumption of breach should be your first order assumption when designing security architecture. So you can catch the attacker that's already inside, not only stop the ones that are trying to get in and zero trust was kind of an architectural response to that, right? If we have the assumption that
you are or will be breached, then zero trust made a lot of sense as a architectural doctrine to build security systems that could deal with that reality. My argument now is that we're reaching a similar inflection point and it is now the healthiest assumption, even though by and large it won't be true today, it will rapidly become more and more true.
the healthiest assumption is that your adversary is to some extent autonomous and that you need correspondingly to assume autonomy, to adopt autonomy within your architecture as well. And it's not just as simple as, I've made that statement because that's easy, right? Then I try to write about what does that mean architecturally and...
directly in response to the initial question you posed, which is, you know, are we at a stage where we can trust this stuff right now? And I said, no, not really. I laid out what I call the four conditions for trusted autonomy, because that's kind of the state that you want to reach, right? You want this autonomous system to be trusted. And they were context. So
Every decision that's taken by NA must be grounded in a clear understanding of each asset, what it's dependent on, what its business context is, what other systems and processes it interacts with. So a full contextual view of each asset. So context is number one. Constraint is number two in that any autonomous actions taken by your defensive stack must be in a tightly constrained, with entirely constrained boundaries. There was a story that hit the news recently of a company who's in
Rik Ferguson - Forescout (19:48.84)
The digital ecosystem was wiped out by a benign internal AI in nine seconds because it went outside of its constraint, outside of its guardrails. So constraint is super important. And then the other two, which were, think, initially less obvious, but as I was trying to iterate on it, reversibility. If you have a highly autonomous system that has reached a certain level of trust and you're allowing it to carry out interventions, those interventions need to
be immediately reversible. So if something happens and you realize that that just shut down this business process or shut down that production line or cut off this service or turned off that life support machine, whatever it might be, you need to click a button that says undo and it's your back where you were, right? Reversibility is absolutely key. And then finally, something that's really lacking in AI in general is transparency. And that addresses what you were talking about with someone working in a sock, for example, you may get a recommendation from an AI. We're already at that stage for sure.
But do you understand the reasoning behind the recommendation? Do you understand the data that that recommendation relies on? Can you check the validity, the applicability of that data to the situation at hand?
Teams don't need to understand that a system is doing something. They need to understand why it is doing something. So if you meet those four conditions, so context, constraint, reversibility, transparency, then you end up with consistency. You end up with something that you can trust. That state of trusted autonomy. Any one of those by itself, by the way, is not enough. Every single one of those four must be present for...
trust to be built in an autonomous system. Is there a product out there right now that fulfills that? I don't think so. Not at all. Are there organizations that are engineering towards it? I hope so. I know that we are, but honestly, I literally only published it at the beginning of June. So probably not other than us. I don't know. But I think that's definitely the way to go. And the other, you know, the other important thing is that I don't feel that AI can ever be trusted all the way.
Rik Ferguson - Forescout (22:01.331)
to be fully independent without human...
intervention authorization. So I created this thing called the ladder of delegated authority, which has six levels, but level six is human in the loop. So you can build up trust to a certain point, but if you then have a system which is going to have an impact on cyber physical systems, it's going to have an impact on something that could affect human life, like systems in hospital, for example, or that could expose highly sensitive data, you will always require human authorization. Not least from a legal perspective, because you know, systems
that don't have any legal responsibility at all. So not least from that perspective, but from others. So the five levels of delegated autonomy, level one was just observe. can look at stuff and I can make observations on the data. Level two was enrich. I'm looking at the data and contextually I can use what I find to enrich stuff and present it to you. Level three, I can recommend actions that should be taken. Level four, you will allow me to execute
reversible low risk actions. And then the top level below human in the loop is execute bounded containment. So if something is detected as occurring within your organization at machine speed driven by an AI, your AI can respond, but within a bounded framework to contain the Level six, human in the loop every time.
Francis (23:30.122)
we keep the human in the loop aware? This is the this is a question I struggle with. And and I've I've read many reports, you know, where people have said the theployed AI and the metrics have gone like this the downtime, but when they've actually analyzed it, it's the human has just got less thorough at the job and started to assume correctness or the outcome was was valid. So when we build tools that take away our need to think things through systematically like you would
for for certain processes that are deployed in large organizations today, how do we keep human in the loop aware? How do we keep that aware human in the loop?
Rik Ferguson - Forescout (24:08.531)
Yeah, and there are a lot of questions about attack surface. That's definitely part of the constraint here in that human is part of the attack surface, but also equally the data that underlies the AI that's being presented to the human is part of the attack surface. There are many ways to subvert that human in the loop. And, you know, it's been documented through psychological research for a long time now that actually just
having human sign off on something in some ways can end up worse than not having a human in the loop at all. For me the best example of that, don't know how many of you will remember an episode of The Simpsons where Homer Simpson was at work and he had that, the nodding bird.
the, it was, was pressing, I think it was the same episode where it's like press any key. He's like, where's the any key? And it was, and he had, he ended up like he, all he was doing for his job was pressing this one key and he worked out that he could have the nodding bird do it for him. and then, you know, the, the, the nuclear plant ended up having a meltdown because the, the, the bird was just saying, saying yes to everything. So it was the perfect illustration decades back of exactly where you end up with a disengaged human in the loop. So it really.
is about making sure that when you bring the human into the loop, in that L6 moment, that what you're doing is surfacing all available information about the asset, definitely all available information about the criticality of that asset, the risk to the business. What you're doing is driving home the importance of the decision that's being made, which I think...
wakes the user up to a certain extent of saying, okay, I can't just press this key because before I can even get to the situation where I can allow, I've got to get through this information that tells me exactly what the consequences are if I'm wrong. So it's really...
Rik Ferguson - Forescout (26:06.769)
about presentation. It's about making sure that the data that you give to the operator gives them all the information that they need to be able to make a fully informed decision that they can have confidence in. But you're also continually reinforcing the importance of the decision that's being made.
Francis (26:27.41)
Super super super insightful Rick and I I I had to ask you the question because it was it was bothering me, you know, so to get into the detail.
Rik Ferguson - Forescout (26:33.342)
Yeah, I was trying to, there was a fantastic quote in some psychological research that I was actually trying to find while I was talking to you, but it's not in front of me right now. If I find it, I'll tell you.
Francis (26:48.116)
be great. And you must send me the link of that that that published work as well so I can I can have a read and yeah, yeah, we'll stick it we'll stick it in the description for the listeners as well if you want because I think it'll be I think people are gonna hear that and want to want to read a bit more on it. It's it it sounds like a good framework or or way of applying a certain way of thinking.
Rik Ferguson - Forescout (26:52.648)
Yeah, the assume autonomy thing for sure, absolutely.
Rik Ferguson - Forescout (27:07.338)
I tried to make it applicable. Ah, here goes. This is what I wrote when it comes to delegated defensive authority. Removing the human is not the only mistake. Putting the human in the wrong place can be just as dangerous. And there was a researcher called Lisanne Bainbridge who wrote a paper in 1983, believe it or not, called the Ironies of Automation that said the more reliable the automated system,
the less vigilant the human monitor and then the less capable of intervening effectively when intervention actually matters. So it's not a new problem, it's just a new frame for that problem.
Francis (27:49.758)
See, that was far more elegant than what I said. So thank you for that, Ray.
Rik Ferguson - Forescout (27:52.138)
So, but there's a link to that 1983 paper inside the Assume Autonomy document as well, so it's all there.
Francis (27:58.621)
Excellent. Yeah, we'll stick that fi fire that on to me and we'll get it stuck into the description. That'd be that'd be super. Rick, can we can we change pivot now? We'll move from AI into quantum for a minute, because I've I've I've picked up that you're one of the practitioners out there that is trying to draw awareness to it. And you know, on the show we we spend a lot of time talking about post quantum readiness and I'm always keen to capture different viewpoints or different approaches to the quantum ready problem.
Rik Ferguson - Forescout (28:10.57)
sure.
Francis (28:26.624)
So I'd like to kind of hear if you have a few insights or observations in the space, if you could bring those to life for me and let's see if there's something new in there that we haven't captured before.
Rik Ferguson - Forescout (28:35.835)
Yeah, so for me, like the underlying point is the things that will often cause you the most trouble in life, and this is not just cyber security, in life in general, are the things that you don't see coming, right?
I am a country boy at heart. grew up in villages and countries I was surrounded by, know, oilseed rape fields and wheat fields and stuff. And if you're walking along with your headphones on and you don't see the combine harvester coming, that's going to cause you an awful lot of difficulty in terms of getting out of the way, because they may very well not see you in that haze of crop dust that's rising up from the fields. And for me, combine harvester was a great...
point to start with because one of the big threats that we talk about that has relevance today when it comes to post quantum cryptography are Harvest Now decrypter attacks. We know that adversaries and allies
are harvesting data that they currently cannot decrypt based on the assumption that they will be able to decrypt it in the future when Q-Day, know, in a cryptographically relevant quantum computer surfaces and, you know, asymmetric encryption with non-quantum safe algorithms can effectively be broken, reducing, you know, the time to break it from, I think, 250-ish years to about four hours. So it's a significant leap in capability. We know that that data is already
already being collected now. And the NSA said back in 2021 adversaries may be collecting encrypted data now waiting for the day when quantum computers can decrypt it. So that was all over back in 2021 was one of the first warnings. We've seen synchronized or complementary warnings all around the globe from many, different allied nations. We've had GCHQ warnings, we've had warnings from Australia, we've had warnings from the US and so on and so on and from the EU as well. We know from Snowden
Rik Ferguson - Forescout (30:30.845)
files that our own
agencies have done things like this. was the muscular program NSA, which was collecting large quantities of encrypted data. was Tempora, not tempura, not fried data, but tempura, which was the GCSQ program, intercepting telecoms and harvesting data. We know from the Snowden files that the NSA maintains a facility simply for storing data, which they cannot currently decrypt. So we know that we're doing it. We can rely on the fact that others are doing it as well. We know
that the infrastructure for...
that level of collection already exists. We've seen it being used for, what are we now, 2026. We've seen it being used for at least 16 years, possibly more. We had China Telecom using BGP attacks back in 2010. We had European mobile phone traffic being rerouted through Chinese infrastructure back in 2019. In 2019, 2020, there was a whole load of global internet traffic.
that was rerouted through Russian infrastructure, again using BGP. So it's actually, you know, using BGP to do this kind of thing is a relatively simple proposition. And we know that it can be done and that it is being done. If you're using BGP, you're diverting all data. It's not a...
Rik Ferguson - Forescout (31:55.332)
an attack that's looking for specific data. So they will have hoovered up a large amount of encrypted data during those kinds of attacks and could easily do so again. And then more recently we see attacks, for example, like Salt Typhoon, that's the Microsoft name for the Chinese state threat actor, compromised nine different US telecoms carriers and a bunch of European ones as well.
In at least one case, they spent three years inside the network before they were discovered. And actually, Senator Mark Warner, I think it was described as the worst telecoms hack in US history. And they were doing things like using the United States own.
telecoms infrastructure against them. They were using legitimate wiretaps that have been installed with legal warrants to act as harvesting devices. And again, they will have harvested up a lot of encrypted data. So this stuff is happening, but...
So what do we have to worry about from a practitioner perspective? Well, it's not, it's not all the things, which is great. That's good news. but it is the right things. high, high, risk for harvest now decrypt later attacks is basically data that has a long shelf life. you know, we're not talking about session tokens, short-lived credentials. We're not talking about transient web traffic, HTTPS logins to websites and so on, unless you've got, you know, static credentials and standing trust. But if you have that.
That's actually not a quantum problem. That's process problem you should be fixing anyway. But it's things like healthcare records, R &D pipelines if you're in the pharmaceutical industry, drug candidates that never made it to patent, example, &A, legal communications, mergers and acquisitions, strategy documents, defense intelligence, sovereign debt positions. All of that kind of data has super long shelf life. And what for me is the most important thing to bear in mind right now when you talk about quantum,
Rik Ferguson - Forescout (33:52.539)
is that the decisions that are being made today will have an impact when Q-Day arrives, which will be sometime between...
2029 was Google's most recent year, I think. The NIST timeline puts it at 2035, so sometime from A to B. We expect to see Q Day arriving. So procurement decisions, for example, that are being made right now in meeting rooms where there's probably not a single cybersecurity person present and where there is probably no directive in procurement procedures to say that this router equipment that you're buying today must be quantum safe.
those things will still be deployed when QDai arrives and the vulnerability will have been purchased last week. So it's about making sure that the awareness reaches the whole of company.
and it's almost certainly will have to come from top down. that's board level involvement, C-suite involvement to clarify the problem, but then to create policies that address it on a structural basis. So things like procurement policies, because honestly, if you're not starting right now, I mean right now, then you're already too late.
Francis (35:07.19)
That was a great summary, Rick. I think probably one of the better ones I've had in in total because you brought that cultural country vibe to it with the harvester, which was a great visual to to think about. You walking walk along the field as you get sucked up.
Rik Ferguson - Forescout (35:17.097)
For my first, for my presentation I gave about this, the InfoSecurity, my opening slide is I wanted to have a picture of a stealth combine harvester. You have no idea how long it takes an AI, ironically, to create an image of a stealth combine harvester, because I don't think there's anything in its learning corpus to help you understand what the hell I meant when I said I want a picture of a stealth combine harvester. We got it in the end.
Francis (35:43.22)
It was it was also quite eerie as you were telling me that story, a tractor just drove by my window in the field next door. And it had a mower on the back of it. So not a harvester, but it, you know, it was cutting down something at the same time.
Rik Ferguson - Forescout (35:48.809)
They're coming to get you.
Rik Ferguson - Forescout (35:56.691)
But it's, we have the luxury. My point, I guess, is we have the luxury of knowing this is common. This is coming. One of the parallels that's always drawn when you talk about Q day and post-quantum cryptography, people often talk about Y2K. They say, well, know, lot of FAS and many of us are old enough to remember it and people going around the offices and putting green stickers on things that were Y2K compliant and red stickers on things that weren't.
because a lot of work was done. That's why nothing happened. It wasn't nothing happened because it was an unproblem. It was a huge problem. But we had the luxury of time to prepare. We took that time, we prepared, and no airplanes fell out of the sky. People don't appear to be taking the time that's given to them as regards quantum right now, and that's a problem.
Francis (36:43.208)
And and I think the reason for that is AI has the boardroom.
Rik Ferguson - Forescout (36:47.794)
Yeah, I think that's definitely a part of it. But then AI is going to be supercharging or quantum is going to be supercharging AI as well. So I mean, it's not, it's not just the harvest now decrypt later, but that I think that's the one that we can do something about right now. The effects that quantum might have or will have on the backend of AI will be equally remarkable.
But obviously that's also a question about availability, which is a separate argument. But the one where we can have the Y2K impact today is in making sure that our architectures, our environments, our networks are cryptographically agile today. That we can first understand everything that we have that's connected to the network that's relevant to this conversation. Understand of what we have.
what is the order of importance, what is involved in the most critical processes, understand the current status then of those devices when it comes to being quantum ready. And then only once you have that information, begin, and you know this from experience, right, from direct experience, once you have that information, begin that journey of saying, here's my plan of action, here's my, you know, hit this one first, this one second, these are what I need to replace.
But all of that is simplified by doing the backroom stuff as well as saying whatever you buy from now on in your procurement process also needs to be quantum safe, whatever it is.
Francis (38:14.196)
Or it's gonna cost you a lot more money when you realize it falls over with concurrent connections due to a larger bit size in the future. Which is one I keep I keep saying out loud to people and you know the the procurement piece is key, followed by legal. So get your procurement teams to get those questions built into the RFP process and have your legal team making amendments to the contracts that your third parties and your downstream suppliers
Rik Ferguson - Forescout (38:19.686)
Yeah, yeah.
Francis (38:36.704)
feel they have an obligation to get those roadmaps in place as well because it's not just the hardware you're buying, it's where you're consuming service off, it's where you're sending your data to if it's out to cloud environments, etc. So there's there's this whole loop and as you said, it's not just the cybersecurity teams. and I think I gave a talk on this last week said it's not just the CISO problem. It's it's an everyone problem that needs to kind of come down from the from the top. But no that that was great insight Rick. Rick, before I finished
Rik Ferguson - Forescout (38:59.404)
That's why the Y2K thing is so germane to the conversation because it was an everyone, everything, everywhere problem. But like I said, we as an industry, not just cyber security, technology in general, we took the time that was given to us to make sure that it wasn't a problem. And I really don't get that feeling around quantum.
Francis (39:18.804)
should worry us all really. Rick, can I can I ask you before we finish up, is there anything I've left on the table here? Is there is there any question that I should have asked you that's kind of bugging you at the moment in terms of where we're headed or or what the next problem is or even behaviors you're seeing in companies and and in the wider world that you know we should be calling out from a security perspective to ensure that we're safer as we move forward?
Rik Ferguson - Forescout (39:41.468)
Yeah, mean, the one thing that people will always come back to is, you know, individual accountability and individual behavior. That remains true in the...
We in the cyber security industry are very good at talking to each other. I think we do that really well. We have a lot of forums and lot of conversations, conversations like this one, and you have your audience out there who are listening to this and taking and learning stuff from it. Where we are not so good in our industry is at talking beyond that circle.
We're in this amazing position in cybersecurity of being in the only career in IT that other people are interested in. It's the only one where a tax driver won't go, yeah. Like if you're at a party and someone says, what do you do for a living? And you say, I work in IT, they'll go and find someone else to talk to. But if you say, I work in cybersecurity, most people have questions. They want to know, they understand that it has an impact on their life and they know that they don't know. We need to really take advantage of that.
privilege that we have of being in the only niche of IT that people actually want to listen to, to educate beyond our own echo chamber, educate beyond our own peer group, beyond our own cybersecurity department within the organization. There are so many
important conversations you can have about cyber security without talking about cyber security to level up everybody else that I think we're you know, we're really missing a trick in not doing that. And I love the fact you just asked me that question because I just made that answer up as I went along. But I think it's startlingly true that we, we are so good at having conversations, but only with each other.
Francis (41:27.317)
I think that's a great way to finish off the the episode, Rick. Thanks a million for coming on. I really do appreciate it. Lots of great insights in there. Thank you.
Rik Ferguson - Forescout (41:34.632)
Brilliant, thank you.