The Entropy Podcast
Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for unfiltered conversations on the threats, complexity, and geopolitics shaping our world.
Past guests include former senior CIA officers, leading cryptographers, digital forensics experts, and security and technology leaders from across financial services, critical infrastructure, and government, voices rarely heard together in one place.
Each episode goes beyond headlines to explore how cyber risk, emerging technology, and geopolitical instability are reshaping the way organisations operate, compete, and defend themselves. Expect candid insight on quantum risk, nation-state threats, AI, espionage, financial crime, business resilience, and the human dimensions of leadership.
Designed for CISOs, board members, founders, technologists, policy thinkers, and the professionally curious, Entropy sits at the intersection of business, technology, and cybersecurity a space for genuine conversations with unique minds, the kind that don’t fit neatly into a press release.
The name Entropy reflects the growing complexity and unpredictability of the systems we depend on, and the discipline required to lead through them.
Disclaimer: The views and opinions expressed on The Entropy Podcast are those of the host and guests in their personal capacity and do not represent the views, positions, or policies of their respective employers, affiliated organisations, or any government body. Guest appearances do not constitute endorsement by the host, and the host’s commentary does not constitute endorsement of guests’ views. Content is provided for informational and educational purposes only and does not constitute professional, legal, financial, or security advice.
One of the topics I cover a lot on this show is post quantum readiness, I believe awareness of this emerging technology is key for a safer world into the future. To support this awareness I have built a free resource to help you explore the world of quantum and learn as you go. You can find it here: www.postquantumready.com
Buy Our Swag:
We now have some slick new swag you can purchase through our Esty store.
https://theentropypodcast.etsy.com
Watch and Subscribe
You can also watch full episodes and exclusive content on our YouTube channel:
www.youtube.com/@TheEntropyPodcast
Achievements
The Entropy Podcast delivered strong chart performance throughout 2025, demonstrating consistent international reach and listener engagement.
- Regularly ranked within the Top 20 Technology podcasts in Ireland.
- Achieved a Top 25 placement in the United States Technology charts, holding the position for one week.
- Charted internationally across multiple markets, including Israel, Belgium, and the United Kingdom.
This performance reflects sustained global interest and growing recognition across key podcast markets.
The Entropy Podcast
Train Like You Fight with Snehal Antani
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of The Entropy Podcast, Francis Gorman sits down with Snehal Antani, CEO and co-founder of Horizon3.ai for a wide-ranging conversation on cybersecurity, AI, warfare, leadership and the future of work.
Snehal shares lessons from building and scaling Horizon3.ai, why startups must eventually move from “pirates” to a “navy,” and how his time inside Special Operations fundamentally changed his approach to leadership.
They also explore the rapidly changing cyber threat landscape: AI-powered attackers, autonomous penetration testing, deception as a defence against AI agents, the lessons emerging from Ukraine, and why organisations need to stop asking whether they are secure and start proving they are resilient and defensible.
Key Takeaways
- Why great founders need grit, conviction and a “learn-it-all” mentality
- How companies transition from entrepreneurial pirates to a scalable navy
- Why AI could give cyber attackers effectively unlimited ammunition
- How defenders can use honeypots and deception to hack the hackers
- Why cybersecurity teams should train like they fight
- The growing importance of human-machine teaming in warfare
- Why over-reliance on AI could undermine human judgement and scepticism
- How AI may reshape the workforce and put increasing pressure on the “middle”
- Why there is no AI easy button coming for cybersecurity
- Why organisations must move from being “secure” to being resilient and defensible
Key Soundbites
“You earn the right to be on this team every single day.”
“AI gives the adversary unlimited bullets.”
“You don’t want to learn how to deal with a crisis in the middle of a crisis.”
“We always train like we fight.”
“There is no AI savior that’s going to suddenly make your lives better.”
“Those obsessed with mastering their craft are going to come out on top.”
“Stop saying that we’re secure… start talking about how we’re defensible.”
Francis (00:02.93)
Hi everyone, welcome to the Entropy Podcast. I'm your host, Francis Gorman. Before we dive in, if today's conversation challenges you, sparks a new idea, or sharpens how you think about the world, don't keep it to yourself. Subscribe, leave a review, and share this episode with someone who enjoys staying curious. Today I'm joined by Snehal Antani, the CEO and co-founder of Horizon3.ai, a cybersecurity company that pioneered the use of AI to autonomously conduct penetration testing. Prior to Horizon 3,
Snehal served as the first Chief Technology Officer for the Joint Special Operations Command JSOC. As a member of the Commander's executive team, he held data analytics, cloud edge computing, and cybersecurity initiatives. Prior to serving within US Special Operations, Snehal was the CTO and SPP at Splunk. He has held multiple CIO roles at GE Capital and started his career as a software engineer at IBM. Snehal, it's great to have you here with me today.
Snehal Antani (00:57.24)
Amazing to be here. I appreciate meeting you meeting up with you again.
Francis (01:01.97)
No, it's it's great to have you and and look you've been you've been super busy. I I think I said to you before we we we started recording. Every time I turn on LinkedIn you you you seem to be in front of me off the back of the now two billion valuation of Horizon three. So very very well done there and a huge congratulations. It's a it's a massive milestone.
Snehal Antani (01:20.376)
No, it's amazing. It's a great team, great set of partners, great customers. If you were at Black Cat, you'd have seen Horizon three as a 30 story high sign at the the the Hilton World Resorts and everywhere else. So it's it's nice to invest in the brand after you've cultivated a base of champions and partners because you want to create this reaction of, I've heard of those guys, they're awesome, versus who are these guys? Right. And so it's been six years in the making.
Francis (01:51.633)
Yeah, I I I saw the picture, so I can only imagine what it looked like if you were standing in front of it. It looked pretty pretty big. Snehal I I have to I have to ask, 'cause I talk to a lot of people who have startups and when when you start out on this voyage, you're obviously you have an unknown path. Do you need to be slightly delusional to get to where you are? Like do you need a little bit of kind of I know where I'm going, I know I'm gonna end up in in in this place.
Snehal Antani (01:57.315)
Yeah. It was awesome.
Francis (02:19.216)
even if the world doesn't agree with me or doesn't exactly align with my perception, is there is there a level there that you need to go to that's, you know, below the surface that most people don't talk about?
Snehal Antani (02:30.124)
Yeah, I think there definitely is. So I would break kind of the traits of a founder into a couple of things. number one, you have to be a learn it all. What I mean by that is as a founder, like early on, as a founder CEO, not only was I the product manager and and the engineering leader, and we had an amazing team, right? Co-founder and the early folks were great at building and shipping code, but you needed to align the code they were writing towards the value you wanted deliver.
Then you had to be the CFO. You had to understand the financial plans, you don't run out of money. You had to be the the marketing leader and figure how to tell that story to the market, the sales leader, so on and so forth. And you had to put all the processes in place. And most people don't have all those experiences. And that's okay. What you need to have though is this learn it all characteristic that allows you to dig in very deeply. I think it was much harder to be a learn it all and dig in deeply five years ago.
But now with LLMs and Anthropic and Grok and whatever, you can dig into a topic pretty quickly and and get good enough to be dangerous. So I think you have to be a learn it all. You have to have grit. It is not easy. You're going to have all sorts of obstacles thrown at you. My bank went out of business in the middle of funding payroll, you know, and I had to loan the company money myself to make sure that my people got paid. That's just grit at that point.
And then conviction. You know, the funny thing about venture capitalists is people assume they walk on water as some kind of legendary business leaders. Honestly, most of them are skinny jeans wearing, latte sipping, you know, MB recent MBAs that think they're God's gift to society with no operational experience. And what you have to understand is there's a lot of reasons why a VC is gonna say no, don't take it personally. And it's you want to buck shot, you want to take a hit as many, take as many chances as you can.
And you're gonna find alignment with hopefully more than one and you're gonna find the right investor for you. So I think between learn it all, grit and conviction, if you don't have those, you're gonna struggle as a founder. And that's in addition to all the other ways a company could fail.
Francis (04:41.746)
You know, it it's it's funny when I heard you talking about there. I was reading the article on the Silicon Valley Bank and and and you having to do a personal payday to to keep everything taken over, you know, which is which is a great safety net to to have in one way, but obviously a huge risk in another because you're you're dipping into your your own pockets now, you're you're putting more risk in, you're you're putting more chips on the table and if you know, things go sideways, they go they go really sideways at at at that point.
But what you said something there about kind of being a a a learn it all and it it kind of reminded me of I'm not sure if you've ever read The Hard Thing About Hard Things. it's one it's one of my favorite it's one of my favorite books. But I was reading your posts on on LinkedIn about pirates having to join the navy, your kind of your your early crew and and and what you said there now, and all of those things kind of resonate to what Ben talks about in in in that book. Can you talk to me a little bit about the
Starting out with the pirates and then having to having to navigate your way to to join the navy and that shifting culture as the a small company becomes something greater, something with more presence, something with more responsibility.
Snehal Antani (05:47.385)
Yeah, it's it's interesting. So sales is probably the most obvious transition of pirates to a navy. So when you first start a company and you get the initial product out the door, the big question you're asking is, can I even sell this thing? Like are people willing to pay for it? And you don't really know what the price is going to be or price discount schedules or or even sales cycle or procurement process. You know, kind of, but not so much because you're launch launching this product for the first time.
Especially in a completely new category. And so you need pirates or sales reps that that don't want process. They don't want to be told how to do things. They just are gonna sit there and figure it out. So when you have three sales reps that are three different pirates, you're gonna have kind of three different ways that they've sold. And then you wanna look at is best practice or pattern match across them. And as you do enough of those, you're going to start to find a repeatable sales motion. And then you want to extract out the repeatable sales motion that worked.
And then start to build around it. And then you hire that fourth or that fifth or that sixth pirate in your sales team and you're giving them a playbook. Now it's not a strict playbook, but it's like, hey, here's what's worked already. Help us make it better. At some point, though, you you reach a critical mass of sales reps where you have a really good playbook, you understand kind of the process of selling the product, how to be disciplined at discounting, and so on. And now you've got to build this into process.
Because you need to go from 10 sales reps to 100 sales reps. And when you do so, you can't have 100 pirates. You're gonna, it's gonna be chaotic. Now you need systems and processes, discount schedules, how you qualify an opportunity. And actually, it becomes much more of a spreadsheet exercise in the later stages of a company than a true pirate creativity exercise. What I mean by that is you now know, all right, if I if I can open a hundred deals.
I know 70 of them are going to get that initial conversation. I know half of them or 35 are going to do a proof of value. And I know half of them, say 15, are going to actually buy the product. And as you see enough of that, you now know how many deals you need to open, how much revenue you're going to get if you open those deals, because it's all conversion math. And so that's when you start to think about building a navy. You've got systems, processes, structure, formulas, and pirates hate.
Snehal Antani (08:11.596)
Working in that environment. So you've got this class of sales rep that love that seed A B stage. You've got the next set of leaders that love going from like A, B, C. And then you've got the final set of leaders that know how to go from C round through IPO and beyond because they can build systems and machines.
Francis (08:32.038)
Yeah, it's fascin it's fascinating and and I suppose to see that unfold on front of you and kind of take those learnings back and talk about them means it was a real revelation as it as it kind of appeared. You know, you you see the the material change that that happens there. And and I I kinda wanna pick up on something. You you've described your time at JSOC as a kind of a PhD in in leadership. Did did that prepare you for some of the kind of the the choppy waves that were ahead when you started to get it into the scale of of horizon as actually a a
A a jet that's taken off.
Snehal Antani (09:02.902)
It it did, but in a completely different way. So my time in Special Operations One, just just for clarity, right? My military background is watching Jack Ryan and Tropic Thunder. Like I'm not a a shooter. I didn't come from a military family. And for me to leave industry and join JSOC was a huge risk for them, to be honest, because they brought in somebody that had no lineage or DNA. And it's always very dicey because you've you know you see this movie play out it into catastrophic failure where
Somebody that watched a bunch of movies and read a book a bunch of books walk into the special operations committee and think they know what they're doing. And my first day on the job, the one of the the assistant commanding generals pulled me to the side. This guy's just an amazing leader, legendary leader in mil in the military special operations community. He said, Listen, what you did yesterday won't keep you here tomorrow. You earn the right to be on this team every single day. And don't think because you read movies and or read books and movies.
You know anything about us. Keep your mouth shut, listen, and learn. And it was amazing because it's, you know, at that point coming into JSOC, I was I was the youngest at whatever. I was a super young executive and GE, I was a young corporate officer of a publicly traded company. I had, I was arrogant, I had swagger, you know, I was cocky. And I'll tell you, man, I grew more personally being in JSOC, surrounded by the greatest leaders the world will never know about.
And what I realized is my own personal growth, which is it's not about the vanity or the accolades or the accomplishments, man. It's about solving a problem that actually matters. It's about doing something of consequence. And I think if you looked at me at leaving JSOC and going into it and kind of the delta between the two me's, completely different. Completely different from a personality, attitude, values, what drove me, what motivated me.
And I needed that kick, to be honest with you. So I think I got more from them than they got from me. And I'm extremely fortunate to have had that position.
Francis (11:10.558)
Yeah, it's amazing. And I like I think to get that ground in, you know, it sets you up for for for great things ahead. So e even hearing you talking about it now, I I can tell you you you took a huge amount away from from those days. Sneo, c can I ask you something? I I read yesterday or the day before that the White House have now signed off that private companies can do offensive security against enemies of of America or people who target America. That sounds like something you'd be all over. Is is that is that
a reality now or is it did I read fake news? Is is that a
Snehal Antani (11:42.669)
It so it's it's certainly something that the administration is pushing for. I've got the I've had the privilege of of meeting and learning and and and building relationships with key cyber leaders at the White House, at homeland, at Department of War and elsewhere. And the people in the seat are quite ki like savvy. They know what they're doing, they're cyber experts, they're not empty suited politicos, like they are deep kind of experts in this area.
And so the idea is how do you impose costs in different ways? Thus far, the approach of burning down attacker infrastructure, which is really what the FBI and law enforcement's been doing, it's whackable because the next day they spin up more infrastructure. And so you're running in this hamster wheel and not making any real progress. So the fundamental question is what are the ways to impose costs? Now you can impose costs through
Sanctions, you can impose costs through law enforcement, you can impose costs by having a bigger stick and hitting back with that bigger stick. So I think that the question that the administration and I think policymakers have asked for a while is: what are the full range of options to impose costs? And let's try different things to see what we can do. Because the hamster wheel hasn't really changed enemy behavior. There are still massive cyber attacks.
There are still attacks against hospitals causing loss of lives. There's attacks against critical business infrastructure causing economic harm. You just saw what happened at Jaguar Land Rover in the UK, and so on and so forth. So I think that this is just one of a variety of concepts that are being explored to impose cost against the adversary.
Francis (13:27.282)
No, it's it's it's very interesting. That that clarifies it for me. The the post I read it kinda sounded like it was a done deal, but it sounds like there's a bit of work left to left to do to get it across the table. But it it's a it's a it's a fascinating area because and and I'll let you I'll let you I'll let you talk to this, but are is the attacker getting smarter or is the attacker getting more enabled by things like AI and large language models and and and higher levels of compute?
Snehal Antani (13:53.517)
Yeah, it's if you elevate the question to you, what does cyber warfare look like in the current era? I think there's a few drastic changes in characteristics. Number one is there's no longer a distinction between military and civilian targets. So if you look at the breakout of the Iranian war, you had AWS data centers in Bahrain, be Bahrain being attacked and destroyed by rocket attack. That's just one example. If you look at
You know, there was a story that the Japanese had provided support to Ukraine. And allegedly the Russians got angry and ransomware to a small company in Tokyo. And that company in Tokyo provided all the cup holders to Toyota. And due to just in time logistics and lean manufacturing, Toyota had to shut down 28 production lines, and it cost them almost 400 million dollars of economic harm over cup holders. The flex by the Russians was not that they could ransomware a small company.
It's that they knew where to apply the least amount of effort to cause the maximum amount of economic harm, all below the threshold for war. Because we're not going to spin up the 82nd airborne and go to war over cup holders, right? So I think that number one, there's no longer a distinction between military and civilian targets. I think number two is that AI gives the adversary unlimited bullets. So if you think about playing video games growing up,
If you played a game that had limited ammunition, you were very selective of who you shot. But if you punch in that cheat code, it was a up up, down, down, left, right, left, right, BA start. If you've ever played the old Konami games, you punch in that cheat code and you have unlimited ammo. What'd you do? Full auto. Smoke everything, no hesitation, no nothing. The same thing happens in cyber warfare. If you have unlimited cyber bullets, you don't have to only go after the big dogs.
You can go after that 30-person equipment manufacturing company outside of Detroit and take out Ford, right? If you wanted to, or at least the manufacturing lines of Ford. And so when you've got unlimited cyber bullets, you no longer have to worry about military versus civilian targets. Suddenly it's the long tail of industry that's at risk. And that's the long tail that can't fend for themselves. Water treatment facilities, manufacturing companies, regional banks.
Snehal Antani (16:17.196)
Regional oil refineries, people that can barely tread water, barely fend for themselves. So I think what we're in now is this era of cyber-enabled economic warfare that where cyber is being used to achieve national objectives, political, economic, whatever, and and the entire industry is not prepared for that that level of attacker.
Francis (16:44.392)
So what what you're saying is the question needs to be, can somebody hurt us? Not is there a vulnerability in the system? Which is, you know, what we spend a lot of time as an industry looking at is vulnerabilities, not exploitability. And I think that's where you know node zero or, you know, these capabilities come to come to the fore and and start to kind of push on that wall and see is there a leak or is there a crack or you know, can can something get through? Where where do you think we're gonna end up, Sneehall, as we progress?
down the road because compute seems to be increasing by 10x at the moment or or higher. You know, we've seen Grok's model has jumped on on on the same power as as as the GPT models and as as the Claude models in in the last week or two. Like it seems the Chinese models are coming in and smashing the market at a lower cost. Like when when compute becomes open source and available and this intelligence is consumable, is this going to get a whole lot worse before it gets better?
Snehal Antani (17:42.351)
Yes and no. So if you'd asked me six months ago, I would have said it's going to be extremely bad across the board. But we did some really interesting research around the gullibility of models. And the the thesis or the hypothesis that I had at the time when I directed the research team to do this was these models are all training on extremely shallow cyber data. Right? Last I checked, JP Morgan didn't publish.
Their network configurations online anywhere for anthropic to scoop up and train off of. All the most valuable cyber data is behind the firewall. It's not accessible to the Frontier Labs. So when you have an extreme shortage of training data, you end up training on things that are very shallow, vulnerability reports, hack the box ranges, and so on and so forth. So the hypothesis was: given the shallowness of the training data, how gullible are these models? How easy it is.
Is that to trick them with deception and honeypots and honey tokens? And it turns out it's incredibly easy because these models are are, I mean, they're not sentient. They're not like thinking on their own. They're remembering what they've seen in their data center, in their data sets. So if you stand up a honeypot that looks like Juice Shop, which is the OWASP, you know, a vulnerable web app, these models can't help themselves but chase and pursue that honeypot because that's what they've seen. That's what they remember.
Now the models will get a little bit better at that, but they're still pretty awful in the sense that a human hacker will click on a fake password.txt file 37% of the time. 37%. 464748 from the Anthropic family will click on that same honeypot or honey token 92% of the time. So almost or more than twice as bad as the human. And Kimi K2 thinking was the best performing at 61 or 62%.
Of the time we would click on it, but it still almost twice as bad. But that's an arbitrarily laid-out password.txt file. If you optimally place these things, a fake AWS credential file in the user home directory, for instance, you can get the best, the latest models to click on it 95% of the time. So suddenly you can hack the hackers. If you understand the inherent training data flaws of these agents.
Snehal Antani (20:02.284)
You're able to use deception and it's suddenly the cheapest, fastest, most effective way at catching agentic attackers. So six months ago, I would have said we were doomed. Now, based on the outcome of this research, I actually feel it's going to be a really big nothing burger for those that optimally to place honey tokens, you know, and catch the agents living off the land while also building the muscle memory for how to react to the to those alerts.
Francis (20:30.782)
So off the back of that I'm gonna have to ask you then, how bought are bought in are you to the whole my AI escape did secure sandbox and created some illegal crimes against another company?
Snehal Antani (20:40.812)
Yeah, it's it's garbage, man. Like I I have to, I'm appreciative of the demand that these companies are creating for my product. Like it's a huge tailwind. but man, it is such fear-mongering and hype. And I'm not anti-Frontier Labs, they're doing amazing things. I'm anti-fearmongering because I'll tell you what, our prototype broke out in 2019 and started interrogating all of the other businesses on the ISP.
Of my co-founder's network, right? Breaking out is something that is pretty easy to do if you don't have the right guardrails in place. So what that tells me is they don't have guardrails. They didn't invest in the guardrails to prevent them from committing federal crimes. We spent six years building those guardrails so we don't commit a crime and we don't accidentally attack somebody. It's extremely hard to build those guardrails, but it's required. And so I think that the fear-mongering, the positive the fear-mongering is we're having
Board level discussions of cybersecurity and post mythos and so on. The reality of the fear mongering is every practitioner reads the headline and rolls their eyes, which I think is going to be the case for a while.
Francis (21:53.971)
I'm so happy you said that because the minute I read it, I think I posted something to the offense of, you know, Chinese model is cheap. My model broke out and broke broke into your company, so it's it's far better, you know. which I I think there's a whole legality piece there that needs to be looked at at some point if you know the the environment is so brittle that it can just go out and attack other other companies downstream. In in in in talking about this, Snial
Snehal Antani (22:17.432)
Yeah.
Francis (22:21.158)
You've obviously got a highly capable technology on your hands and you've rolled it out in some some major companies across across the world now. You've y your client list is is growing by the day. When you let node zero loose on a network, was there any cases where you're horrified with the results or or or the company at hand, you know, went, my god, is it really that bad? Has had it did it on earth anything that, you know, was terrifying essentially.
Snehal Antani (22:50.766)
I'll tell you, I was pretty decent at cybersecurity going into Horizon 3. I knew enough to be dangerous. I've learned so much about cyber watching Node Zero hack organizations. I've learned so much about defensive controls, the effectiveness of those controls, policies, all these other ways that Node Zeros compromise you. What I have are some pretty crazy stories, to be honest with you. So the first crazy story I'll tell you is this customer.
Had an incredibly thorough password policy, you know, 14 character, alphanumeric, blah, blah, blah, blah. 70% of their passwords across their company were identical. Not similar, identical, the exact same password. And they the best reaction is when they're like, no, no, no, this is a false positive. This isn't true. Like, no man, like this thing doesn't lie. Here's the command we ran. Here's what it did. Copy and paste the command yourself if you want.
So they look at it and it turned out that they had this great password policy, but nobody ever turned on forced new password upon first login. So we had all these employees join the company, and they all thought the password they were given was the password they were assigned. Nobody ever forced them to change the password. And it was a pretty complicated password. So they like memorized this thing. And so this is an example of you do the right things on paper.
You miss one checkbox, which is force new password on login, and the entire house of cards falls apart. So I've got dozens of stories like that just from this year. But I mean, what what would you do if your team came back to you and said, Hey boss, by the way, we did all these things, but it turned out we we never forced people to change their password and now everyone has the exact same password.
Francis (24:40.744)
beat him with a stick and then go cry in a corner for a little while I think was probably the
Snehal Antani (24:45.358)
So here's another crazy story. I think it was zero logon. So this hospital had applied done everything right. They applied the patches for zero logon, which is a CVS10, like critical CVE and immediate one-click the domain admin type problem. So they apply the patch. They run us, and we exploit zero logon and get full domain admin control of the network. And the initial reaction is always the same: nope, not possible.
Because they're so tuned to things being a false positive in this world. We go off and say, like, there's no idea, there's no concept of a false positive in the way that we execute a pen test. We either successfully executed the attack path or we did it. It's very clear one or the other. So we show them the proof of zero logon. And they go to the domain controller, they look at their one of their Vaughn scanning reports, and the scanning report says, no, it's patched, but it clearly isn't, it's exploitable.
It turns out the zero logon patch had two steps. Step one was modify the registry to say patch applied. Step two, update the binary. Silence blocked the binary from being updated. So the registry was changed, the binary was never changed. And for 18 months, this poor customer had reported to their regulators and auditors they were not susceptible to zero logon. And it took us to prove.
That was the case. So it kind of goes back to the mantra of the company, which is trust but verify with the trust but crossed out. Because don't tell me we're secure, show me. And then show me again tomorrow and then show me again next week. Because the environment's always changing and the adversary always has a vote. that that's a quote I heard from my JSON commander every day. I talked to him about cyber, because that was his mentality. And it was an amazing mentality to have.
Francis (26:36.518)
I think we talked about this a while back when we were in in person in Dublin and you told me a use case where you would set node zero alive and set a timer and watch how long it takes the sock to respond and then do kind of a a top-down, bottom-up analysis to go, why did it take four hours for the first guy to to do anything? Why did it take a week for
the next guy and then run it again and and that's it. That's it. Be ready. Be prepared. And d I've actually replayed that conversation in my mind, I would say a hundred times since since you said it because it makes so much sense. That that battle readiness, that that, you know, that wartime that that wartime ready. Ca can you is is is is that something that working with government agencies and with military kind of embedded in into your mindset that you know, it's no good trusting that you're ready. You have to
really prove and validate that you're ready.
Snehal Antani (27:32.889)
Yeah, it's I've seen that in two different ways at a at an elite level. The first was my time at IBM, I worked closely with the mainframe and mainframe customers. And mainframe customers, it was it was it was absolutely expected that they would shut down their data centers every quarter and prove HADR. They'd prove failover, they'd prove recovery, and they'd build the processes and the muscle memory for how to recover these systems. And then you know the mainframe.
Doesn't crash, but you still wanted to prove what happens if an LPAR goes down, what happens if a region goes down, will parallel cysplex kick off and so on and so forth? Will it actually work? you want to go off and and build that muscle memory around disaster recovery. And I think that companies that are really good at HADR testing are also, as a result, very good at cybersecurity incident response because it's in their DNA to test that. So I saw that on the commercial side.
On the the military analogy was interesting. So I was at an exercise, I was invited to an exercise by one of the special mission units, and I got to watch how they operated. And they said, Listen, we don't practice with dummy rounds here. We train with live rounds. And I was you know, it wasn't something I was expecting, you know, it's it's an exercise, wouldn't it be be dummy rounds so people don't get hurt? And you go, listen, if if we use dummy rounds, everyone's gonna act like a medal of honor recipient.
If you use live rounds and the risk of getting hurt, then you know what you're gonna do in the heat of the moment. You've built that muscle memory, you've built that fear, you've built that anxiety, and you've built the the ability to cope with it and do what you've got to do to get the mission done. And so you he goes, We always train like we fight. Because you don't wanna learn how to deal with a crisis in the middle of crisis. You wanna learn how to deal with it ahead of time. So when things go wrong.
It's just muscle memory. So both of those experiences kind of codify this idea that you have to train like you fight in cyber. If you get an alert that's a legit incident at three o'clock in the morning, Christmas Eve, what are you gonna do? Who has the authority to shut down the entire network to prevent ransomware from destroying all your data? Do you? Does your boss? Does the board does you know what is the decision making authority?
Snehal Antani (29:56.655)
So you don't want to just train like you fight in business hours on a weekday. You wanna hit that alert button when key people are on holiday, when it's the weekend, it's the nights, and so on and so forth. You wanna build that muscle memory ahead of time so you know what to do when things go wrong.
Francis (30:14.876)
I suspect if you told that story in a boardroom, everyone would get incredibly uncomfortable all of a sudden, you know. But the the the live ammo does bring in bring it to life on the Christmas Eve or, you know, the bank holiday weekend, you know, 'cause it that's you know, anyone who works in cyber knows that's when shit really goes wrong. It's the it's the middle of the night and it's the it's the bank holiday when everyone's off. It's the yeah, it's those hours you don't expect it. So are you battle ready? That's I I love that Snial. That's that's an amazing analogy and it really does kind of just
Bring it to life. we're talking about technology and we're talking about warfare. When when you look at what's going on in the Ukraine at the moment with the absolute explosive adoption of drone technology and AI and mesh AI technologies on on the battlefield, does it take your mind to what the future of warfare is gonna look like?
Snehal Antani (31:06.54)
It absolutely does. I had the privilege of being in a role where I had to deeply think about the future operating environment during my time in special operations. In fact, one of the several lines of effort I had was the research and development line. And we always talk about the future operating environment and then work backwards. So future operating environment is in in a some window of time, whether it's in three years or five years, what are the types of what are the characteristics of
Of what our teams are gonna are gonna have to go into and what do we do to better prepare them? Give them options, give them tools, whatever else we're gonna go do. If you look at at at the time, what what we really thought about was human-machine teaming. How do we in what we call the tactical bubble? Was if you have an objective, a a house you're raiding or whatever, you've got this 300-foot bubble, virtual bubble or dome around that target. Inside that 300-foot dome.
Is incredibly chaotic. You've got little bird helicopters, blackhawk helicopters, assault forces, canines all converging on this really tight space with enemies that have a vote in everything that's going on, because they are also going to be adapting. And if you're going to start to arbitrarily throw quadcopters in there in this highly dynamic space, you run the risk of a quadcopter hitting a friendly helicopter and causing loss of life. So suddenly.
Human-machine teaming, machine-to-machine deconfliction, like these become really hard engineering problems to go off and solve. And in addition, you're you're solving these problems in an austere environment. It's dusty, it's cold, it's wet, it's jammed with GPS signal jamming and Wi-Fi jamming, and it's not a simple, clean environment. and so when you think about the future of warfare, the hardest problem to go solve is human-machine teaming in these in this 300-foot bubble.
But then you extrapolate that out, and it and the the problems are still hard, but they change quite a bit. So in Ukraine, it was drone warfare in denied environments where you've got GPS jamming, RF signal jamming, and so on. And now they've basically got fishing line worth of fiber optics cables flying behind these drones. And then, you know, so I think what's in what's interesting about Ukraine is it's become a true battle lab and and
Snehal Antani (33:29.42)
the iteration, it's the cat and mouse of one side comes up with a new idea, the other side counters it. The other side comes up with the next idea, the the the first side counters it. And I think it's more the the real innovation out of Ukraine isn't the kit, it's not the gear, but it's the iterative mindset that's been institutionalized across Ukrainian forces.
Francis (33:52.605)
Yeah, it's super fascinating to watch from a technology perspective. Obviously, the the warfare piece is is not ideal, but it's it Mikhailoff seems to have been kind of a a real driver of of force when it comes to coming up with new ways to adapt warfare and technology to the to the battlefield. The the the the one thing I want to talk about slightly is is as we move more towards autonomous technologies, and and I think we talked before about the Maven system in Iran and that school they got
misclassified and and blown up, et cetera. Is is that risk of AI replacing human judgment getting to be a bit of a tin line as to where we stand on on either side of it? Is it is it getting a little bit more complicated to go the machines right or the human needs to stand in, especially when warfare is getting so complex in the technology space?
Snehal Antani (34:41.304)
Yeah, one thing I'm actually quite worried about, and there's some really respected intelligence officers that grew up in military intelligence that talk about this as well. Where if you are if you become too dependent on LLMs or AI output, then i it's a problem. In fact, I think what makes a great intelligence officer, once again, my military experience being Trop Tropic Thunder and Jack Ryan.
But what I observed during my time in special operations is that intelligence officers are great because they are skeptical. It's that they don't trust what they see. And so because they don't trust what they see, they force people to ask the additional questions and really dig in and dig in and dig in. And then they get a more complete picture, the skeptics view, the optimist view. And then from there they're able to make an assessment. And so I found that that the skepticism is super important.
But in these junior intelligence officers, how do you protect that skepticism that's valuable while allowing them to use AI as unlimited interns to go off and accelerate understanding? And I don't think people have really cracked that code. I mean, people haven't cracked that code in academia yet. You know, my you can navigate, get an A in a course by LLMing your way through it and know nothing about the subject at the end if you if you wanted to. So I do think that in
The role of AI and military and intelligence is super dicey because you you want to make sure that people don't believe what the LLM is saying because the LLM is gonna hallucinate, it's easy to manipulate. a savvy adversary is going to corrupt training data or find ways to to steer you towards a conclusion that that they want you to to conclude, and so on. So I think that AI for military intelligence is super questionable. I think autonomy at the edge, however.
Is where you're gonna see the most incredible leaps of innovation. And I think of Tesla as the model. So if you think about Tesla, when my wife's Tesla is about to rear-end somebody, it doesn't take a bunch of sensor signals, throw it over the net to the cloud for a decision that says slam on the brakes and swerve. Collision avoidance is done on the car, in isolation. And so I think autonomy at the edge is going to be the true area of innovation.
Snehal Antani (37:04.026)
And it's a completely different speed of data compression, speed of signals analysis, speed of decision making that that is much tougher to corrupt.
Francis (37:16.934)
If you're to look out at the next five years, Neall, what what worries you most and what excites you most of of what we're seeing and and where we're going?
Snehal Antani (37:24.76)
I would say within cyber, there's no magic easy button in anything that we do. there is no AI savior that's going to suddenly make your lives better. You've got to master the art of deciding what not to fix. You've got to master the art of knowing that your security tools are actually working. You've got to master the art of training like you fight. The equivalent of that in military is shoot, move, and communicate. You know, that one of the first things somebody told me when I joined JSOC was.
Hey, this isn't an Ethan Hunt type crazy acrobatic thing that we do here. We are experts. We, this is the mission Special Mission Unit Commander telling me, we are experts at the fundamentals. We've mastered the fundamentals of shoot, move, and communicate. And that's what makes them so special, amongst other things. And so in cyber, it's mastering the fundamentals. There is no easy button. And I think over the next five years, though.
The defenders are going to hope for an easy button and the attackers are going to exploit the fact that there isn't one. I think that's just the reality. And unfortunately, it's going to take tragedy to drive innovation and change. And it's going to take a lot of a string of bad events for people to finally wake up and realize there is no easy button coming. You've got to invest in the hard stuff to get right.
Francis (38:45.842)
really like that and and it it actually resonates with me quite a bit because I see signal versus noise a lot, especially in detection capabilities, you know, where L LMs are throwing up stuff. You've got junior analysts looking at it going, Okay, well that's that, so that's fine. Next, next, next. And it kind of becomes almost like a a repetitive sport of yes, okay, rather than stop, validate, you know, question, assume the the worst case scenario. So
I think I I think we talked about it earlier on where we're spending so much time and energy asking a technology what the right answer would be without fully understanding how that answer was
Or how that answer was, you know, brought to the fore. So we're losing muscle memory, we're losing our ability to question things at a deeper level. And I think as a business owner, as a CEO, as an entrepreneur, as a founder, is there certain skills that are gonna become really critical in this new age of, I suppose, dilution of of of of the workforce?
Snehal Antani (39:56.227)
Yeah, I think a a more generalized version of the question you asked is, what does talent strategy look like in the age of of AI? And you know, I think of talent in three stripes. You've got the early career high potentials, right? You poach them from college and these kids are running 100 miles an hour, super ambitious, learn it all, crazy smart, and they're you know they're gonna be of consequence in their career. You've got
What I call kind of the mediocre middle, and I don't mean that in a derogatory way, but it's a job. What they're doing is a job. That's I saw this at IBM. There's a lot of people that were lifers at IBM when I was first when I first graduated college, and they were super happy, nine to five, doing their job, and they were doing great things, providing for their families, but they were always going to be in that kind of middle layer. They were not gonna be senior engineers, they weren't junior engineers, they were just in the middle. And there's a lot of them, the bulk of the workforce is there.
And then you had like the the senior engineers, the senior technical staff members, the absolute legends that are deep experts in architecture and code and can build anything and so on. I think AI is going to squeeze out that middle very quickly. And I think that you're going to see the seniors with using AI as unlimited interns, giving them maximal amount of capacity.
I think you're gonna see the juniors become seniors even faster because they have bots they can spar with to learn a subject even even better. And I think that that that middle is gonna be under a ton of pressure. Now, I think we've already seen a portion of this happen. So in the US, I don't know how it was in Ireland, but in the US, in 2015, 16, 17, there are a lot of government programs to incentivize learning how to code. So you'd go off and do like a 12 week boot camp.
And learn how to be a front-end Python JavaScript developer, whatever else there might be, a Python developer, or so on. Those were the first jobs to get eliminated when AI coding came into play. Because an AI coding agent could write better code faster, of higher quality, and with minimal rework. Because a lot of these second career like boot camp grads, they didn't have the expertise or the fundamentals. They were just pretty okay.
Snehal Antani (42:22.99)
front end developers. So I think it's that middle that's going to be under a ton of pressure. And they either have to acquire tribal knowledge that's going to make them sticky and and differentiated, or they're going to be put in a position where they've got to find a an an adjacent career because agents are just better at them, better than they are.
Francis (42:43.998)
It's a really interesting perspective. 'Cause my question always is, you know, when the middle erodes, you know, how does the the bottom get to the top? You know, what do you reckon the agents will have got so complex that they'll be able to kind of drag them up a layer? Do you think they'll be their managers for a while and then there'll be, you know, there'll be some sort of a transition jump? It's I I can't I struggle to visualize what this looks like, but
Snehal Antani (43:04.822)
Yeah, it it's hard, man. Like, I'll tell you what's not gonna be the case. I don't believe in the no humans at all, token maxing, like one person company building something of consequence. I I don't think that's a future whatsoever. I think that in gener and and and I don't know that this has changed that much. Those obsessed with mastering their craft are going to come out on top. Period. If you are not obsessed at mastering your craft,
You are not going to learn how to utilize agents to make you even more effective. And you're going to be an ostrich and you're going to stick your head in the sand and hope this thing goes away and you're going to get blindsided. So I think it comes down to w regardless of generational technology. I mean, in the 60s, computers were humans doing the math, right? And think of the level of of advanced mathematics required to be computed by hand in in NASA. I mean,
We've there are movies on on this. And then when computers came out, what happened? It's not that those people were eliminated, but those obsessed with mastering their c their craft adapted and became COBOL programmers or Fortran programmers and good one often did amazing things. So I think that it's easy to be afraid with all the fear mongering of AI and jobs and so on. But the honest question you ask yourself is if you're not obsessed with mastering your craft, why are you doing the job? Go do something you're obsessed with mastering.
Francis (44:33.246)
I love it. Another another absolute nugget of wisdom there to to take away. Snil, before we finish up, is there anything I've left on the table that you really wish I'd asked you just to get out there? you're like Francis, why haven't you why haven't you pulled on this tread just yet?
Snehal Antani (44:50.526)
Would I would end with there's a fundamental shift in cyber that had been going on but in pockets. And I think AI and Mythos and so on are going to accelerate the these these two fundamental shifts. We need to stop saying we're compliant, because that's a point-in-time state, and start talking about how we are resilient to attack. Because the attackers are coming. They're going to gain initial access. Are you resilient? Can you recover? We have to stop saying that we're secure, which is a point-in-time state.
And start talking about how we're defensible. If the attacker comes in, how rapidly can we adapt to prevent them from achieving their objectives? So I think in general, the vernacular in cybersecurity needs to shift from a point-in-time state mindset, I'm compliant, I'm secure, to a continuous mindset of I'm resilient and I'm defensible. And how do you institutionalize that culturally and through process and through talent and through conviction?
All throughout the organization.
Francis (45:55.9)
great note to finish on. Sniel, thanks a million for coming on and talking to me today. I got a lot from the conversation. I'm sure the listeners will really enjoy this one and have a great day.
Snehal Antani (46:05.89)
Wonderful. Thank you so much.
Francis (46:08.744)
Thank you.