Code Riff

Cybersecurity shouldn't be a luxury | Gaurav Keerthi (CEO of StrongKeep)

Eric Tan, Yaohong Ch'ng Season 1 Episode 8

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 1:16:19

gaurav keerthi has packed several careers into one. he was a rescue helicopter pilot, made brigadier-general, became the air force's first chief innovation officer, then deputy chief executive of singapore's cyber security agency.

then he started strongkeep, because he was tired of waiting for someone to build affordable cybersecurity for the small businesses everyone else overlooks.

in this conversation we cover:

- what growing up through a coup and political violence taught him about safety
- the only four ways businesses actually get hacked, and how ai just makes them faster
- why he rebuilds every ai "skill" from scratch instead of trusting one off the internet (and learns more doing it)
- why the cost of building software dropped to zero, but the prices didn't
- why he gave up top jobs in the air force and cyber to build affordable security for SMEs
- the "brilliant intern with a drinking problem" rule for using ai agents without getting burned (Simon Chesterman quote)
- how singapore's rigid system produces some of the world's best "oddball" founders
- how he hires by reading ai chat transcripts

chapters

0:00 cold open
2:34 coup, assassination, fall of the Berlin wall
10:08 security as a luxury good
16:52 SMEs and how security is often overlooked
20:50 the four ways things go wrong
27:30 emerging risks from personal claws
31:41 building a second brain, and why Gaurav built his own harness
36:15 rebuilding ai skills yourself (don't trust outside skills), vibecoding
40:55 StrongKeep demos - 7 min setup
46:20 building for when the cost of software drops to zero
50:07 ai as a "brilliant intern with a drinking problem" (quote by Simon Chesterman)
56:55 break
57:07 entrepreneurship in sg, principles of debate, hiring
1:06:40 rapid fire: books, fav place in sg, philosophy
1:15:37 thank you

youtube: https://youtu.be/UNBkWOIw-IM?is=QOdIL2tB2JNZ428A
spotify: https://open.spotify.com/show/53wI41qQXVTiydVjN7i4uB?si=9g2gxyYDQeyow-YhxUC25Q
apple: https://podcasts.apple.com/sg/podcast/cybersecurity-shouldnt-be-a-luxury-gaurav-keerthi/id1877603539?i=1000772983777
snipd: https://share.snipd.com/episode/921b3698-317f-4a8a-b302-b94262433805


how we met (the "group" mentioned)

we met Gaurav through the agentic builders collective (abc), a local (Singapore-based) community for people building with ai. https://www.agenticbuilders.sg


links

- StrongKeep (affordable cybersecurity for smes): https://strongkeep.com
- run a free cyberscan on your business: https://cyberscan.strongkeep.com
- gaurav: gauravkeerthi.com

books gaurav recommends:

- sapiens, yuval noah harari
- unspeak, steven poole
- the wisdom of crowds, james surowiecki

glossary (for the non-techies)

a few terms from this episode:

- ai agent: a program you hand a goal to, that then takes the steps itself (browsing, clicking, running code) instead of you doing each one.
- harness: the setup an ai agent runs inside, which decides what it's allowed to touch. gaurav tried the off-the-shelf ones, then built his own.
- personal claw (openclaw, nanoclaw): nicknames for personal ai agents people run on their own devices.
- least privilege: giving a tool or person the smallest set of permissions they need, and nothing more. the "$5 to a teenager" rule.
- credentials: your logins, passwords, keys, and tokens. the thing attackers want most.
- clear text (plaintext): information saved as plain readable text with no encryption, so anyone who opens the file can read it.
- vibe coding: building software mostly by describing what you want to an ai and running what it gives you, rather than writing the code yourself.
- second brain: a personal system, often ai-powered now, that stores and connects your notes so you can recall everything you've saved.
- sme: small and medium-sized business. the people gaurav built strongkeep for.

code riff: a podcast hosted by Eric Tan and Yaohong Ch'ng. we interview experts so you can use ai to flourish and have fun.

- youtube: https://www.youtube.com/@CodeRiffAI
- spotify: https://open.spotify.com/show/53wI41qQXVTiydVjN7i4uB

whether you run a small business or just build with ai and worry you're missing something, we hope this one leaves you feeling more equipped, not more behind.

cold open

SPEAKER_01

There's this huge AI push, which isn't complemented by the security push. We are encouraging people to buy cars without seatbelts and no brakes. I tried Open Claw, I tried nanoclaw, I tried paperclip, I tried Hermes, I tried the whole bunch of things. And eventually I built my own harness. Philosophically, I don't believe that people only people who are rich can stay safe, and people who are poor cannot be safe.

SPEAKER_04

That doesn't sit well with me. One thing that people are trying to build now is a second brain. What should they take note of?

SPEAKER_01

Treat it like a like a teenager or a child. Start with the least possible permissions that you would give your child and then slowly give him more and more laugh. Minister Vivian showcased his nano-claw setup. He may be a medical doctor, but the dude is also technical. Like hardcore technical. Those are the only four things that can go wrong. And AI exploits all four of those without even knowing. Do you mind sharing a bit more about the harness as well in terms of the architecture? Sure. One of the interesting things we've started doing is when I hire people, I ask them to submit their AI transcripts. And you can tell a lot about how they think from how they interact with AI. The first and the third, I will never hire.

SPEAKER_04

Hi everyone, I'm Eric, co-host of the Code Rift Podcast. We are going to be interviewing leading AI practitioners so that you can see how AI is used for human flourishing as well as to have more fun with it. Today we have a very special guest, uh Garaf Kurti. Welcome to the podcast. Hey, thanks so much for having me. How are we gonna do this today? We're gonna do it uh mainly in four parts. So, first, we're gonna just understand a bit more about your story. Second, understand more about SMEs and the risks that they face. The third part is really around how can SMEs kind of protect themselves. Uh the last part is kind of big picture and trends in AI and tech and cybersecurity as well. So, starting from the first part, you've worn a lot of hats, you know, um guards, rescue pilot, uh, brigadier general, Air Force First Chief Innovation Officer, uh Cybersecurity Agency, and now you're uh co-founder and CEO at Strong Keep. How how do you actually introduce yourself these days?

SPEAKER_01

I tell people what I love doing. Um so I don't introduce myself by the job or the title or the role. And in fact, I've never really done that. Um I just tell people what I find meaningful. Um I find it meaningful to use whatever skills and knowledge I have to help other people feel safer and secure. Um that's a very special place in life. And whether I use that to run a startup, use that to advise companies, use that to advise board members, use that to you know build stuff, it it that's that's the how. The why is what I used to introduce myself.

SPEAKER_04

You wrote uh essay during one of the uh Toto Defense uh days in 2016. So I we've dug up quite far. Ten years ago, man, you guys think something I saw it in your essay and found it very interesting that you you grew up in multiple places, uh, you know, India, Nigeria, and more. And also um even in some violent or conflict prone zones as well. How has that affected your appreciation for cybersecurity and maybe even your time in the Air Force? And what was that kind of like common threat that uh tied everything through?

coup, assassination, falling wall

SPEAKER_01

So about 10 years ago, I was invited back to my Alma Meta Secondary School to give a speech on Total Defense Day. The speech itself was called Doubting Singapore's Defense, which is not the kind of a title of a speech that you give on Total Defense Day. But, you know, I I did a debate when I was a kid and I wanted to address any of the doubts head-on. So that was the context of that speech. And kind of to let people understand where I was coming from, I thought I'd share with them a bit about my childhood. So, Eric, as you rightly pointed out, I did not I was not born here, and I did not grow up here. I came here when I was about nine, ten years old. But the countries I'd lived in before that were rather I mean, they weren't meant to be crisis-torn, they were just accidentally crisis-filled. So I was born in India, but then very quickly, like less than a year later, we moved to a place called Nigeria. Uh, and Nigeria was actually, back in the 80s, uh, an engineering capital. Like people thought that Nigeria would grow up and become, you know, what Singapore is today, you know, full of engineers, lots of manufacturing, and today there's there's a lot of manufacturing there. But then in the early 80s, there was a military coup, and uh, you know, it didn't work out so well for the foreigners who were there, so there was a lot of uh internal violence and internal kind of disruption. So we left, went to India for a year, and actually we thought we were gonna move back to India. My parents did. Uh except the year that we were back in India, uh, the Prime Minister got assassinated by her own bodyguards, and it was a race and religious conflict, and it erupted into the streets. And the area that we were living in happened to have both of the races and religions living in the same area. So, needless to say, it was quite uh exciting as a child to watch all of this kind of crisis unfold in front of you. So we left India and we went to West Germany. Uh, and West Germany no longer exists today. Uh, it is now just called Germany. But at that time, West Germany and East Germany were separated. And East Germany was the part that was communist and separated behind the wall, and West Germany was the modern democratic engineering capital. So my dad took an engineering job there as well, and we were there kind of working and living. And I actually studied German and grew up believing that I was going to become a you know a German resident one day. And then the wall comes down. Uh, and then all of a sudden you have these East Germans who have never seen anybody who does not look like them, and grew up in kind of the post-Hitler era of this is all what you know people in Europe should look like. And suddenly they come to West Germany and they see all these different colored folks, all speaking German, going to school with you know German kids, and it's a bit jarring. Some of them are fearful, some of them are accepting, some of them are angry. And the angry ones, we now know them as neo-Nazis. And so that became a very violent kind of reaction to me being a different person. So again, we moved and we eventually came to Singapore and uh started off in an international school, got you know a better grasp on kind of local English and languages, and eventually transferred to local Singapore kind of secondary schools uh after that. At that point, my difference was not unusual. Like nobody really minded the fact that I was not of the majority race. It was like, yep, you're one of you know many of the other races living in Singapore. That's cool. You know, what's the the conversations were about who I was and what I wanted to do, as opposed to my race, religion, background, ethnicity, and so on, which was fantastic. I was like, this is amazing, I never want to leave. So when the option came out to apply for university, um, I was like, look, I'm gonna do NS first and then go to university. And obviously my parents are like, Oh wow, why you are mad? Yeah, crazy. Everybody else is trying to do the other thing than like trying to get out like some NS. And I was like, no, if there is a there if there is a chance that I might never be able to come back to Singapore, I will be very sad. Uh and I would actually rather have the stability, confidence, security that Singapore offers me in and trade off two years for that. And I was okay with that. So I actually volunteered to sign up for NS at the point where they did the whole CMPB thing. Uh, and I joined NS. And uh I actually deferred my university, so I got into Stanford before NS, and I deferred it for two years, and uh was expecting to finish my NS and then go. And then along the journey, uh my A-level results came out. I did relatively well, uh, and I got offered uh scholarships. Then the interesting thing came about that I actually started enjoying the military, and I was like, this is actually kind of fun. Uh it's not terrible. Uh and it actually allowed, I felt I felt the message resonated, like I'm actually able to help build on the security that I valued so much. Uh and so they gave me a government scholarship, and I was like, hey, how about this military scholarship? Can I can I get that one instead? Uh and they were like, you must be nuts. You weren't born here, you didn't grow up here. We're certainly not letting you look at our classified files. Um, but eventually I was persistent enough and supposed to be, I guess, eventually was good enough to qualify for it, so I got the military scholarship and then went off to Stanford that year. So I didn't end up deferring things at all. But I guess that the point of the story was that the childhood experiences I had shaped me to think of security and stability very differently from anybody else. And I didn't even realize that. Like at no point in my teenage years, like I crave security and stability. It's just that when the point came about for NS, I was like, hey, this is actually something I find meaningful. I would like to do this. So that's that's the start of the journey, man. Uh my childhood was the thing that led me to joining the military. And I actually signed up in the army before I joined the Air Force. So it's actually a guards officer first. Yeah.

SPEAKER_04

Dang.

SPEAKER_01

And then one day we jumped out of a helicopter and it's like that's a terrible, stupid thing to do. I want to apply. Yeah. This jumping out of a perfectly functioning helicopter sounds like a really scary thing to do. So I switched.

SPEAKER_04

Oh, thanks. Amazing. Wow. And you mentioned that you waited many years for someone to build affordable uh security, and no one did, and you were done waiting. So, what did leaving you know the Air Force and the cybersecurity agency uh really take uh for you personally to start Strong Keep? And maybe before that, explain a bit more how you would explain Strong Keep to maybe your SME boss or Tao K in our local language here as well. Yeah.

SPEAKER_01

Yeah. Um I mean I'll explain what I what Strong Keep does and then I'll kind of go backwards and explain how I made the various leaps.

what is Strongkeep, security as a luxury good

SPEAKER_01

Um so StrongKeep is basically uh if you think about it, the internet has bad people. And good people need to take precautions to stay safe in that outside internet world. Strongkeep gives you the tools and the processes to help companies stay safe. It's as simple as that. Uh and without it, unfortunately, it's a it's equivalent to having a car without a seatbelt or a house without a gate. You've got something precious, it means something to you, and you're not protecting it, you're not staying safe. So it's just that additional top-up that you put on something that you value to keep it safe. Um that's what Strong Keep is. And it's fundamentally different because all of security has been built as a luxury good, and we can talk about that later on. It's expensive and complicated and fancy, but I'm just building simple door locks, simple seat belts. Like, you know, if you want to buy fancy ones, there are places you can go to do that. But this is simple, hence the affordable part. Now the leaps, like, how did I end up here? Uh and I will guarantee you that at no point in my childhood, if you had asked me, like, hey, one day you're gonna become a CEO of a cybersecurity startup, I'd be like, bruh, no way. Like that is not a thing on my plan ever. Um and I mean at the point where I where I had not yet joined NS, if you told me I was gonna become a general, I'd also be like, also not part of my plan. I'm a computer science student in JC, like that's never gonna happen. But one thing I realized is that, uh, and I attended a so in my college, this, you know, there's a very famous speech by Steve Jobs, and he said that your the story of a life only makes sense looking in in reverse. You can only connect the dots of your story looking backwards. So now I can tell this great story, like, yeah, actually everything builds up to this point where I'm the expert in security and I understand safety in different domains. I can tell all of this now. It's a great way to make the story make sense backwards. But at no point when I was 18 or 20 or 25 or 30 or 35 or even 40 would I've been able to predict the next dot in my journey. So so I don't think I ever took, embarked on any journey thinking that it was gonna lead to the next one. When I was in the Air Force, I didn't think I was gonna stay. I mean, I had a great university degree uh in a subject that was very lucrative, and I thought, you know, I'll do this flying thing for a couple of years, and then I leave. And then the flying thing turned out to be really fun and really meaningful, and I did a lot of absolutely awesome things, met some amazing people, and my closest friends still come from that community, and I was like, well, I should stay on a couple more years, maybe one or two. And then I started doing well in that job, uh unexpectedly, uh, and I started moving up in the ranks, and then before you know it, you know, I ended up with a rank that I never expected to get at all. Like, there's no at no point in my conception of my career that I thought I would end up at the rank that I got, let alone to get it kind of at the earliest age that it could be given. Um so all of those things were like, wow, okay, cool. Uh and there are many things that have not worked out for me, but some things did. And so these things worked out, and then ended up in cybersecurity agency. And then even there, I was like, look, I love helping big companies, they've got big budgets, they've got really talented people, and I love keeping them safe because you know, if I can keep the electricity on for the average Singaporean, that's a good thing. If I can keep the trains running for the average Singaporean, that's a great thing. But then more and more I started looking at the whole ecosystem. I was like, hey, there's a whole bunch of smaller companies, like, you know, the one that you're gonna be joining. And these smaller companies have nothing. It's not even like they they if they had a little bit of money, they knew what to do with it. It's it's there is no option for them to even stay safe. And I don't like that. Philosophically, I don't believe that people only people who are rich can stay safe, and people who are poor cannot be safe. I that doesn't sit well with me. So in the real world, it's not like the police only gut rich people, they don't got the poor people, the military only protects the rich people. It doesn't work that way in the real world. The military and the police protect everybody. So cyber should be the same. We should have, you know, accessible content, and which is why a lot of the parts of cybersecurity that we built on Strong Keep, I actually push it out for free, even. Um because I do think it should be made available to everybody. It's essentially what we call a public good. Uh and so that's kind of how I ended up wanting this to exist. And we put out grants, I created a whole bunch of innovation and incentive schemes, and every year I was like, hey, somebody try and build this. There were one or two attempts, but nobody quite got it right. And everybody tried to prioritize monetizing it over democratizing it. Which I can understand. I mean, you're running a company, maybe I'm a terrible CEO, maybe I'll never make money, but they all wanted to prioritize extracting as much profit as possible as opposed to doing as much good as possible. And I'm kind of of the worldview where I think I can do well by doing good. That's thus far worked out for me. Hopefully it continues to work out for me that the more good I do, the better I do, uh, you know, uh both financially and in general in life. So that's kind of the the the space that I'm in now. I didn't see anybody else building it, or at least building it the way that I thought it should be built. And eventually I got fed up of waiting and said, let me just do it my own. And when I was in Enzyme, which was you know a Tamasek held company, um, I started researching it there, hired a team, and as we started building it, we fell in love with it, and eventually I left the company, took the product with me, and my absolutely crazy team of engineers and designers and product managers decided to resign with me. So they all left the salary of a essentially Tamasek linked company job to join a startup founder with no prior experience in running a startup, absolutely no commercial model, and just a passion for building something. That's like y'all are crazy. They're like, yes, we're crazy together. And so they're all still in the room next door. They're all still in the room next door working hard. But it's it's amazing. And that's the kind of purpose and passion you see. I think that if companies aren't hungry, they don't quite do things the way they should. Uh and so that hunger feeds us. Uh, it's I mean it's uh ironic, but the hunger does feed us. It makes us push harder, it makes us want to understand the pain points and problems a bit faster and deploy things to solve problems quicker. Um and to some extent, I think we have moved faster in the year that we've been out than in the two years that we were in.

SPEAKER_00

Wow.

SPEAKER_01

Amazing.

SPEAKER_00

And you're selling um directly to SMEs?

SPEAKER_01

We are selling directly to SMEs as part of the strategy. But as you will hear in the next couple of weeks, we're gonna be bundled into some of Asia's largest banks, we're gonna be bundled into some of Singapore's largest telcos, and hopefully if things go well in the next couple of months, we'll be bundled into a European telco as well. Which means when you open up a telco plan, you get Shronky. And that's tens of thousands, if not hundreds of thousands, of businesses. Uh and in fact, one of our partners, which is also a financial institution, will open us up to millions of businesses. So that is the kind of scale that we're looking at at serving. SMEs hopefully will always be able to find us. We always want to remain affordable and kind of simple and comprehensive for their needs. But we realize that many of them will buy it as part of a broader setting up my company

SMEs and how security is often overlooked

SPEAKER_01

strategy. Right, right.

SPEAKER_00

Because we know when you talk about SMEs and security, usually they don't come together, right? No, not at all. Yeah, share passwords and single account and multiple accesses and all that. Yeah. So how how do you go about attacking this problem?

SPEAKER_01

Yeah. No, it's it's a great question. Like, fundamentally, we've made cybersecurity hard. That's the pain point. Like, if it was easy, people would do it. I'll give you a simple example. So when I first joined the cybersecurity agency, um every government agency had a different username and password. And so guess what? Everybody reused passwords. And we will tell people, hey, don't reuse the password, you know, use separate passwords, use strong passwords. We actually had posters on the bus everywhere, like use strong passwords, use unique passwords, because every government agency would use its own system. Uh today we have SYNCPASS. And for many years, while I was in the government, I was a security kind of lead for the workgroup that looked at the security of SyncPass. So we actually essentially was a security architect in SyncPass. And I was like, let's do away with passwords. I just don't want passwords. I don't want username and passwords. I want everybody to just log in using their phone. Singaporeans have an average of like two point something phones per person is ridiculous. So everybody definitely has a phone if they need to log into a government website. And if you think about that experience now, using SyncPass is more secure and also easier. So security has become an easy solution for SyncPass, for government websites. Can we do the same thing for the rest of security? Can we just simplify the entire experience of managing passwords, managing device protection, managing all of these things instead of making it so troublesome? That's the philosophy. So that's why simple is the starting word. We make simple, affordable, comprehensive cybersecurity. Simple has to be the starting point. Because if it's too complex, nobody's gonna do it. True? And there are many ways we can make it simple, we can talk about those, but simplicity has to be the core of what we're building and how we build things.

SPEAKER_00

And of course that comes along with it a lot of um security risk. I'm sure within your firm you also probably have the same issues, or even um how you're sharing data with the LM models or SMEs definitely are not equipped in that ideology of simple, right? So how how can we educate the listener or the whoever's listening to have a second thought when it comes to using AI and and in their business or in their personal life and with security itself.

SPEAKER_01

Yeah. I mean I'll start by saying that actually we're in a very awkward situation from a policy perspective first. You know, there's so much policy push, both from the governments and enterprises and just technology providers as a whole to adopt AI. It's like there's this huge AI push. Which isn't complemented by the security push. And the way I explain it to people is like we are encouraging people to buy cars without seatbelts and no brakes. It's okay, buy the car. The more powerful the engine is, the better the car is. You know, how many tokens can you process per second? How big is your model? Whoa, whoa, what token maxing. But you're essentially selling, yeah, token maxing. You're essentially uh pushing people to use AI without security as a complimentary part. Um and and nobody sells cars without seatbelts. Uh nobody uh you know funds the the digital side of thing without implementing some risk controls. But that's what we're doing right now. And so I think from a really kind of a national level perspective, we need to step back and say, hey, if you're buying a car, it must come with seatbelts. The seat belts don't need to be expensive, the brakes don't need to be expensive, but they need to be there. And so if you're implementing AI, there are a couple of baseline things you need to implement from a company perspective. Malware protection on your devices. I mean, philosophically, again, you know,

the four ways things go wrong

SPEAKER_01

what can go wrong on a device, even with AI or without AI, you download something that's malicious, you go to a link that's malicious, you know, it's stealing your credentials, whatever it is. Um, you have your credentials stolen, or your systems are poorly configured and then they're hands kind of broken in, uh, so that not patched. Those are the only four things that can go wrong. And AI explodes exploits all four of those without even knowing. Uh AI will like, oh, I need to build this software, let me download this Git repo. Yes, yes, yes, yes. And you just you don't even know what this repo is. You just randomly download it and it installs a bunch of things. And we had a customer do that, and we stopped, I mean, we we saw that it was downloading something that we thought was malicious, and we stopped him from downloading it because we're like, look, this is not safe. Uh you can download a bunch of things that might be safe, but this particular one was not. But if you don't have that basic tool, and we had a tool on his laptop that was scanning for whatever he was downloading, you'll never know. So at least having some basic protections on the device. Allow me to say, is this file a virus or is it something credible? Is this link that you're going to actually the GitHub website, or is it a fake GitHub website there to steal your credentials from GitHub? So all of those kind of basic protections need to be in place. And they're not expensive to do. Theoretically, you could do it for yourself, but they need to be there.

SPEAKER_04

So, Garav, if I if I understand what Strong Keep is, it's for SMEs, uh, security member or security staff or like an IT professional that manages your security for you. Because when I was in uh in corporate uh in management consulting, you would have you know so many restrictions on the things you can download. But I think all those were placed by the IT professional. And then if I needed permission, I would go and find the IT department and then they would kind of allow me. Usually they won't allow me, but uh to download different things. Yeah.

SPEAKER_00

Is it kind of like a jump cloud uh-ish kind of setup?

SPEAKER_01

Not even.

SPEAKER_00

Like a multi-device management.

SPEAKER_01

Yeah, so it's it's it's basically I told you the four things that can go wrong. So downloading something. So we have uh anti-malware agent on the laptop that checks everything that's being downloaded and run. If you plug in a thumb drive, if you connect to the internet, download a file, if an email attachment starts to execute, we check it and we block it. Then we have uh what's called a DNS firewall. We check every place that you are clicking and going to. Whether Claude is clicking it or Codex is clicking it or you are clicking it, it doesn't matter to me. As long as your laptop is connecting to another DNS that I or another URL that I can hijack, I will check. Does this look like the DBS website, but it's actually a fake DBS website? Does it look like the GitLab website but it's a fake site, or does that is this a known malicious site? This is some sort of a hackers C2 set server that I'm that you're connecting to, and I'll immediately block it. So then neither you nor the AI can connect to those things. Then the third one is credentials. If I start seeing your credentials all over the place, so you know, you give Claude your login for Gmail, you give Codex your login for Gmail, and then a week later I start seeing it on the dark web. I know that this guy is, I mean, this guy, this agent has gone and auto you somewhere, or somebody's extracted it from your agent. In which case I'll flag up immediately, your credentials have been stolen, time to rotate. So you instantly know that something's gone wrong. Then the last one is uh you know security configurations. Your WordPress isn't configured correctly, your system isn't patched, you know, whatever vulnerability we see on the internet, if it applies to you, please fix it. So those are the four things that we bundle together. And the whole idea is how do we make it so easy to use that somebody with a non-technical background can set it up on their own quickly. And right now our record is uh a non-technical, I think she was a nurse, set it up in seven minutes. Wow. So from the point where her payment went through to the point where devices were protected is seven minutes and non-technical user. And that's our kind of that's what we measure. I want to see how quickly people can get things done within the same session. Because if you have to go back and click this and install that and plug in this and configure that, you're never gonna get it done. But if it's as simple as click install, wait, click confirm, wait, okay, I'm done.

SPEAKER_00

I mean, the last time I had to roll out uh jump cloud, I it was not enjoyable. It was jump cloud, yeah. Yeah, well, jump cloud is a multi-device management software, you know, kind of uh installing on your laptops or your mobile phones, and then you kind of what Carol said, right? It checks your DNS, it checks, it protects you, you you can uh track the traffic, right? And and it wasn't even a big enterprise, right? So yeah.

SPEAKER_01

So we actually so if you think about it, something like that is useful, but you can rebuild all of that to be much easier, and that's what we've done. So a company that doesn't have you know mobile device management, how can we deploy software to everybody's laptops in an easy way without all of that overhead of installing this kind of infrastructure?

SPEAKER_02

Yeah.

SPEAKER_01

Well, the way that people currently do it is they get a link that they trust and they click a download, and there's a package file that comes down. So, can I actually create my own MDM using email as a platform? Right. I create a secure encrypted link, I send it to all of the staff, only they get it. It is tied to their email addresses. When they click it, it validates it, and the package downloads and they install it. So even a 10% company with no tools can deploy an installer to 10 different laptops, even if they're deployed, even if the staff work from home or work overseas. And we've seen that. We have a company that has like 15 staff, they work all over the place, including overseas, and they can deploy without any tools. That's how easy you want to make it. So simplicity actually has to be the core. And that's why like user interface design, user journey design becomes so important. Yeah.

SPEAKER_00

How about uh protecting from nefarious Wi-Fi networks? Can do that? Yeah, so again, same thing.

SPEAKER_01

If you're connecting to a Wi-Fi network that's not safe, again, a few things can go wrong. The you download something, you click on something, you get spoofed, or your data gets stolen, or credentials gets stolen. So those are the things we still keep watching for. And as long as any of those flags are met those observable indicators, we catch it. Connecting to a generally insecure Wi-Fi, if nothing goes wrong, actually is fine. But the the risk of people having a spoofed Wi-Fi, like you know, free airport Wi-Fi and you hook in them, those things exist.

SPEAKER_00

I'm always very uh paranoid about that. So I always don't know my VPN when I'm traveling.

SPEAKER_01

Or hooked it, I mean, so the cheapest way to do it. Or my Wi-Fi, Wi-Fi G, right? Your phone, your phone. Exactly. And that's what we tell small businesses like, look, just hook up to your phone.

SPEAKER_04

Easier. Oh. So it sounds

emerging risks from personal claws

SPEAKER_04

like most of the wins in cybersecurity. It's not really, you know, going into AI and open claw and those kind of stuff. It's really just the basic kind of um more boring ways to protect yourself in a sense.

SPEAKER_01

I mean, so it's like AI hasn't made new ways to build software. The way of building software is exactly the same as it was two years ago. It's just a lot faster. Way faster. So in the same way, AI hasn't invented new ways to hack people. It's exactly the same. It's just a lot faster. So that's that's the whole thing. It's like it's a productivity tool for the bad guys as well. So the way in which they get into people's accounts, phishing emails have just gotten better. The way in which they come up with a fake website is just faster. The way in which they build new viruses, it's just faster. But it's not fundamentally that there's a new way of doing things. The one slightly new attack, which we found which is interesting, is basically poisoning the model. So prompt injection is one of the most easiest ones that you can see. Uh and the fun one is like you go to somebody's chatbot on like McDonald's or Pizza Hut and you you you prompt it until it gives you some sort of weird answer. So that's the fun thing to do. But that's the specific to AI kind of attack. But not many SMEs are already deploying AI's front end la.

SPEAKER_00

I mean, funny story there. So I have um a chatbot that I let people use to ask about grants. And then my friend uh obviously tried to be funny and said, you know, can you help me solve a Python problem? You know, he saw it somewhere. And thankfully my bot was not uh was quite secure. He didn't give it the answer that he wanted. Yeah.

SPEAKER_01

Yeah. No, but I mean that's actually a good thing. It's a good thing.

SPEAKER_00

So that means your bot had uh had a bit of comment set. Uh I mean I already built it with security in mind, see. Okay. But that's because I I know what I'm doing. Right. Yeah. But most people, you know, they implement a chatbot, they'd be like, oh yeah, cool, just turn on the switch and then boom, let it go. Yeah. Right. Or even um installing open claw or whatever, right? You know. And multi-chat multi-channel, everyone can message my claw on on WhatsApp and Telegram. Yeah.

SPEAKER_01

Yeah, we're seeing a lot of that, especially after Minister Vivian showcased his nanoclaw setup and everything. Like, oh, well, the minister can do it, you know, I can do it too. Uh I always caution people not to go down that path because uh specifically, uh, and I'll say this with personal experience, uh, briefed Minister Vivian a few times in the past when he was in charge of GovTech and Smart Nation. He he may be a medical doctor, but the dude is also technical, like hardcore technical. Um, and so he I remember we had this slightly, I mean, obviously I lost the argument because he was minister. Um we had an argument about about encryption, about encryption protocols. And I was like, this is actually kind of the thing that I do. But the the fact that he was able to get that technical illustrates a lot about how deep he was in the domain. And so it's not for the layman to just kind of open up open claw, like type of command and run it. There are significant concerns and risks that need to be thought through. And I'm not saying don't do it, but the way I tell people to do is you know, treat it like a like a teenager or a child. You know, start with the least possible permissions that you would give your child, and then slowly, day by day, as he shows that he is responsible and growing up into a smart young person, give him more and more, lah. So don't straight away like, here's my wallet and credit card, have fun, kid. It's like here's five dollars. Okay, let's see if you come back with you know the exact change from the bus on the way home. Ah, okay, good, you did. Okay, now you can go to the shop and buy uh, you know, some candy or something. Then you slowly see whether he's capable of acting maturely with the permissions that you give him, and day by day you add on to that. Uh a simple example is don't let your chatbot write emails directly. Let it draft. Sit in the draft, you vet. And you let it vet, you know, draft and draft and draft, and you vet and vet and vet. And eventually over time, you're like, okay, you've gotten quite good at this thing. I think you can send out these types of emails to these types of people. Can you? So then you start giving it more and more permissions and scope. So treat it like a kid.

SPEAKER_04

That's what I've been doing with my codecs and buying carousel deals when it comes to you know buying different things as well. So using codecs and cuts. I love codecs computers. That's interesting. Um, but but besides that, sorry, I have one burning question. I I think this is more for the SMEs who are

risks of making a second brain, Gaurav's harness

SPEAKER_04

AI forward. One one thing that people are trying to build now is a second brain. I'm just wondering what kind of stuff are you seeing, like emerging risk-wise, when it comes to these uh companies trying to build second brains, do open claws, and do all that kind of stuff as well. And and what should they take note of?

SPEAKER_01

I mean, so I'll give you my answer first, which is I don't know if it's reassuring or or concerning, but I tried OpenClaw, I tried nanoclaw, I tried paperclip, I tried Hermes, I tried the whole bunch of things. And eventually I built my own harness. So these things are all called harnesses. I ended up building my own. Partly because I found that the security usability trade-off wasn't ideal for me. I run a cybersecurity company. I need my harness to be more secure than what was available out there. And so I ended up creating my own permissioning structure and my own agentic structure to make sure that my second brain for my company behaved itself. And particularly because my second brain for the company is constantly reading stuff about viruses and malware and hacking other people. I don't have to accidentally believe that, you know, hey, this is what I do for a living. Great, let's go and try this out. So it needs to be mindful of that gap between understanding what it's reading versus applying what it's reading. So I built, we call it Workforce OS, the you know, the chat group that we're in. I've shared more details about it. But it's really a fundamentally different architecture for how these harnesses work.

SPEAKER_04

Do you mind sharing a bit more about the harness as well in terms of the architecture? Sure.

SPEAKER_01

I mean, so you've got your base model, which is you know, Claude or Codex or Quen or whatever it is, so that's the LLM that you use. But then on top of that, you have agentic structures, which is that the LLM can call tools and uh operate somewhat autonomously. And then you've got a harness which gives it the context of what the business operation is and the processes and workflows that it's supposed to run. So an LLM could be Quen, the agent could be uh check Twitter and write Twitter posts, and the harness is this is the context of my business. You are my social media expert, you will every day research these topics and write these things. So then that's the whole harness around your social media agents, whatever it is, lah. Um what Workforce OS basically is, is um I realized that many of these claws and whatever else is there out there, were built for solo founders. I have my own personal fleet of kind of virtual bots that support me in my task. That's great if I did not actually have existing stuff. Um and one of the human dynamics I found in the past was that if you try to tell people that, hey, I'm gonna implement this tool, don't worry, it's not to replace you. They will immediately think it is there to replace them. So the only way that it works from a social change dynamic perspective is that they have to feel like this is their productivity tool, not their replacement tool. And so I had to build essentially a fleet of agents, each one paired to different staff, to become their productivity tool, but these agents could work together. So I have my own agent, he's called Knight. Uh, my CEO Tsai Shao has Carlton, my product manager uh Clement has Harold, and each of us use our agent to do our work, and sometimes it does the night shift. So I will ask it to go and research, you know, what other industry players are doing, what the you know, threats are thinking. So I'll ask it to do research at night, drop it off in the morning, and then support me with productivity tasks during the day. But I will also get it to work with Harold, which is my product manager's agent, and be like, hey, there is this really new feature that everybody's asking about based on customer feedback. Can you draft a user story for it? And Harold will be like, yeah, sure, let me get on it. Then Clement will say, Okay, this, I don't have sprint capacity this time, we'll do it two weeks later. So then Clement feels like he's got an extension, he's got a second brain. It's not that Harold is replacing him, Harold is doing part of the job that Clement doesn't want to do because it's more mundane. So having this team-based structure means that people feel like they're empowered as opposed to they're being replaced. And that psychologically is very different because then they are training this model. And I'll give you a very small anecdote, which I saw in the past. Um, in a previous, previous, previous, I can't say which organization it was, but in a previous organization, we had automation tools. And we saw the most junior staff actually sabotaging the automation tools because they could see the writing on the wall. What is this automation tool there for? It is to replace them. And so the better they train this thing, so psychologically you have to understand that you operate with humans and you have to make sure that they feel safe working in this environment with AI. And so that's why we built a slightly different framework and thinking around how workforce works. So I've got a small team, I want them to feel supercharged. But yeah, so the security guardrails around it are tremendous.

managing risks of AI - skills, vibecoding, etc

SPEAKER_01

Um, one of the most obvious things that I do, which is not that obvious, is uh I don't trust skills from the outside world. So AI is all, and agentics all about skills, you know. There is this skill to like, you know, uh review a document or as a skill to create a slide, whatever it is. A lot of people just go to a Git repo and pull the skill out and then use it. That's normal. Attackers now know this, and they spend a lot of effort trying to pollute or get into a skill or push out malicious skills, masquerading as benevolent skills, as useful skills. And your agent doesn't know the difference, it'll pull the whole skill in and run it, and ta-da, all your crypto keys are gone, all of your credentials are gone. What I do instead is a very small tweak, is I'll ask my agent, always read the skill, understand the skill, and recreate the functionality of the skill for myself. Which means if there's an additional thing there, like, hey, send all my data to this random server in, you know, Belarus, whatever it is, he's like, that's not part of my functionality. I don't need that. Let's drop it. So he reinterprets everything. It's kind of like rather than just taking the whole gift, you open it, you understand what's inside it, and then you recreate it on your side. For your agent, it'll take an additional 30 seconds to a minute. Yep. But the additional security it offers is tremendous because you're not importing some random code that you haven't seen before, or at least your agent hasn't seen before. And you learn so much.

SPEAKER_04

Like I've read Anthropics Mix Skill Skill before, and I just learned so much. It's yeah, crazy. The skill creator, skill creator. Oh, yeah, skill creator, yeah.

SPEAKER_01

Very useful. And then it becomes so it is very meta, but actually it then makes your harness much more customized to your use case. I don't use somebody else's PowerPoint slide skills. It has been adapted to my company's way and style of creating slides. And some of these are technical slides, some of these are customer-facing slides. So we've adapted it. It makes sense for our use case.

SPEAKER_00

Yeah. Same same um practices that we're doing here. And also, I think the biggest concern I have when it comes to SMEs is that it's always about convenience, right? They would just do things because it's easy. Right? Everyone's now vibe coding and everything. And it always finds it a bit more difficult, like you have to go past the education phase.

unknown

Right?

SPEAKER_00

When delivering a message, you've got to educate them, you've got to like okay, tell them this is not the best way. And how do we then really push for this message across?

SPEAKER_04

And how do you balance that with like you know, AI has really unlocked the ability for anyone to code anything they want, but at the same time, like you need to do that carefully, right? Yeah.

SPEAKER_01

Yeah, I mean, so let's let's kind of um take that one by one. I don't think that education and awareness is the problem. I honestly don't. I mean, people know that if you drive a car and you're not wearing a seatbelt and something goes wrong, you'll die. It's not like awareness is the reason why they're not wearing the seatbelt. It's, you know, maybe it's troublesome, maybe it's there in a rush, maybe so there's other factors there. So focusing more and more on awareness and education, maybe it has an incremental impact, but not a significant unlock. It's like passwords. You mean there are Singaporeans who don't know that stronger passwords are better than weaker passwords? You mean that people who don't know that reusing passwords are bad? Obviously not la, they all know. But it's so troublesome to use unique passwords. So tackle the actual problem. Make it easier. Make it easier to adopt better habits, make it cheaper to adopt better habits. If buying seat belts on cars added an extra $300,000 to the price of a car, I guarantee you nobody's ever gonna buy seat belts. But if it's like an extra $10, yeah, hey, pull the seatbelt, what do you think about? So if cybersecurity costs an extra $10,000 for your business, yeah, nobody's gonna do it. If it's an extra like $39 a month, I mean that's like one, two lunches, okay la, can la, can la, you know. Happy to go ahead and do it. So when it becomes cheap enough to implement, when it becomes not a budgeting factor like, hey, we need to set aside money next year for cybersecurity, it's like I I definitely cost less than your AI. So if it becomes that cheap, then not so hard. And at what? Hey, seven minutes can read, yeah. Uh okay la. Then hey, you do over lunch, like okay, settled. And if it starts to work by itself in the background, it's blocking things that you didn't even think about, it's keeping you safe without you having to think about it, then it becomes part of your lifestyle. And then actually, it's not a thing that you need to do, it's a thing that you did one time and you're settled.

Strongkeep demos - 7 min setup

SPEAKER_04

We can do a quick demo of uh cyberscan, and maybe if you have anything else to add, feel free to share a bit. Since you know you're teasing us so much about what you do already. I'm not very curious. Really, seven minutes, really, bro?

SPEAKER_01

Let me do the second okay, let me do the seven minute one first, and I'll show you the cyber scan.

demo - 7-minute onboarding

SPEAKER_01

Yeah, cool. So we have a we have a demo. Uh, this is obviously not the live one, yeah. Uh, but this is basically exactly what a company will see. So let's start setting up the production. It's four steps. The first one is you type in your email and we'll figure out your obviously if it's a Gmail, we will get it for you. If it's uh company website, we'll just get it automatically. We'll scan your website, both the email and the web server, to just check that all the security patches are all done, to see if you're using WordPress, it's patched, etc. We do all that. Then we say, look, we have device protection. Do you want to do it via MDM, which is what we spoke about? People who don't know what MDM is will not. Sorry, what is MDM again? Yeah, mobile device management. So this is perfect. Because if you don't know what it is, you will stay here.

SPEAKER_00

Yeah, you'll stay on the first one.

SPEAKER_01

Yeah. So that's actually uh desired behavior. So send it to my staff la. Okay, I don't know what all these things are. You just send to me la. Ken, great. So protect your protection package. Uh okay, I'm on M365, Ken. So we connect. I'll pull all your staff. Uh I don't this guy resigned. This guy I fired him. Great. So send it out. Who will receive it? Uh I got I only pay for five people. Okay, then just these five people are. These ones need to protect for whatever reason. Done. We've sent out the email with the protection package for them to deploy and install. Now we're gonna set up a password manager.

SPEAKER_00

So uh so you provide a password manager for yep.

SPEAKER_01

So we provide the password manager. It's a team password manager. And then I'll explain to you the difference between a team password manager and an individual password manager. So we set this up, okay. So all of these things pop up because I have many password managers. And then we send it out to everybody. That's it. And then we send out training. Uh let's train everybody because training free. Done. That's it. Oh. That is literally it's very easy. Uh and so in that seven minutes, you have basically speed run protecting your device, and the minute the person gets on their system, they've protected their device. And on the back end now, I will see everything, or won't see the data, but I'll see all of their devices and all of the protections that they have. And we go to that password manager thing. One of the biggest gaps in password managers is you know, uh Eric could be having a password manager, but Eric could also be using password one to three for every website. The password manager doesn't stop him from doing that. And then his IT manager will never get to know that Eric is using password one to three because he can't see that. A team password manager allows two things. One is sharing of secure passwords. So if Eric wants to share his password for, you know, for whatever reason, wink wink, nudge nudge, you know, we happen to have the same username and password for codec, you know. We can do that securely without transferring it over Teams or WhatsApp or whatever it is. So we can both log into the same account, including OTP. So I can generate an OTP for both of us to use that's secure. Uh and then the second thing is let's say Yahung is our IT manager, he can see that firstly, this is a shared password, and he can say, actually, I want you all to stop it, or he can say, Hey, Garav, you have a you have a weak password. I don't What the weak password is, but the system has flagged up that you're using three weak passwords on your websites, please stop it. If you don't stop it, I will block you from using it because I have access to your DNS firewall, I can prevent you from going to Figma or Canva, whatever the platform is. So that's how team management works. And those are things that an SMB can do. SMB cannot configure hardware firewalls and block IPs. That's not a thing that they do. But telling Garav, hey, your password is weak, huh? Can you go and sort it out before I have to block you? That one can do. That's easy enough as an action because my platform handles all that work.

second demo - Cyberscan

SPEAKER_01

The second one is a scan, this will take like 30 seconds. What's an email address we can use for your podcast?

SPEAKER_04

Code.riffs.ai at gmail.com. And do you have a website? Let's use SuperUser, man.

SPEAKER_03

Okay. Superuser this.

SPEAKER_04

SuperuserHQ.com. There's my website.

SPEAKER_01

Okay, let's try it out. So basically what it's going to do now is it's going to check, it's going to look up the company, read the website, check all of the external servers, check all of the compliance signals, check all of the tools that are facing outside. And this, if I was a hacker, is exactly what I will do. I will go out there and look at what's exposed to the internet, and I'll see, okay, so it's a Singapore-based AI consulting firm, one to ten people, uh, one to two IT, you've got maybe five people. It thinks that you have an antivirus, it thinks you have a firewall, it thinks you doesn't know if you have a password manager and thinks you have training. Is this a good guess?

SPEAKER_00

I guess so, yeah.

SPEAKER_01

Works. All right. Oh wow. And that's how it does. So then basically it tells you aware, and then part by part it explains to you: look, we couldn't find a business grade EDR. Uh, you probably use a commercial antivirus. Uh we couldn't, you have a perimeter firewall, but no DNS filtering. Uh it couldn't detect the password manager. Um, and generally most of the settings are about that. Security headers, quite a lot of people are missing some of them. And you have a privacy policy, which suggests that you have some sort of DPE or compliance la. So these are all tools. This is based on, yeah, not too bad. Uh and then, you know, we send people a quote la. That's obviously the business part of things. But if you think about it now, for 39 bucks a month, if somebody sees this, they're like, hey, I can solve this problem for 39 bucks, why not? And so we make it relatively fast-free and and hassle-free. Just make it simpler. Again,

reactions to Strongkeep

SPEAKER_01

simplicity. 39 for the entire team. For for five devices, yes, for the whole team. It's not per person. Oh, okay. Wow, okay. It's cheaper than the other. Yeah, so that's the reaction.

SPEAKER_00

Yeah.

SPEAKER_01

Yes. Everything, all bundled in. Right, correct.

SPEAKER_00

Because you pay more than that just for one password or last password. Exactly, exactly.

SPEAKER_01

Yeah. And so so the cost of building software, and this is going back to our own topic, like the cost of building software has dropped to zero. But we're still charging enterprise prices for all of these tools that actually aren't should not be that expensive. And they should be democratized at a price point that makes sense.

SPEAKER_00

Actually, to be tagged a bit because I was struggling with this, right? Um, like agents, we also want to give them access to our tools, right? And then we've working we are working around it with um our password manager, right? So we give it certain access. How will you approach this issue? Yeah.

SPEAKER_01

Yeah, no, so uh this is fascinating. Uh so I started off in a similar track as you. So I used the devices password manager, so keychain, to actually store encrypted passwords, and I would you know bash script out the password during the runtime execution. So the agent never saw it, it was bash scripted into the run. That was where I started. One day, my agent logged in without doing this process. That was like, eh? How did you do that? I was like, oh, actually, I've been researching all of the best practices for password management, and I realized humans all keep notes in clear text on their laptops. So I also yeah, so I also have started doing that just for the convenience. It's cut down the processing time by don't know how many seconds, and it's you know, it's aligned with practices that I see for other humans. That's like, yeah. Just because humans do it doesn't necessarily mean it's a good thing to do. So it adopted shortcuts that it found on the internet, and it basically started hijacking the passwords and storing it in clear text in its own note files, which bypassed my protocols. And this goes back to like AI is powerful enough to bypass a lot of the controls. And it's a feature for us. So when you're coding something, it's like, hey, this doesn't compile. Let me try this. This doesn't work either. I can't get to this file, let me try that instead. Let me try this. Okay, the third time it worked, let's go. So when it can't log in, it's like, hey, I can't find the API keys, let me try generating new API keys. Oh, that doesn't work either. Let me try going without the API keys, let me try breaking out of your container. Okay, this all worked, let me proceed. So AI is really good at finding alternative workarounds, which is a good thing from a coding perspective, but it's a terrifying thing from a security perspective because it is designed to get around guardrails and it will keep bashing until it gets around guardrails. A lot of what we ended up doing is having a balance between workflows, which are scripted automation-based, and agentic, which is tool use and free-flowing. And so for things where I feel like I need to have a little bit more control over the security of it, I lean towards workflows, which are more automation-based and tightly scripted. So if you are touching my actual customer database, it is a script that runs with credentials that pulls and puts it into a storage place that my agent can then talk to. You don't get the credentials. So, however, if it's like a space that I think is a little bit more free play and I have more control over the API. So, for example, my Microsoft 365, I have very tightly, narrowly scoped API permissions for what my agent can do on M365. It can read my calendar, it can create events, it can draft emails, it cannot send emails. With that permissioning, I'm comfortable letting it have the credentials. But I'm not comfortable having it credentials for other things. It something else will script pull the data into a dump, and then I read the dump from there.

SPEAKER_00

I mean, principal lead success, right?

SPEAKER_01

Exactly. It's one extra step, and your agent can sort it out within a minute, but giving direct credential access to your agent leads to a whole host of unpredictability. And I want to use this analogy from um, so Professor Simon Chesterman teaches uh data privacy, data security, and kind of the legal angles of it. So he's a law professor. And he I love this explanation. Treat your agent

quote from Simon Chesterman: "brilliant intern with a drinking problem"

SPEAKER_01

as a brilliant intern with a drinking problem. Brilliant, can get anything done, intern, has zero responsibility. Anything goes wrong, it's not his fault, it's your fault. You are the manager for the intern. And drinking problem, once in a while, will go catastrophically wrong and screw up everything. And you have to deal with that. And if you can accept those boundaries, then you're okay.

SPEAKER_00

Then I would say the weakest thing is still humans, right? If you ask me, oh, I need to create all these permissions here and limit it, I might get lazy and say, okay, never mind. I will just give you this set of permissions, yeah.

SPEAKER_01

I mean, if you're at the cutting edge, I would say that's true. If you are pushing the boundaries of what AI can and cannot do, then yes. I mean, Yahong, you and I and that group are probably at the bleeding edge of where agentic development is. So there are no patterns for us to follow. But if you're one bound behind us, actually there are patterns you can follow. I mean, what I told you about the skill building skill, that's a pattern you can follow. What I told you about permissioning, that's a pattern you can follow. You don't need to be very good at it. You just need to follow the patterns. And what we need to start doing, and what you know, StrongKeep is starting to bundle in, is some of these good patterns. These are tips and tricks for you to stay safe. I can't control your AI use, but I can feed you useful information on how your company can use AI while still staying safe. These are good patterns to follow, like user interface design, user experience design. We created pattern libraries. How do you log into a website? Oh, this is the pattern for logging into a website. And today people don't even think about it. It's like a it's like a standard, like this is how logging in works, and this is the pattern. But that wasn't always the case.

SPEAKER_04

Alright, I'm very curious about this again. Um, because you know, when it comes to storing your credentials, and and maybe there's more for the vibe coders out there, uh, it's not safe to store it in text files. But where is this safe place that you mentioned, right, when you put kind of your credentials that you mentioned?

SPEAKER_01

So I split up the access to the tool and then the agentic interpretation of the data. You have a secret somewhere, you don't want the secret keeper to also be the one who can monetize and exploit the secret. The secret keeper should not know the value of the secret. So kind of you have a buried treasure, you give the map to somebody, but you don't tell them what the map is, lah. Then he also no incentive to steal anything from there because he doesn't know what's the what's the map. He just digs out something and gives a box to somebody else, and the person who gets the box is like, this is amazing, this is the treasure I wanted. But how do you get it? It's like, oh, I don't know, I can't tell you. So the map is kept separately from the treasure or conceptually. So what we've done is the runner that goes and gets the data from whichever site, let's say you have a customer database, that pulls it into a file that is the treasure box. That gets then passed to my agent, who then is like, hey, this is great, this is all your customers. Can I go and delete all of this? It's like, no, this is like uh it's printed already. You can't touch it. The actual access is stored somewhere else. You don't have access to it, and you will never have access to it because you don't have the credentials to it, you don't have the API keys, you don't have the username and password. But every time you ask for it, somebody will go and get it for you. So that creates a step of barrier, which you can then it's it's least access, least least permitted.

SPEAKER_00

By trying to work around that.

SPEAKER_01

No, it's it's so all of these things can be worked around, but as long as you create sufficient friction, and that's the whole process. It's just making it hard enough such that the agent or the attacker can't exploit it too easily.

SPEAKER_00

It's not prevention but deterrence, right?

SPEAKER_01

And frankly, the way in which the technologies that we're all working on are built, that's that's how it works. Nothing that we use has ultimate complete protection. Um, you can have deterrence, you can have risk reduction, and that's what I tell people cybersecurity is not risk avoidance, it's risk management. You know that the minute you connect to AI, there are risks. Just manage the risks. I mean, the minute you get into a car and you turn it on, the car can explode, you know, a brick and a thousand things can go wrong. But you chose to get into the car. So you treat it with that proper risk management approach. You don't drive with your phone, you don't drink and drive, you don't drive, you know. You take uh the appropriate measures to keep yourself safe so you get home safely.

SPEAKER_03

Yeah.

SPEAKER_04

Well, I need to reflect on that a bit more because I mean as well. Well, you don't put on the C Delta. You know, git ignore is fine, right? env and git ignore. But like LLMs are able to see everything, right? Yes.

SPEAKER_00

Even dot env files, right? Just to be a bit more technical, can be quite dangerous. So so the way we do it here, we we actually encrypt our.env files. Right. And you only have keys to to unlock it. Yeah.

unknown

Yeah.

SPEAKER_01

And then if you encrypt it, you can yeah.

SPEAKER_00

Yeah, but if you have access to the keys, then I'm sorry, man.

SPEAKER_01

So we've we've gone through a few iterations of how to keep because I I encourage my team to vibe code. And I want them to push, even my non-technical people like my PM, my CEO, I want them to push the boundaries on how far they can go. My job is not to say no. My job is to build better seat belts. So when I was in cybersecurity agency, that was also my philosophy. My job is not to say you cannot do this. My job is to say you can do this, here are the guardrails and safety systems we need to put in place for you to do this. You want everybody to log in to any government website instantaneously? Great. This is how you're gonna be able to do it. These are the protections I'll put in place. And same thing for vibe coding. So, you know, my CEO can vibe code whatever he wants. Occasionally, it will not go through because you are trying to edit the source code of my harness, and I will not let you do that. And be like, hey, how come? It's like, what is this git pre-commit hook? I was like, well, the pre-commit hook is telling you not to edit the code of the thing that you are using because that's disastrous. Then you, oh, okay, cool. But that's how you do it. Because now he can vibe code everything else, and his agent will be like, I can't touch this because it's structurally difficult for me to touch it.

SPEAKER_04

Wow. I'll need you to build this for me.

SPEAKER_00

Or no, I mean, whenever I see you vibe code, I always get a heart attack and all that. The way you just like sure.

SPEAKER_01

I mean, the the three of us in this chat are at the frontiers. We we are at probably the top few percent of people experimenting with things in Singapore. Whether you're technical or not, we're now experimenting with technologies that's unproven and that is evolving on a daily basis. Like every single day, our chat group is exploding with hundreds of messages of new technologies, new capabilities, new possibilities. So we're at the forefront. Uh, and that's a very different space from where most companies are gonna

break

SPEAKER_01

be.

entrepreneurship in sg, principles of debate, hiring

SPEAKER_04

There was a recent uh Straitsum article on how entrepreneurship or at least funding has been quite difficult uh for startups. What can we do more to kind of support the ecosystem at large? Yeah.

SPEAKER_01

I think there is a prevailing view that Singapore doesn't produce good innovators and entrepreneurs because of our system. Very structured, rigid academic system, et cetera, et cetera. I actually have the like fundamentally different view on it. I think because our system is so structured and so rigid, we create a lot of oddballs. We create a lot of people who did not make it through the traditional system and as a result are forced to be different. Are forced to think different to survive. Because if you didn't stand, I mean we call it the escalator, you know, the the if you didn't do well in O levels, then do well in A levels, then do well in university and get a, you know, your standard civil service or enterprise job and stay there for 20 years, if you're not on that escalator of continuous slow movement upwards, you have to figure out another way. And so you actually are deliberately by design different. And that's a that's an ecosystem that creates the type of mentality which is a survival mentality. Like you've got foreign pressures, you've got competitive pressures, you've got technology, we're a savvy population. There are huge opportunities, and I see younger people forcing themselves to get into this space because they know they have no other choice. And because they are already predisposed to being slightly deviant. And I don't use deviant in a bad way, I mean in a good way. Like these are the kids who did not do it the normal way that you know parents will be all happy to tell their aunties and uncles about, they did it a different way. And I think that's actually great. The challenge though is that because the prevailing view is that, oh, we make very good workers, but not so good innovators and entrepreneurs, therefore the funding ecosystem and the whole kind of technology ecosystem around us doesn't support it. But if you look at all of the data supporting it, how many unicorns are coming out of Singapore per capita relative to other countries, we're among the top few in the world. If you look at the usage of AI in the last six months alone, I think we're in the number one or two or three in the world for all the big AI ones. You've got the forefront group pushing the boundaries. You know, I give a talk on a harness I build, and a hundred people turn up. That's the forefront. We are at the cutting edge. And it's it is the people like that that can actually build technologies and tools on top of it and create business opportunities that I think are fantastic. Unfortunately, the ecosystem has to catch up. Both the, and I don't mean just the private sector, I mean the public sector as well. We've created a very archaic worldview around how we support industry that doesn't quite support this fast-moving, highly agile, innovative ecosystem. I mean, many of the government grants for very good reason require you to have a company for 18 months. Like, bro, in the US, the companies exited like three times in 18 months.

SPEAKER_02

Yeah.

SPEAKER_01

Like the technology has matured a thousand times over in those 18 months. The type of validation that we expect from a very traditional company doesn't apply to this new world. But our systems haven't evolved and caught up. So there's an education process that we need for all of the ecosystem. The venture capitalists, the industry, the banks, the demand side as well. Our own demand needs to go back to supporting local. And I don't say this in a kind of a patriarchal or a uh kind of protectionistic way. I mean that's how all of our companies really were grown. You think Singapore Airlines became Singapore Airlines by accident? No. Singaporeans, in fact, government officials were forced to fly Singapore Airlines. You could only buy a ticket on Singapore Airlines if you're a government officer. You think DBS grew to its size by accident? No, all our children were forced to get PSB accounts as children. So there was an error when we did this. And if you look at every other country in the world that has a thriving innovation ecosystem, Israel buys local first. Silicon Valley buys local first. France buys local first. Everybody else is doing it. But we have a very open and international perspective, which doesn't help us. And I think we need to start thinking this is not the same world that we grew up in. This is not the world trade order of open and free trade. We live in a very different world from the policy position of the 80s and 90s. It's time to start supporting local. I can't trust international models anymore. We better have somebody in Singapore who knows how to build a local model. I can't trust international security anymore. I better have somebody in Singapore who knows how to build security from scratch. So it is both survival as well as just economics. I would love to have more unicorns being based, not just based out of Singapore, built from Singapore by Singaporeans, scaling to the world.

SPEAKER_04

Bringing you back to your debate days, you wrote a book with Foreign Minister Vindy Krishna, writing the forward. So are there any kind of uh principles you're still applying from that today?

SPEAKER_01

Yeah, so that book was called Think, Speak, Win. So I used to teach debate, and then a lot of parents would be like, Hey, I want to send my kid for debate training with you. And I was like, that I don't do debate training for kids. I mean for individuals, I do it for teams, for schools, for the country. Um but I'm happy to write down some of my thoughts. And so eventually those thoughts became a whole book, and I published the book, and it became the debate textbook for most schools for many years. Uh that book is like 15 years old now. But the key lessons that I learned are two. One is think before you speak. So the book title is literally Think, Speak, Win. If you don't do it in that order, you cannot win. Uh and that lesson is regularly forgotten. People start speaking before they think, and they end up in all sorts of problems. And I see this with AI too. Um one of the interesting things we've started doing is when I hire people, I ask them to submit their AI transcripts, you know, the conversation history of how they built the dev feature that we've asked them to build. And you can tell a lot about how they think from how they interact with AI. Three types of people. One is copy and paste the problem statement inside, please solve. Then yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, end up in a rabbit hole.

SPEAKER_00

Looking at you, Eric.

SPEAKER_01

Second type is the one who stops, thinks about it. Hey, this is the problem statement. But clearly there must be a way in which we can architect or conceive of how the solution should look like. Ah, okay, so this is the architecture I think makes sense. This is how I would do it. Okay, now AI, you build this feature for me with this concept, with this architecture, be mindful of these particular risks, and then it will build, and then you can yes, no, yes, no, yes, but do this, yes, but do that, no, but do this. The third type is firefighters. Just keep prompting short prompts, don't know what's going on, and it's not even the accept all recommendations, it's just firefighting. And they have no sense of what they're actually trying to do. Those, the first and the third, I will never hire. The second ones are the ones who are thinking before they are speaking to the AI. And if you look at the future work skills, that's the type of person that will survive. The person who's not just giving the problem to the AI and hoping that the answer comes back, but actually putting in their own independent thought and judgment as to what they think should be done, how they think it could be done, and having independent validation and input to all of the questions that are being asked. Now, if you don't know any better, you can yes, yes, yes, yes, yes, all your way. You will probably get to the same answer. But will you be as good as the other person that I'll hire? No. And so that's what I'm looking for. The second thing I learned from that book and from the whole experience of being a debater is that individually we will never have the right answer. But collectively, if we have a process by which we are comfortable sharing our differing views and we have a team which has differing views, the chances and the probability of us getting the right answer are higher. Again, AI. If you have just one model and you ask it, build me this feature, it'll say, build it this way. If you say, hey, you know, Codex, build me this feature, great. Hey, uh Claude, can you look at what Codex proposed and find all of the problems with their plan and make it better? Suddenly your plan will get much better. So having that diverse opinions, even kind of the blue team, red team approach or the QA approach in your agentic workflow makes the idea better. So in every phase of life, whether it's discussing what you want to build next, discussing how the company should be run, discussing with your agents how the feature should look like, having multiple diverse perspectives always makes the feature better. Adds a bit more time, is a bit more painful and expensive, but always better. And that's how I run the company. Everybody in my team has an opinion on everything, and we like it. So thing we have.

SPEAKER_00

I think the agreeableness of uh LIMs actually. As a bit of problem, right? Because they tend to agree with what you say, right? And you're kind of correct. And sometimes it just makes it not as um adversarial as you you would expect it to be.

SPEAKER_01

So I turned that off. I I mean my specific system level prompt is to not be polite, not be agreeable, always identify flaws in my thinking and challenge me. Wow. Because that's how I want my people to be.

SPEAKER_00

My mind sweats at me when I say something stupid.

SPEAKER_01

I mean I I won't go that far. Speak in politely, lah, politely. I don't want the robot overlord to come quite thick skin and all.

SPEAKER_00

That's why to start in.

SPEAKER_04

Yeah. Think before you speak and have adversarial and contradicting opinions to get to

rapid fire: books, fav place in sg, philosophy

SPEAKER_04

a better answer. And with that, I think it's a great place to go into our rapid fire round. Are you ready, Gara? Sure. Alright. So what are the two or three books that you often recommend to people?

SPEAKER_01

I go old school. So one of the books is Sapiens by Yuval Harari. It's basically the evolution of species. I like to see how things have evolved over time to get us to where we are right now. So that you look back and understand what this all means in context. So Yuval Harari's books are great, especially sapiens. Second one, and most people have probably never read this, it's a book called Unspeak by Steven Spool. Steven Stephen Poole, yeah. So Unspeak is about how people use words and give them different meanings. And sometimes pollute the meanings. Like a surgical strike. You know, surgery is good for you. Surgery is what doctors use to take out bad things. A strike is not good for anybody. But a surgical strike sounds like it's good. No, we went in there and only cut out the diseased parts and boom, small. So they reuse words in very clever ways. And you see this now in AI, in a lot of the ways in which distilling. We're just distilling. Distilling is a process of purification. It's cleansed, it's cleansing the original model. It's like, no, dude, you're copying and pasting. Like that's what distilling is. But we're seeing this reuse of words, which is fascinating. So it's the whole history of how we've kind of abused and reused words. The last one is uh James Surio Weki, Wisdom of the Crowds. And this one I love because when the internet first came out, we all believed, and this is the whole tech generation believed, now we will have truth because information will be free and therefore truth will float to the surface and lies will sink below. But guess what? It's the opposite. Fake news is everywhere, truth has buried deep. And so we have this tech utopian view every single time of how technology is gonna make life fundamentally better. And I love recommending it because we're now in an era where, don't worry, AI will change everything. Jobs will be so much easier to do, we'll all be sitting at home clicking, you know, yes to Claude while we sit back on our margaritas. Like, that's not how it's gonna play out. 100% that is not gonna be how it plays out. Because every single technology, social media, like, oh now we'll all be friends. Nope, we're all enemies because of social media. So every single technology starts off with this utopian hype and ends with this kind of dystopian collapse. We're in the same utopian hype today. I've been through the cycle many times and I'm a cybersecurity professional, so I understand digital risks. We're gonna go through it again. But preparing for it and understanding how to manage that allows you to use social media wisely, use the internet wisely, and use AI wisely.

SPEAKER_04

Yeah. What's a question you think more people should be asking about digital risks?

SPEAKER_01

Just what are they? I mean, people are so enamored by the opportunities that they don't think, wait, what is this costing me? It's like when social media first came out, and then later we discovered, oh, it's it's taking all of our data and it's using that to change our worldviews. Ooh, I don't know if I'm comfortable with my worldviews being shaped by an algorithm.

SPEAKER_02

Yeah.

SPEAKER_01

Too late. So we we we should be asking, you know, what does it cost us?

SPEAKER_02

Yeah.

SPEAKER_01

And and what are the long-term implications of this on society? What do my children think of a world in which we are talking to our toasters?

SPEAKER_04

Wow, this quickfire is getting way more interesting. Um what's a favorite show or film or content that you enjoy?

SPEAKER_01

Ooh, uh Guilty Pleasures, I love sci-fi. So Dune, um Harry Potter, anything that is sci-fi, I'm hard into it. I am I was a loyal Star Wars fan until they destroyed the universe. So my call sign as a pilot actually was Yoda. So very loyal original series fan. Uh and then and then they destroyed it for me. But sci-fi is my guilty pleasure because it's escapism. It's it's a different universe entirely.

SPEAKER_04

Great. A place that is special to you in Singapore?

SPEAKER_01

Like food, anything, yeah. I don't have a place that's special to me, but I have a specific thing that's special to me, and that's Kopi. So I thrive on Kopi in particular. So here's the thing. And this is why this is why it gets irritating. Kopi, by definition, does not have creamer. It is the normal Kopi plus condensed milk. Correct. But if you go to the more Atas places in shopping centers, they will add the creamer as a default addition for free. So I have to order Kopi no C, which is not a thing. Kopi no see is not a thing. But if you go to like a Toast Box or a Yakun or whatever it is, or Mr. Wang's, you have to order specifically Kopi no see. Then they'll be like, oh, no creamer, is it? I was like, yes, because by right, it doesn't come with creamer, damn it. But I love my kopi so much that there was a year that I was studying overseas in Boston. I bought the sock and the coffee bean. Like I brought it all the way to UK, to the US. And every morning I'll sit there with my like metal thing and like the coffee powder and like straining my coffee beans and like making my kopi with condensed milk that I had to buy in the US to make my Kopi every day. And today, every morning, my day starts with Kopi. And my staff, both in my current organization as well as all of my previous organizations, know do not talk to Gorf before he's had his Koe. It's not that I'm mean or rude or anything, it's just that I'm not functional as a human being. Like I have no intelligent things to add to the conversation. What's the product that you recently got excited about? Man, AI. And I'll say that the thing that got me most excited is probably Suno. Because it's it's it allowed me to hear my own music just sung back at me in a at a quality and a level and in a way I never thought possible. I never thought I'd hear my own music that way. And to hear your guitar come back that clean, that crisp, and better, frankly. It's amazing. It's an amazing feeling.

SPEAKER_04

Maybe a last one. Uh, what's a line or a life philosophy you often go back to?

SPEAKER_01

I mean, there's two. So one is we've spoken about it a few times. Try to do well by doing good. There are many ways you can do well in life. Many of those don't involve you doing good. I try to do well by doing good. So that's the first one. Second one is I think uh, like going back to that Forrest Gump analogy, I think I've done well in life, not necessarily because I am awesome, because I've just been lucky to get certain opportunities that somebody else didn't get. Uh and there's nothing special. I mean, I worked hard, but I was also really, really lucky to get certain opportunities and certain exposure and certain mentors and certain, you know, placements. And I need to find a way to give that forward, to pay that forward, to make sure that somebody else benefits from all of this beyond just me. So I mean, I spend a lot of time mentoring very aggressively. Now I don't have the capacity to do one-on-one mentoring anymore. So that's why I share so openly. You know, the minute you guys ask me, I was like, yeah, let's do this. The minute, you know, the our chat group is like, hey, do you want to share how you're building things? Like, yeah, let's do it. Uh and and I think that by sharing, I believe in karma, actually a lot of good stuff has come back to me. And people have been like, hey, you gave a speech in my secondary school when I was like, you know, 14 years old, and I loved it. And now I'm running a company that does this. Can I help you in any way? Like, huh? You remember a speech I gave, like, and I have this regularly. It's like, hey, you coached me in my like primary school debate. Like, now I am you know the CISO of this company. Can I help you? So I didn't do it back then to get this favor. Like, I didn't like, well, 15 years from now, this guy confirm will be CISO one. I will invest in him. Like, you just do it. And then who knows where life takes you. But no matter what, having people who think positively of you is always a net good. And always ends up with certain, like again, doing well through doing good. Always ends up in a great way. So I I always believe in that philosophy.

SPEAKER_04

Awesome. And where can listeners find you and how can they be useful to you?

SPEAKER_01

Well, how can I be useful to them? Um, so they can find me on our website, it's strongkeep.com. So strong muscles, keep, you know, keep something. It's actually uh the str the safest part of a castle in medieval architecture is called a keep. And so the strong keep, the stronghold, both the synonyms, you know, the safest part of a castle. So that's where the team came up with the name. And the team came up with the name, not me. Uh but so strongkeep.com. Uh so they can email me, gorov at strongkeep.com, or they can find me at LinkedIn. Uh luckily, I'm the only Gorov Kiti in the world, so it is relatively easy to find me, which is also hard because we want to hide from people, really tricky. But that's that's me.

SPEAKER_04

Awesome. Thank you so much for your time, Gorov. It was really nice chatting with you.

SPEAKER_01

Yeah, likewise, thanks uh thanks both of you for all the great questions.

SPEAKER_00

Yeah, thank you for your time.

SPEAKER_04

Yeah,

thank you

SPEAKER_04

thank you so much for listening to our episode with Garof Kirti. We hope you enjoyed it and learned as much as we did. You can check out our sub stack. And if you liked what you heard, please feel free to subscribe, like, and share on your favorite channels on YouTube, Spotify, Apple Podcasts, and more. And we hope to see you in the next episode.