AI Threats & Opportunities in Cyber Security With Material Security Co-Founder Ryan Noon artwork

AI Threats & Opportunities in Cyber Security With Material Security Co-Founder Ryan Noon

No Priors: Artificial Intelligence | Technology | Startups

October 26, 2023

Cyber Security is going to change significantly in the era of AI, according to Ryan Noon, cofounder of Material Security, a security company that makes cloud-based Google and Microsoft email a safe place for sensitive data.
Speakers: Elad Gil, Ryan Noon
**Elad Gil** (0:05)
So this week, I'm joined by Ryan Noon. He's the co-founder and chairman of Material Security, the cybersecurity company making cloud-based email a safe place for sensitive data.
He previously started Parastructure, which was acquired by Dropbox, where he was an engineering manager prior to starting Material Security. Ryan, welcome to No Priors.

**Ryan Noon** (0:22)
Hey, it's great to be here, man. Always lovely to talk to you.

**Elad Gil** (0:25)
Yeah, it's always fun to chat with you. So one of the reasons I'm excited to be chatting with you today is, I feel like you have such a great perspective on both the broader security industry, various tech topics, etc. But also specifically how this all starts to tie into AI.
And I know that in Material, you were a very fast adopter actually of AI related technologies as the first sort of APIs really came out. And you start playing around with them quite early and doing interesting things with them. Do you want to first talk a little bit about how you started Material? And then maybe we can touch on how you started getting involved with the AI side of it.

**Ryan Noon** (0:55)
Yeah, sure. So we started Material, I guess, 2016, 2017 or so. I had left Dropbox and was living in Europe and fell in love with all the election hacking that happened here.
That year it was pretty nasty. Like every random Gmail account kept getting dumped on the internet. So I had an idea for how to protect a Gmail account, just an ordinary personal one in a fairly novel way.
I coded it. It shockingly worked, the Gmail API let you do it. I brought it back home and showed it to some friends.
We realized this is actually a special case of a broader way of thinking. Now, seven years later, it's a, you know, whatever cybersecurity unicorn thing and we get to work with the coolest companies in the world by far. The stuff that you get to do at the scale is just mind-blowing. It's wild to think just where it started and where it's come.

**Elad Gil** (1:50)
What are the main products that Material focuses on just for the audience so they have a better sense?

**Ryan Noon** (1:55)
Yeah, so the broad thesis is basically we've all kind of got these Google and Microsoft accounts. Email is sort of where we started, but since then we've kind of just went deeper and deeper and deeper into sort of everything that you can use a Gmail account or a Microsoft account for. The bread and butter of the business is selling to companies mid-size and up with these kind of these big Google workspace and Office 365 deployments.
The product has a bunch of different modules that are all kind of based around the main things people worry about. The kind of the first big product that you mentioned in the intro was people have years and years of sensitive information sitting in these accounts. If somebody gets into your Google account, they're just going to download all of your email and go through it later, and your whole life is in there. It's even worse in a corporate environment. So that product, what it can do actually is finds sensitive stuff that's just sitting around, kind of just sitting in your inbox, your archive, whatever, and then it can basically redact it and then replace it with a clean copy so that if somebody gets in and downloads the whole thing, they don't get anything good. But then if you happen to need it, like I like having all this information in my fingertips, you can just press a button and do an extra face ID or a touch ID or more advanced policies and work, but just something that's easy for you, but hard for the attacker. So we started there and then we expanded into fancy phishing. People can send you tricky emails and get you to do things and steal money from you.
We expanded into account takeover protection, which is more of the things that people do after they compromise the account. And I try to reset all your other accounts and steal your bank account and all of that. The operative concept is defense in depth, which is just assume that the bad guy got in like what do they want?
They got over the wall, there should be another wall and a machine gun. It's like history has all these fairly basic lessons about resiliency that never really always get applied the right way when it comes to computers.

**Elad Gil** (3:58)
Yeah, so it's kind of like, I guess, part of the impetus was the 2016 election where there is all the things around the Podesta emails and Hillary Clinton and everything else and the basic idea is somebody is able to hack your account but it doesn't matter because your email is not accessible to them or the sensitive information that you designate.

32 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000632682183