**Dean de Beer** (0:00)
There are certain things you just have to do when building a product, right? You need to be able to present data in the UI and have the user experience be something that isn't frustrating to the user. No one likes to wait. It's the classic sort of elevator waiting time problem. It might take 20 minutes to get up 100 flights of stairs, but waiting 45 seconds for the elevator to get there, most people get frustrated. The principle is exactly the same with what we're doing. And with language models, latency is a real problem for them, right? I don't believe that, at least in the current state, we should think about wielding language models as a hammer.
**Derrick Harris** (0:34)
Welcome once again to the a16z AI podcast. I am the frequent co-host and always reader of these episode introductions, Derek Harris. If you're a new listener, the very quick summary of the show is that it primarily features the leading builders, researchers and founders in the AI world, discussing how and why they're doing what they're doing. This episode is no different, as I'm joined by Command Zero co-founder and CTO, Dean de Beer, as well as a16z partner, Joel De La Garza, to talk about the nexus of AI and cybersecurity.
We cover a lot of ground, from the origins of incident response and early headline grabbing breaches, to how Dean's team is utilizing generative AI and LLMs to help shoulder the burden for today's overworked response teams. He also shares some founder level insights into the economics and trade-offs when it comes to building a product on top of LLMs. Now, this is actually our fourth episode on security in as many months of doing this podcast, and that's because generative AI represents a golden opportunity to give the good guys a meaningful leg up against determined attackers, whether that's aiding an incident response, identifying vulnerable or malicious code, or something else altogether. And it kicks off after these disclosures with Joel explaining his background in the cybersecurity space. Peace.
As a reminder, please note that the content here is for informational purposes only, should not be taken as legal, business, tax, or investment advice, or be used to evaluate any investment or security, and is not directed at any investors or potential investors in any a16z fund. For more details, please see a16z.com/disclosures.
**Joel de la Garza** (2:15)
I started my career in incident response and computer forensics, and so that is typically considered to be the smoke jumper of the security industry. So whenever something breaks or goes horribly wrong, tends to be what you do when you deal with incident response.
Worked at a bunch of startups, founded a couple of startups, but eventually got to deal with the really heavy stuff while working for financial service companies, so Citigroup and Deutsche Bank, obviously. People like stealing money, and people spend a lot of time and effort in trying to steal money.
And it's actually interesting, a lot of the security industry, the information security industry largely started and grew up around financial services, as well as the intelligence community. But obviously, those folks don't typically share with the broader world. So a lot of the stuff you see in public comes out of financial services. So I've seen some of the most sophisticated hacks you've probably ever seen, where people have used human assets, so employees to infiltrate third-party suppliers, to implant backdoors into software to eventually steal money. Everything from that to nation states that are in control of the infrastructure and planting listening devices in the data centers that they're pouring the concrete in. All sorts of fun stuff.
**Dean de Beer** (3:20)
Going all the way back to, I guess, early 2000s, I was doing IR and pain testing for a living. Then Dove, Yoran, one of my co-founders and I, we started Threat Grid, where we focused on malware analysis and threat intelligence for going on 10 years. We were acquired into Cisco, and a little under six years there.
And then after that, Dove, myself, and Elle, we started Command Zero. In terms of some of the things we've seen, similar to Joel, done incident response across all form of organizations and verticals, financials, healthcare. I would say that early in my career, the one thing that truly impacted me in terms of what is possible and what the consequences of us not doing our jobs well could be was in hospital systems, seeing medical devices compromised, seeing devices that are connected to patients, that are exploitable, and realizing just the impact that can be had through malicious actors at that point, like real lives are at risk, and not be more so today than ever before.
36 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000663439143