**Zane Lackey** (0:00)
Some of the best security people I ever met early in my career didn't even have a background, didn't have like an education in security, like a college education in security or anything like that. What really made them great in their field was a deep passion for it. And so that's often what I look for in founders is, you know, passion and understanding. Like they really grok the space, they really have dove into it and are very excited about it.
**Joel de la Garza** (0:25)
And an easy screen for this is, did you stay up till three in the morning playing with ChatGPT when you got access?
The answer should be yes. Like it's just gotta be excited about this stuff.
**Derrick Harris** (0:38)
Hi, you're listening to the a16z AI podcast, and I'm Derek.
Cybersecurity was a big topic this week with the RSA conference taking place in San Francisco. So this episode is all about, you guessed it, security.
We actually covered it last week too with Fros from Socket and our a16z partner, Joel de la Garza. And Joel makes a triumphant return this week along with a16z general partner, Zane Lackey. Although technically, this episode was recorded earlier than last week's episode. We cover a range of topics, from the difficulties of training security industry-wide foundation models, to how CISO's experiences with AI washing in the mid 2010s might affect their buying decisions today. And if you're unfamiliar with their bona fides, here are some brief bios. Zane was previously the co-founder and chief security officer of Signal Sciences, which vastly acquired in 2020 And before that, he was the CISO at Etsy, among other things. Joel was previously chief security officer at Box. Before that, among other roles, he was global head of threat management and cyber intelligence for Citigroup and ran incident response for Deutsche Bank. And he kicks off this discussion, explaining why 2024 could be a big year for applications of generative AI in the security space.
As a reminder, please note that the content here is for informational purposes only, should not be taken as legal, business, tax, or investment advice, or be used to evaluate any investment or security, and is not directed at any investors or potential investors in any a16z fund. For more details, please see a16z.com/disclosures.
**Joel de la Garza** (2:20)
I think it's still very early in our journey with this stuff, and security has always been a laggard. So if you look at where security tech has been developed, it's always in response to something bad that's happened. And for that something bad to happen, you've actually got to have real meaty kind of use cases that the tech is addressing. And so, with the internet in the early days, there were a lot of people doing hacks and stuff, but it wasn't really until you had credit cards and e-commerce and the internet become more than just a message board, that you started to see security become pretty important.
And so, we're still kind of in that transitory period where we don't know, but we have a suspicion of what we think is going to happen.
And to some extent, we're just waiting for those kind of meaty use cases. I think we believe that this is probably the year you start to see them happen. Like, this is happening at a rate that's faster than anything we've ever seen before. And instead of taking two years, it's probably going to take two months, and we're probably entering that window now where we'll see some fun stuff.
**Zane Lackey** (3:21)
To that point, it kind of feels like the first five years of cloud smashed into a matter of months.
So yeah, we're definitely seeing things change at a really rapid clip. And exactly as Joel was saying, it really feels like this is the year where we see how the enterprise starts to really make use of AI, and then inherently you see how does security then adapt to that and provide both reactively and then ultimately proactively providing controls around it.
**Derrick Harris** (3:48)
So obviously companies have been selling, and I'm air quoting AI-powered security products, for at least several years now, some of which seemed a lot like AI washing. Are things really different this time, and is the big difference mostly the emergence of LLMs and foundation models?
**Zane Lackey** (4:03)
I'd say so. I'd say, you know, look, anyone who walked around the RSA and Black Hat show floors 10 years ago saw plenty of AI up on booths and things like that on marketing slogans. I don't think anyone would disagree that this time is different, right? I think everyone has gotten a chance to play with ChatGPT with LLMs in some capacity at this point, and really just viscerally seen how different it is.
35 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000655180268