In this interview from theCUBE + NYSE Wired: Cyber Security Leaders, Shuman Ghosemajumder, chief executive officer and co-founder of Reken, joins theCUBE + NYSE Wired's Gemma Allen to discuss how generative AI has turned online trust into an identity crisis. Ghosemajumder traces cybercrime's evolution from organized click fraud and credential stuffing to today's AI-generated attacks that can carry on a real-time conversation and defraud victims convincingly. He explains why traditional email filtering forces an impossible tradeoff between blocking legitimate messages and letting sophisticated phishing through, and why phishing awareness training has repeatedly failed to change user behavior.
The conversation explores how Reken's on-device product, Northstar, was built to close that gap by analyzing hundreds of technical and contextual signals in real time without sending sensitive data to a third-party cloud. Ghosemajumder details the two-year R&D effort required to run this analysis on ordinary hardware without a GPU, and why he tested it on the cheapest laptop he could find at Best Buy. He also unpacks the "trust network" concept behind the product's UX, drawing comparisons to TLS padlocks and iMessage's blue bubbles to explain how positive security indicators can guide users without triggering alert fatigue. From protecting Fortune 500 design partners to reflecting on why cybercrime can never truly be solved, Ghosemajumder outlines why he built Reken to keep adapting as the threat landscape morphs into new forms.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For theCUBE + NYSE Wired: Zero Trust Cyber Series
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for theCUBE + NYSE Wired: Zero Trust Cyber Series.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to theCUBE + NYSE Wired: Zero Trust Cyber Series
Please sign in with LinkedIn to continue to theCUBE + NYSE Wired: Zero Trust Cyber Series. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Shuman Ghosemajumder, Reken
In this interview from theCUBE + NYSE Wired: Cyber Security Leaders, Shuman Ghosemajumder, chief executive officer and co-founder of Reken, joins theCUBE + NYSE Wired's Gemma Allen to discuss how generative AI has turned online trust into an identity crisis. Ghosemajumder traces cybercrime's evolution from organized click fraud and credential stuffing to today's AI-generated attacks that can carry on a real-time conversation and defraud victims convincingly. He explains why traditional email filtering forces an impossible tradeoff between blocking legitimate messages and letting sophisticated phishing through, and why phishing awareness training has repeatedly failed to change user behavior.
The conversation explores how Reken's on-device product, Northstar, was built to close that gap by analyzing hundreds of technical and contextual signals in real time without sending sensitive data to a third-party cloud. Ghosemajumder details the two-year R&D effort required to run this analysis on ordinary hardware without a GPU, and why he tested it on the cheapest laptop he could find at Best Buy. He also unpacks the "trust network" concept behind the product's UX, drawing comparisons to TLS padlocks and iMessage's blue bubbles to explain how positive security indicators can guide users without triggering alert fatigue. From protecting Fortune 500 design partners to reflecting on why cybercrime can never truly be solved, Ghosemajumder outlines why he built Reken to keep adapting as the threat landscape morphs into new forms.
In this interview from theCUBE + NYSE Wired: Cyber Security Leaders, Shuman Ghosemajumder, chief executive officer and co-founder of Reken, joins theCUBE + NYSE Wired's Gemma Allen to discuss how generative AI has turned online trust into an identity crisis. Ghosemajumder traces cybercrime's evolution from organized click fraud and credential stuffing to today's AI-generated attacks that can carry on a real-time conversation and defraud victims convincingly. He explains why traditional email filtering forces an impossible tradeoff between blocking legitimate ...Read more
exploreKeep Exploring
How has cybercrime evolved over the past 20 years?add
How have cybercriminal tactics evolved—from exploiting large data breaches and replaying credentials to a commoditized, federated criminal ecosystem—and how is generative AI enabling them to carry out the “last mile” of attacks by conducting real-time conversational fraud?add
How are users protected against malicious or spam emails, and why do email filters sometimes fail to stop them?add
How should UX and security indicators be designed to build user trust, avoid banner blindness, and clearly signal when a connection or communication is trustworthy?add
Who is the ideal user for this technology — is it primarily intended for high-net-worth individuals and corporate executives, or for the general public?add
Is this product a defensible, standalone company or merely a feature that a larger platform could easily replicate — in other words, could other companies simply rebuild or integrate this technology into their platforms?add
>> Palo Alto Studio Connection, Silicon Valley and Wall Street.>> I'm John Furrier, co-host of theCUBE here with Dave Vellante, my co-host. Welcome back to theCUBE studio here at the New York Stock Exchange.
Gemma Allen
>> I'm Gemma Allen, co-host of NYSE Wired Cybersecurity Leaders. And we know that the internet used to have a trust problem. AI might have just turned that into an identity crisis. Deepfakes can sound like your CEO. Phishing emails can be generated on an industrial scale. And increasingly, the hardest thing online isn't knowing what's malicious, it's knowing what's real. My next guest has spent his career fighting exactly this problem. From Google's battle against click fraud to Shape Security, which was acquired by F5 for $1 billion, and now Reken. Shuman, CEO and co-founder of Reken, welcome to NYSE Wired.
Shuman Ghosemajumder
>> Thanks so much for having me.
Gemma Allen
>> Okay, so let's get straight into it because when it comes to cybersecurity and the challenges of the AI era, this is not your first rodeo. You have been in this industry a while. You have seen all sorts of challenges emerge, I am sure. Talk to me about this moment right now and the decision to found Reken.
Shuman Ghosemajumder
>> So I think that we've seen the world evolving to this point for more than 20 years now. So when people thought about cybercrime, in the '90s or in the early 2000s, I think that they had a fairly simplistic view of usually imagining someone in a hoodie in their parents' basement trying to hack into different kinds of servers. And that's not what cybercrime has looked like for a couple of decades now. So in the early 2000s at Google, we started to see how organized cybercrime was getting very sophisticated, and they were creating click fraud attempts that were using all kinds of different software and automation. And that only got more sophisticated at Shape Security, where we were protecting the largest banks and airlines and federal agencies against, when cybercriminals would take all of these stolen usernames and passwords that we read about on a regular basis from big data breaches, and they would replay them essentially against your bank and your airline and all of these other types of big companies. That had millions of usernames that, they needed to manage. And so in those cases, what we saw was the first sign of cybercriminals using a very commoditized and federated kind of ecosystem where they were collaborating with different groups that each specialized in different kinds of tasks in order to be able to defeat our security. And so, the culmination of this is really recent, where we've now seen because of generative AI, cybercriminals can essentially do the last mile of the attack that they were never able to do in the past, where you can actually carry on a conversation with a real human being and you can defraud them even in real time.
Gemma Allen
>> we've certainly seen some alarming examples of this, right? Like imitations of Jamie Dimon, for example, that went out on the net last summer. It's pretty scary stuff. But cyber itself as an industry, I feel like it gets a lot of press, right? But we also think of it as a relatively saturated space in some respects, right? I remember reading a while back that some CISOs might have 80 different cyber tools or technologies on their P&L in any given month. How do you build a product that's unique for this moment, though? Talk me through the competitive advantage of Reken?
Shuman Ghosemajumder
>> Yeah, that's a great question. And I think that it's been evolving in this direction for quite some time because every single time there's a cyber incident, you look at exactly what the vulnerability was. And in many cases, what people decide is that there was an attack surface that wasn't actually protected. And so we need to create some kind of new product to be able to deal with that attack surface. So this is the story of the evolution of email spam protection, of two-factor authentication, of all of the different types of security that we use, in any kind of complex environment. And over time, you think that basically every single attack surface has been covered in some form or another, but I think that there are attack surfaces that are not covered for a variety of different reasons. So in one case, an attack surface may not be covered because it's brand new. So if you create a new type of product that has never existed before and a lot of people start using it, then that creates an attack surface that you now have to think about, how do I protect it? So AI is in this category. So we didn't have so many people who were using AI, especially generative AI, 3 years ago as we do now. And so the more organizations and people who are using AI the more new security products need to be created to be able to protect against that. But the other way that you can create a protection for an attack surface that has not been protected is to have some kind of technology breakthrough in the cybersecurity area itself. So what if you could do something to be able to protect something that you previously thought wasn't really possible to apply technology to? And so in our case, the breakthrough is being able to use AI in a context that we were never able to use previous technologies. And that's how we communicate online. So when we're reading a message, whether it's an email or a text message or we're on a Zoom call, all of those cases are real-time or near real-time or offline communications where we're trying to protect what we get there. But we never had the ability to be able to do that in real time before. And so AI enables that breakthrough.
Gemma Allen
>> And am I correct in saying that this is a product that lives on your device, that travels and works along with you? Right. So from a real-time perspective, it's happening here and now. It's not necessarily an alert is being sent to a security operations center alerting, somebody who's alerting somebody who is saying, oh, we need to look at this. This is very instantaneous. Explain to me the user experience of this. yeah, say tonight I get an email from John Furrier saying, hey Gemma, you need to wire this to this person, right? How, it sounds like John, it looks like John, it's John's email address. What would this product do to make me realize, oh crap, there is something not right here?
Shuman Ghosemajumder
>> Yeah, so first of all, let's talk about how you're protected against that right now and why that doesn't always work. So the first way that you're protected against that is by some kind of, email filtering. So you've got various email filtering products that are analyzing all of the emails that are sent to you, and Google and Microsoft are doing the vast majority of this because they're looking for all of the spam that's sent all around the world, and they're putting that into your spam folder instead of delivering it to you in your inbox. But the problem with any kind of email filtering product, including the email filtering that goes on top of what Google and Microsoft provide is that there's a false positive/false negative trade-off. So if you want to be as aggressive as possible and say that we don't want to take any chances, we're going to look at this message that looks like it's potentially suspicious because maybe John hasn't sent an email that late before, or maybe John hasn't sent an email on that particular topic before, then you could be very aggressive with the filtering and then end up taking a legitimate message and putting it in spam. And that's when you create all kinds of organizational problems, because you have an executive or a salesperson or anyone that communicates with the external world, like journalists, on a regular basis, and they're going to wonder, where's this important email that I was expecting? And then if they find out that it was quarantined for 48 hours and then the entire opportunity is gone, then that's completely unacceptable. And so nobody sets their email filtering to actually be that aggressive. And so you accept that there are a certain number of malicious messages that are making their way through to your users right now. And so then the backup mechanism is phishing awareness training. And so everyone gets dragged through phishing awareness training, either four hours a year, or a smaller amount of time. But the amazing thing about phishing training is that it doesn't seem to affect any of our security outcomes. So there's been a number of, , research studies that have been done on this, and unfortunately what they show is that for a variety of reasons, going through phishing training, regardless of what the phishing training is, doesn't actually make anyone safer. It doesn't change their behavior. And there are a couple of reasons for this when you think about it. So one reason for it is that people are distracted when they're reading their email. They're not always thinking about security. They're not thinking about, , what are all of the minute telltale signs that something could potentially be malicious. And of course, the messages are now AI-generated and they're much more sophisticated than ever before. So that's one reason that you're just not in that mode. And most people aren't tech experts to be able to identify a very sophisticated phishing message that's been created. But the other reason is that you can never really simulate in a phishing simulation a scary scenario that a cybercriminal will actually put someone through. So, , there was this case of GoDaddy doing a phishing awareness exercise a few years back where they promised all of their employees a free gift card, and then when they clicked on the link, they discovered there's no gift card, and it was a phishing training test that they just failed. And so that made them so angry that they actually went public with it, and people complained to the press about it.
Gemma Allen
>> Wow.
Shuman Ghosemajumder
>> And so if you were to try and do a phishing training exercise that, said that here's a message where we're saying your family is in danger, or your job is in danger, or the CEO is angry at you, that would create psychological trauma. And so you can never simulate the really scary scenarios that real people have to deal with. And so what we've created is a brand new approach, because what you need is protection right at the moment that you're about to make a mistake, and something that uses technology to be able to see what you can't see as a user. And so that was never possible before.
Gemma Allen
>> But that example you gave, and first of all, that's fascinating. I did not know that about GoDaddy. I would probably click that link and be like, great, a free gift card, hooray. But from the perspective of what you're building here, so what you describe, it's on your device. It has to understand a lot of context about your persona, correct? It understands that John doesn't typically email me at 11 o'clock at night, or he wouldn't ask me to wire money to somebody or whatever it might be. It knows some sort of nuance or it reads into some sort of nuance about how I live, how I work, how I play, that it can then detect an anomaly in this potential engagement, correct? What is the signal like? I'm interested to understand what uniquely is it looking for.
Shuman Ghosemajumder
>> So that's part of it. So there are many different things that you want to look at. So for example, when you look at what you're supposed to learn in phishing training, you're supposed to look at who is this actually coming from? Is the domain accurate? Is this including a link that looks like it could be suspicious, and all of the other technical characteristics that are associated with email. Then there are the contextual characteristics that you were talking about. How does John usually email me? What are the topics that he usually emails me about? Is there an unusual sense of urgency to this message that seems anomalous in some way? And what we can provide is a comprehensive view of all of the different things that we're able to detect that are potentially wrong about this message that you may be too distracted or may not be looking closely enough or may not have the technical expertise to be able to find. And so if you can take all of these hundreds of different characteristics and you can surface them to the user in a way that presents it with a very simple user interface that doesn't get in their way, that's really the magic of how do we navigate the complexity of the online world at this point.
Gemma Allen
>> It might seem like a simple question here, but how do you grab their attention immediately in that moment? Right. Because oftentimes we're doing like 20 things at once, right? You're reading an email, you're feeding your kids, and your technology is saying, holy crap, this is really dodgy, don't do this. How do you engage with them in real time?
Shuman Ghosemajumder
>> Yeah, that's one of the key secrets here in terms of how we've built this product. And now that we're out of stealth, we're happy to be able to talk about it. But the UX that we've employed and we've done a lot of research on is one that has a combination of positive and negative security indicators. And I think that's something which is very important. So what— one of the very first jobs that I had in the early 2000s at Google was running experiments across our ad system, across millions of different websites to be able to figure out how do users actually respond to different kinds of information. Ads especially, but other types of information as well. And when do they start to experience banner blindness? So if you keep showing the same thing to the user, if you keep showing them a whole bunch of alerts, if you keep showing them a whole bunch of indications that are exactly in the same place all the time, they begin to learn that that's something that they should ignore, and it doesn't actually change behavior anymore. So if you start to tell users, for example, that you should be careful, this is an external website that you're talking to, or it's an external domain that you're talking to, and you have it on every single email whenever they talk to someone who is outside of their organization, they get banner blindness almost immediately. And so what you want to have is some kind of positive security indicators that tell them when something is trustworthy and when it's okay. And this is actually a core part of our approach. In terms of being able to build out a trust network where if I'm using a product that uses what we call the Reken Private Core and you are using a Reken Private Core application as well, when we communicate, we become part of that trust network and now we can provide positive trust indicators that allow you to basically accept this information almost subconsciously so you don't have to think as much. So an example of positive trust indicators is TLS. So when you're visiting a website and you used to be able to get that lock icon on many different browsers, that gave you this positive trust indicator that as soon as it was missing on a site where you were giving your credit card information, you would start to feel a little bit weird about that. You're like, why is this not an encrypted connection? And that was just a very simple kind of trust indicator. You could have much bigger and more obvious trust indicators. So another example of that is, the blue bubble, green bubble distinction that Apple has made in iOS. So if you're communicating with another iPhone user, you actually get end-to-end encryption built in.
Gemma Allen
>> Mm.
Shuman Ghosemajumder
>> And that shows up as a really simple blue bubble. And so the user doesn't have to think as much. Whenever they're communicating in the blue bubble world, blue bubbles are safe. And then when they get SMS spam, they get a weird feeling about that. And because that's always showing up in the green bubble world.
Gemma Allen
>> So you've come out of stealth. Am I correct in assuming that this is designed— I'm sure it has mass usage, but is it designed for high net worth individuals, for executives within Fortune 500s? who is the ideal user for a technology like this?
Shuman Ghosemajumder
>> Yeah, that's a great question. And I think that there are folks that have had bad experiences with fraud online. Unfortunately, an increasing number of people have had such bad experiences, and this is, of course, those are the types of folks that we had in mind when we founded the company, and we wanted to be able to protect friends and family members who have experienced fraud. My co-founder and I both have friends and family members that have had thousands of dollars stolen from them. But of course, large corporations and governments and large organizations and high net worth individuals and executives also have similar kinds of concerns. So really, this is a problem that is affecting everyone that uses online communications. And all of our communication media are essentially getting overwhelmed by fraud, especially because of AI now. So, there was a study that was done a number of years ago that had an analysis of where is all of the email spam coming from. And what it found was that 90% of the world's email spam at the time was actually coming from just 3 sources. And so that's what automation enables. And so that's what's now possible with generative AI as well. So cybercriminals can use generative AI and attack millions of people simultaneously with highly customized messages. And, this is something that all of our existing systems were never really designed to be able to deal with. And that's why we need to have essentially some kind of a guide. We call the product Northstar because it guides people in the right direction. And it doesn't matter if you're an executive or an individual. As a consumer, everyone is getting affected by these types of fraud and scams.
Gemma Allen
>> So the business is predominantly B2B, but it certainly has a B2C use case. Am I correct?
Shuman Ghosemajumder
>> Well, we want to be able to get to B2C in the future.
Gemma Allen
>> Okay.
Shuman Ghosemajumder
>> Right now we've just come out of stealth and we're concentrating on being able to protect large enterprises and governments.
Gemma Allen
>> And if I'm Jamie Dimon and I have a Reken, I'm on my device.
Shuman Ghosemajumder
>> Yeah.
Gemma Allen
>> And I'm talking to somebody at a hedge fund. Does that person also need to be a Reken user for it to be validated? Or what's the nexus?
Shuman Ghosemajumder
>> That's a really important distinction, because if Jamie Dimon is using the Northstar product just by himself, then he is protected against all of the spam and fraud and social engineering that's directed against him. But if he is then communicating with folks in his organization who are also using the Northstar product, he gets an additional layer of protection. And so that's what starts to give the positive indicators that, similar to the blue bubbles, that now you've got a trusted communication that's been established.
Gemma Allen
>> Okay, so it's fascinating. it's a scary time. I see, certainly see the market value or the user value in something like this. What stage are you guys at? You're out of stealth?
Shuman Ghosemajumder
>> Yeah.
Gemma Allen
>> You have a few POCs in place across enterprises? Talk me through what sorts of use cases or proofs of concepts you've had so far.
Shuman Ghosemajumder
>> Yeah, we've been working with Fortune 500 design partners and making sure that the technology works really well. And so that's what gave us the confidence that we can now come out of stealth and make this available to the broader marketplace. And so that's exactly who we're engaging with. We're thinking primarily organizations that are trying to deal with these types of problems at a large scale. Those are the folks that we're concentrating on right now. But ultimately, we want to be a solution for everyone in the market.
Gemma Allen
>> And the business case, it's license-based, usage-based. How's it commercialized?
Shuman Ghosemajumder
>> Yeah, it's seat-based.
Gemma Allen
>> Seat-based. Okay. Per user.
Shuman Ghosemajumder
>> That's right.
Gemma Allen
>> And I guess last question to you. I mean, you've been in the industry quite a while. It is a very interesting time in cyber. I mean, I think everyone can see or hear that. We hear a lot about the world of cyber and how hard it is to take on some of those incumbents that have been in the space for a while. We've had some very high-profile cyber CEOs on here and say, Everything's going to converge eventually, right? You've already sold a company. How do you think about this time as a second-time founder? Where do you see this industry headed? Do you think that it's too saturated? I mean, obviously not if you founded a company, but how do you fight back against the challenge of what is somewhat of a saturated industry at a noisy time? Right. It seems like everyone's promising to fix all your problems.
Shuman Ghosemajumder
>> Yeah, I think that it's really about the market that you pick. So the question that everyone has about every single startup is, is this truly a standalone company in the long run, or is this more of a feature of a larger platform? And could someone else build this technology and just simply include it within their larger platform that already exists and has a whole bunch of customers? Or is it really difficult to be able to recreate that? And so this was one of the reasons why we were trying to come up with something that had never existed before. And we spent 2 years of R&D figuring out whether or not this technology was even possible. Because when you think about using AI in this kind of a context, what most people think of today, and this is what the market looks like, is putting a wrapper around one of the big frontier models. So, having ChatGPT or Claude analyze all of your messages. And there are a couple of problems with that.
Gemma Allen
>> there's some fundamental problems with—
Shuman Ghosemajumder
>> oh, yeah, right.
Gemma Allen
>> But please continue.
Shuman Ghosemajumder
>> Well, I think what you're probably alluding to is the privacy issue.
>> Exactly. It's basically a nonstarter to have all of this highly confidential data being analyzed and potentially being used to train someone's third-party model. In fact, It's even a liability from a security perspective for you to have a security company analyzing all of that in their own third-party environment. And there are a number of different companies that have you send your most confidential data to their third-party cloud to analyze. And so the privacy issue was one of the big things that we wanted to deal with. And doing that on device requires us to invent brand new technology that's never existed before. Capable of being able to solve the other problem as well. And the other problem is that it's simply too slow to have your device send your data, even if it was okay from a privacy perspective, which it's not, of course, but it's too slow to send your data to a third-party cloud to have it analyzed. At best, it would take several seconds to respond back, and that's way too slow to provide just-in-time protection for users. And so we needed to figure out whether or not it was even possible to have technology that executes on a device without a GPU. So I actually went to Best Buy and bought the worst laptop that they sold, and that was my testing device. And if it can run well on that device without slowing down the experience for users, then we knew that it could run on any Fortune 500 machine. And so building that technology, that is really the answer in terms of, can someone else just simply recreate this? It's not something you can vibe code. It's not something that is trivial to be able to create. So that's one part of it. The other part in terms of, being able to distinguish yourself and grow over time is whether or not the market is a broad enough market. And so what we're dealing with, we think of it as a problem that not only affects every consumer, every small business and every large enterprise and government in the world. But it's also a problem that will never actually be solved. Even if we're highly successful, the problem will not be solved. There will always be crime. Cybercrime is basically the norm now in terms of crime when you look at the amount of dollars that are stolen. And so it will simply morph into new forms. And what we want to create is a company that adapts along the way and becomes, the brand that builds a variety of different products and essentially becomes that platform in a brand new era.
Gemma Allen
>> Well, it certainly ties in a lot of topics that we talk about here on NYSE Wired because it's on the edge, right? Essentially in terms of the device management and it's securing the future of whatever it might be that the inference generation or era is going to bring our way, which can certainly sound a little bit alarming. When we think about it from a bird's eye view. So thank you so much for joining us on NYSE Wired.
Shuman Ghosemajumder
>> Thank you, Gemma.
Gemma Allen
>> I'm Gemma Allen here at theCUBE Studio at the New York Stock Exchange. This is Cyber Security Leaders, one of our programs at NYSE Wired. We talk about all of the threats and all of the hopeful solutions that will solve for the problems of tomorrow. Thanks so much for joining.