AGI-Pilled Cyber Defense: Automating Digital Forensics w/ Asymmetric Security CEO Alexis Carlier
Episode
76 min
Read time
3 min
Topics
Productivity, Remote Work, Relationships
AI-Generated Summary
Key Takeaways
- ✓Threat Actor Hierarchy: Approximately 80% of cyberattacks come from unsophisticated criminals using spray-and-pray tactics, while nation-states like China focus on IP theft from R&D-heavy industries and North Korea runs remote worker programs where operatives infiltrate Western tech companies to earn salaries funding the regime. Ransomware gangs occupy the middle ground, causing order-of-magnitude more economic damage than they capture in payments, with attacks like Jaguar requiring a $2 billion government loan after operations went down for one to two months.
- ✓Detection Gap Economics: Current cybersecurity relies on static rule-based monitoring systems that generate excessive false positives because suspicious behavior often mirrors normal activity. Digital forensics investigations that deeply analyze evidence can distinguish real threats but remain prohibitively expensive, with only 60 investigators at CrowdStrike capable of performing this work. This creates a paradigm where deep investigations only happen reactively after breaches, missing most attacks that go undetected for extended periods.
- ✓AI Capability Threshold: Off-the-shelf language models already achieve approximately 90% accuracy on email-based compromise investigations without specialized training, but the final reliability gap requires human oversight for production deployment. Asymmetric uses human-AI teams where agents perform first-pass analysis and investigators conduct quality control, building proprietary datasets from real incidents to close performance gaps. This services-first approach through insurance company partnerships provides both customer trust and the data flywheel needed for model improvement.
- ✓Defensive Asymmetry Opportunity: Digital forensics specialists who investigate breaches do not typically become skilled offensive hackers, suggesting limited skill transfer between defensive investigation and offensive exploitation. This contrasts with domains like penetration testing where capabilities are inherently dual-use. The separation creates an opportunity to differentially accelerate defensive AI capabilities through specialized datasets, evaluations, and training environments without proportionally advancing offensive capabilities, though this window closes as models achieve broader generalization.
- ✓Jagged Frontier Strategy: Reinforcement learning creates predictable capability improvements in domains with verifiable rewards like coding and math, but lags in areas lacking clear evaluation signals. Organizations can intentionally shape the AI capability frontier by curating specialized datasets, building realistic environments, and developing high-fidelity evaluations in strategically important domains. This approach could be replicated across biosecurity, AI safety, and other areas where hardening defenses matters, but requires subject matter experts willing to encode their expertise into AI systems.
What It Covers
Alexis Carlier, founder of Asymmetric Security, explains how his company automates digital forensics investigations using AI agents to detect cyber breaches proactively rather than reactively. He describes the current threat landscape from financially motivated criminals to nation-state actors, details how AI models achieve 90% accuracy on forensic tasks, and argues digital forensics represents a defensible domain for differential acceleration.
Key Questions Answered
- •Threat Actor Hierarchy: Approximately 80% of cyberattacks come from unsophisticated criminals using spray-and-pray tactics, while nation-states like China focus on IP theft from R&D-heavy industries and North Korea runs remote worker programs where operatives infiltrate Western tech companies to earn salaries funding the regime. Ransomware gangs occupy the middle ground, causing order-of-magnitude more economic damage than they capture in payments, with attacks like Jaguar requiring a $2 billion government loan after operations went down for one to two months.
- •Detection Gap Economics: Current cybersecurity relies on static rule-based monitoring systems that generate excessive false positives because suspicious behavior often mirrors normal activity. Digital forensics investigations that deeply analyze evidence can distinguish real threats but remain prohibitively expensive, with only 60 investigators at CrowdStrike capable of performing this work. This creates a paradigm where deep investigations only happen reactively after breaches, missing most attacks that go undetected for extended periods.
- •AI Capability Threshold: Off-the-shelf language models already achieve approximately 90% accuracy on email-based compromise investigations without specialized training, but the final reliability gap requires human oversight for production deployment. Asymmetric uses human-AI teams where agents perform first-pass analysis and investigators conduct quality control, building proprietary datasets from real incidents to close performance gaps. This services-first approach through insurance company partnerships provides both customer trust and the data flywheel needed for model improvement.
- •Defensive Asymmetry Opportunity: Digital forensics specialists who investigate breaches do not typically become skilled offensive hackers, suggesting limited skill transfer between defensive investigation and offensive exploitation. This contrasts with domains like penetration testing where capabilities are inherently dual-use. The separation creates an opportunity to differentially accelerate defensive AI capabilities through specialized datasets, evaluations, and training environments without proportionally advancing offensive capabilities, though this window closes as models achieve broader generalization.
- •Jagged Frontier Strategy: Reinforcement learning creates predictable capability improvements in domains with verifiable rewards like coding and math, but lags in areas lacking clear evaluation signals. Organizations can intentionally shape the AI capability frontier by curating specialized datasets, building realistic environments, and developing high-fidelity evaluations in strategically important domains. This approach could be replicated across biosecurity, AI safety, and other areas where hardening defenses matters, but requires subject matter experts willing to encode their expertise into AI systems.
- •Distribution Through Insurance: Asymmetric enters the market through cybersecurity insurance carriers rather than direct enterprise sales, getting approved on insurer panels that dispatch incident response vendors when policyholders get breached. This distribution model solves the trust problem inherent in cybersecurity where effectiveness is difficult to assess, following the CrowdStrike playbook of starting with services to build relationships and data before productizing. The approach reduces investigation time from two days to one week down to a few hours.
Notable Moment
Carlier reveals that most technical vulnerabilities exploited in cyberattacks are known issues that organizations simply have not patched, rather than sophisticated zero-day exploits. Attackers consistently choose the path of least resistance, with social engineering and phishing comprising 70 to 80% of attack volume, because there is no reason to burn valuable unknown vulnerabilities when a convincing email works just as effectively.
Episode Transcript
Hello, and welcome back to the cognitive revolution. Before getting started today, I wanna take a moment to introduce our newest sponsor, Granola. You probably know Granola as a leading AI note taker, but it's in fact much more than that. Because it works at the operating system level, it can capture all audio in and out of your computer, allowing it to take notes not just on meetings, every podcast you listen to, every video you watch, and if you choose, everything you say. Right now, to help new users make the most of the platform, Granola is featuring AI recipes from entrepreneurial thought leaders, including several past guests of this show. There's a Replit recipe that converts discussion notes to a Replit app build brief, a Bentasil recipe that creates content production plans, and a Dan Shipper recipe that looks across multiple sessions to build an unspoken company culture handbook. My own recipe, which you can try now on granola, is a blind spot finder. It looks back at recent conversations and attempts to identify things that I am totally missing. This has already proven useful in the context of contingency planning for my son's cancer treatment, though I am very happy to report that he is still doing extremely well. And over time, I expect it will become invaluable for suggesting AI topic areas that I've neglected and really ought to explore. For today, my guest is Alexei Carlier, founder and CEO of Asymmetric Security, which just recently came out of stealth. In response to the launch announcement, Logan Graham, who leads the red team at Anthropic, described Alexei as one of the most AGI filled founders in the space. So naturally, I had to find out what that means for the future of cybersecurity. As you'll hear, Alexei's motivation is increasingly familiar, but nevertheless profound. If we assume that AGI is coming and that it represents a near infinite supply of intelligent labor, the question becomes, how should we redesign our cyber defenses from the ground up? His answer is to move from a paradigm of reactive emergency triage to one of proactive continuous digital forensics. We begin the conversation by describing the current threat landscape, distinguishing between the spray and pray tactics of financially motivated criminals, the more sophisticated ransomware attacks of cybercrime gangs, and the patient, high stakes IP theft operations conducted by nation states like China. Alexi also shares fascinating details on the North Korean remote worker phenomenon, where state backed actors infiltrate Western tech companies not just to steal secrets, but also to earn salaries that actually fund the regime. From there, we turn to how asymmetric is building AI agents capable of performing the deep investigative work that was previously only available from a very limited number of expensive human experts. We discussed the jagged frontier of current model capabilities in the security domain and why, though off the shelf models can already achieve 90% accuracy on many investigative tasks, asymmetric …
Get the full transcript (14,875 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 73-minute episode.
Get Cognitive Revolution summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from Cognitive Revolution
AI:AM Highlights: Welcome to the AGI Era
Sep 5 · 140 min
Invest Like the Best with Patrick O'Shaughnessy
William Hockey - Building the Operating System for the Dollar and Silicon Valley Heresy - [Invest Like the Best, EP.463]
Mar 17
More from Cognitive Revolution
Write, Change, Recall, Forget: MongoDB's Pete Johnson on How Retrieval Drives Agent Performance
Sep 1 · 96 min
David Senra
Mati Staniszewski on ElevenLabs, Voice AI & Building the Communication Layer for AI
Sep 9
Books, tools, and gear mentioned in this episode
SignalCast may earn commission on purchases via these links.
Tools
“SPONSORS: Granola (granola.com)”
“SPONSORS: Blitsy (blitsy.com)”
“SPONSORS: Tasklet (tasklet.ai)”
company
“This services-first approach through insurance company partnerships provides both customer trust and the data flywheel needed for model improvement. This approach could be replicated across biosecurity, AI safety, and other areas where hardening defenses matters, but requires subject matter experts willing to encode their expertise into AI systems. The approach reduces investigation time from two days to one week down to a few hours, following the CrowdStrike playbook of starting with services t”
“Alexis Carlier, founder of Asymmetric Security, explains how his company automates digital forensics investigations using AI agents to detect cyber breaches proactively rather than reactively.”
More from Cognitive Revolution
We summarize every new episode. Want them in your inbox?
AI:AM Highlights: Welcome to the AGI Era
Write, Change, Recall, Forget: MongoDB's Pete Johnson on How Retrieval Drives Agent Performance
AI:AM Highlights: Recursive Self-Improvement, Rushed and Vibe-Coded?
RL's a Hell of a Drug: Metagaming, Reward Seeking & Motivated CoT Reasoning – Bronson Schoen, Apollo
AI in the AM — Weekly Highlights: Relaunch Week (Aug 17–20, 2026)
Similar Episodes
Related episodes from other podcasts
Invest Like the Best with Patrick O'Shaughnessy
Mar 17
William Hockey - Building the Operating System for the Dollar and Silicon Valley Heresy - [Invest Like the Best, EP.463]
David Senra
Sep 9
Mati Staniszewski on ElevenLabs, Voice AI & Building the Communication Layer for AI
David Senra
Sep 6
Zach Dell on Base Power, Energy Abundance & Building a Company for Life
David Senra
Aug 26
Building Defense Technologies to Protect Democracies | Torsten Reil, Helsing
David Senra
Aug 2
Micky Malka, Founder of Ribbit Capital
Explore Related Topics
This podcast is featured in Best AI Podcasts (2026) — ranked and reviewed with AI summaries.
You're clearly into Cognitive Revolution.
Every Monday, we deliver AI summaries of the latest episodes from Cognitive Revolution and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime