AGI-Pilled Cyber Defense: Automating Digital Forensics w/ Asymmetric Security CEO Alexis Carlier
Episode
76 min
Read time
3 min
Topics
Productivity, Remote Work, Relationships
AI-Generated Summary
Key Takeaways
- ✓Threat Actor Hierarchy: Approximately 80% of cyberattacks come from unsophisticated criminals using spray-and-pray tactics, while nation-states like China focus on IP theft from R&D-heavy industries and North Korea runs remote worker programs where operatives infiltrate Western tech companies to earn salaries funding the regime. Ransomware gangs occupy the middle ground, causing order-of-magnitude more economic damage than they capture in payments, with attacks like Jaguar requiring a $2 billion government loan after operations went down for one to two months.
- ✓Detection Gap Economics: Current cybersecurity relies on static rule-based monitoring systems that generate excessive false positives because suspicious behavior often mirrors normal activity. Digital forensics investigations that deeply analyze evidence can distinguish real threats but remain prohibitively expensive, with only 60 investigators at CrowdStrike capable of performing this work. This creates a paradigm where deep investigations only happen reactively after breaches, missing most attacks that go undetected for extended periods.
- ✓AI Capability Threshold: Off-the-shelf language models already achieve approximately 90% accuracy on email-based compromise investigations without specialized training, but the final reliability gap requires human oversight for production deployment. Asymmetric uses human-AI teams where agents perform first-pass analysis and investigators conduct quality control, building proprietary datasets from real incidents to close performance gaps. This services-first approach through insurance company partnerships provides both customer trust and the data flywheel needed for model improvement.
- ✓Defensive Asymmetry Opportunity: Digital forensics specialists who investigate breaches do not typically become skilled offensive hackers, suggesting limited skill transfer between defensive investigation and offensive exploitation. This contrasts with domains like penetration testing where capabilities are inherently dual-use. The separation creates an opportunity to differentially accelerate defensive AI capabilities through specialized datasets, evaluations, and training environments without proportionally advancing offensive capabilities, though this window closes as models achieve broader generalization.
- ✓Jagged Frontier Strategy: Reinforcement learning creates predictable capability improvements in domains with verifiable rewards like coding and math, but lags in areas lacking clear evaluation signals. Organizations can intentionally shape the AI capability frontier by curating specialized datasets, building realistic environments, and developing high-fidelity evaluations in strategically important domains. This approach could be replicated across biosecurity, AI safety, and other areas where hardening defenses matters, but requires subject matter experts willing to encode their expertise into AI systems.
What It Covers
Alexis Carlier, founder of Asymmetric Security, explains how his company automates digital forensics investigations using AI agents to detect cyber breaches proactively rather than reactively. He describes the current threat landscape from financially motivated criminals to nation-state actors, details how AI models achieve 90% accuracy on forensic tasks, and argues digital forensics represents a defensible domain for differential acceleration.
Key Questions Answered
- •Threat Actor Hierarchy: Approximately 80% of cyberattacks come from unsophisticated criminals using spray-and-pray tactics, while nation-states like China focus on IP theft from R&D-heavy industries and North Korea runs remote worker programs where operatives infiltrate Western tech companies to earn salaries funding the regime. Ransomware gangs occupy the middle ground, causing order-of-magnitude more economic damage than they capture in payments, with attacks like Jaguar requiring a $2 billion government loan after operations went down for one to two months.
- •Detection Gap Economics: Current cybersecurity relies on static rule-based monitoring systems that generate excessive false positives because suspicious behavior often mirrors normal activity. Digital forensics investigations that deeply analyze evidence can distinguish real threats but remain prohibitively expensive, with only 60 investigators at CrowdStrike capable of performing this work. This creates a paradigm where deep investigations only happen reactively after breaches, missing most attacks that go undetected for extended periods.
- •AI Capability Threshold: Off-the-shelf language models already achieve approximately 90% accuracy on email-based compromise investigations without specialized training, but the final reliability gap requires human oversight for production deployment. Asymmetric uses human-AI teams where agents perform first-pass analysis and investigators conduct quality control, building proprietary datasets from real incidents to close performance gaps. This services-first approach through insurance company partnerships provides both customer trust and the data flywheel needed for model improvement.
- •Defensive Asymmetry Opportunity: Digital forensics specialists who investigate breaches do not typically become skilled offensive hackers, suggesting limited skill transfer between defensive investigation and offensive exploitation. This contrasts with domains like penetration testing where capabilities are inherently dual-use. The separation creates an opportunity to differentially accelerate defensive AI capabilities through specialized datasets, evaluations, and training environments without proportionally advancing offensive capabilities, though this window closes as models achieve broader generalization.
- •Jagged Frontier Strategy: Reinforcement learning creates predictable capability improvements in domains with verifiable rewards like coding and math, but lags in areas lacking clear evaluation signals. Organizations can intentionally shape the AI capability frontier by curating specialized datasets, building realistic environments, and developing high-fidelity evaluations in strategically important domains. This approach could be replicated across biosecurity, AI safety, and other areas where hardening defenses matters, but requires subject matter experts willing to encode their expertise into AI systems.
- •Distribution Through Insurance: Asymmetric enters the market through cybersecurity insurance carriers rather than direct enterprise sales, getting approved on insurer panels that dispatch incident response vendors when policyholders get breached. This distribution model solves the trust problem inherent in cybersecurity where effectiveness is difficult to assess, following the CrowdStrike playbook of starting with services to build relationships and data before productizing. The approach reduces investigation time from two days to one week down to a few hours.
Notable Moment
Carlier reveals that most technical vulnerabilities exploited in cyberattacks are known issues that organizations simply have not patched, rather than sophisticated zero-day exploits. Attackers consistently choose the path of least resistance, with social engineering and phishing comprising 70 to 80% of attack volume, because there is no reason to burn valuable unknown vulnerabilities when a convincing email works just as effectively.
You just read a 3-minute summary of a 73-minute episode.
Get Cognitive Revolution summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from Cognitive Revolution
Alignment with Awakening: Davidad on Moral Realism, AI Wisdom, & why His p(Doom) is Down to 5%
Jul 12 · 143 min
Invest Like the Best with Patrick O'Shaughnessy
William Hockey - Building the Operating System for the Dollar and Silicon Valley Heresy - [Invest Like the Best, EP.463]
Mar 17
More from Cognitive Revolution
AI:AM Highlights: Exploring the J-Space, AI Superforecasters, SambaNova's Chips, & LTX Video Gen
Jul 9 · 127 min
Software Engineering Daily
NanoClaw and the Rise of Personal AI Agents
Jul 21
Books, tools, and gear mentioned in this episode
SignalCast may earn commission on purchases via these links.
Tools
“SPONSORS: Granola (granola.com)”
“SPONSORS: Blitsy (blitsy.com)”
“SPONSORS: Tasklet (tasklet.ai)”
company
“This services-first approach through insurance company partnerships provides both customer trust and the data flywheel needed for model improvement. This approach could be replicated across biosecurity, AI safety, and other areas where hardening defenses matters, but requires subject matter experts willing to encode their expertise into AI systems. The approach reduces investigation time from two days to one week down to a few hours, following the CrowdStrike playbook of starting with services t”
“Alexis Carlier, founder of Asymmetric Security, explains how his company automates digital forensics investigations using AI agents to detect cyber breaches proactively rather than reactively.”
More from Cognitive Revolution
We summarize every new episode. Want them in your inbox?
Alignment with Awakening: Davidad on Moral Realism, AI Wisdom, & why His p(Doom) is Down to 5%
AI:AM Highlights: Exploring the J-Space, AI Superforecasters, SambaNova's Chips, & LTX Video Gen
Intelligence on the Edge: Liquid AI's Ramin Hasani on the Search for Device-Native Foundation Models
1000 Designs a Day: Neural Concept's Thomas von Tschammer on AI-Native Engineering
AI:AM #4: Cameron on Model Consciousness, Duvenaud's Gradual Disempowerment, swyx's AI-Eng Alpha
Similar Episodes
Related episodes from other podcasts
Invest Like the Best with Patrick O'Shaughnessy
Mar 17
William Hockey - Building the Operating System for the Dollar and Silicon Valley Heresy - [Invest Like the Best, EP.463]
Software Engineering Daily
Jul 21
NanoClaw and the Rise of Personal AI Agents
a16z Podcast
Jul 17
Amjad Masad on Going Direct, Building Replit, and the Future of Software
Masters of Scale
Jul 14
The quiet reinvention of a $42b business, with Canva’s Cameron Adams
Eye on AI
Jul 13
Inside the Enterprise Browser Rebuilding Security for the AI Era | Bradon Rogers, Island
Explore Related Topics
This podcast is featured in Best AI Podcasts (2026) — ranked and reviewed with AI summaries.
You're clearly into Cognitive Revolution.
Every Monday, we deliver AI summaries of the latest episodes from Cognitive Revolution and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime