AGI-Pilled Cyber Defense: Automating Digital Forensics w/ Asymmetric Security CEO Alexis Carlier
Episode
76 min
Read time
3 min
Topics
Productivity, Remote Work, Relationships
AI-Generated Summary
Key Takeaways
- ✓Threat Actor Hierarchy: Approximately 80% of cyberattacks come from unsophisticated criminals using spray-and-pray tactics, while nation-states like China focus on IP theft from R&D-heavy industries and North Korea runs remote worker programs where operatives infiltrate Western tech companies to earn salaries funding the regime. Ransomware gangs occupy the middle ground, causing order-of-magnitude more economic damage than they capture in payments, with attacks like Jaguar requiring a $2 billion government loan after operations went down for one to two months.
- ✓Detection Gap Economics: Current cybersecurity relies on static rule-based monitoring systems that generate excessive false positives because suspicious behavior often mirrors normal activity. Digital forensics investigations that deeply analyze evidence can distinguish real threats but remain prohibitively expensive, with only 60 investigators at CrowdStrike capable of performing this work. This creates a paradigm where deep investigations only happen reactively after breaches, missing most attacks that go undetected for extended periods.
- ✓AI Capability Threshold: Off-the-shelf language models already achieve approximately 90% accuracy on email-based compromise investigations without specialized training, but the final reliability gap requires human oversight for production deployment. Asymmetric uses human-AI teams where agents perform first-pass analysis and investigators conduct quality control, building proprietary datasets from real incidents to close performance gaps. This services-first approach through insurance company partnerships provides both customer trust and the data flywheel needed for model improvement.
- ✓Defensive Asymmetry Opportunity: Digital forensics specialists who investigate breaches do not typically become skilled offensive hackers, suggesting limited skill transfer between defensive investigation and offensive exploitation. This contrasts with domains like penetration testing where capabilities are inherently dual-use. The separation creates an opportunity to differentially accelerate defensive AI capabilities through specialized datasets, evaluations, and training environments without proportionally advancing offensive capabilities, though this window closes as models achieve broader generalization.
- ✓Jagged Frontier Strategy: Reinforcement learning creates predictable capability improvements in domains with verifiable rewards like coding and math, but lags in areas lacking clear evaluation signals. Organizations can intentionally shape the AI capability frontier by curating specialized datasets, building realistic environments, and developing high-fidelity evaluations in strategically important domains. This approach could be replicated across biosecurity, AI safety, and other areas where hardening defenses matters, but requires subject matter experts willing to encode their expertise into AI systems.
What It Covers
Alexis Carlier, founder of Asymmetric Security, explains how his company automates digital forensics investigations using AI agents to detect cyber breaches proactively rather than reactively. He describes the current threat landscape from financially motivated criminals to nation-state actors, details how AI models achieve 90% accuracy on forensic tasks, and argues digital forensics represents a defensible domain for differential acceleration.
Key Questions Answered
- •Threat Actor Hierarchy: Approximately 80% of cyberattacks come from unsophisticated criminals using spray-and-pray tactics, while nation-states like China focus on IP theft from R&D-heavy industries and North Korea runs remote worker programs where operatives infiltrate Western tech companies to earn salaries funding the regime. Ransomware gangs occupy the middle ground, causing order-of-magnitude more economic damage than they capture in payments, with attacks like Jaguar requiring a $2 billion government loan after operations went down for one to two months.
- •Detection Gap Economics: Current cybersecurity relies on static rule-based monitoring systems that generate excessive false positives because suspicious behavior often mirrors normal activity. Digital forensics investigations that deeply analyze evidence can distinguish real threats but remain prohibitively expensive, with only 60 investigators at CrowdStrike capable of performing this work. This creates a paradigm where deep investigations only happen reactively after breaches, missing most attacks that go undetected for extended periods.
- •AI Capability Threshold: Off-the-shelf language models already achieve approximately 90% accuracy on email-based compromise investigations without specialized training, but the final reliability gap requires human oversight for production deployment. Asymmetric uses human-AI teams where agents perform first-pass analysis and investigators conduct quality control, building proprietary datasets from real incidents to close performance gaps. This services-first approach through insurance company partnerships provides both customer trust and the data flywheel needed for model improvement.
- •Defensive Asymmetry Opportunity: Digital forensics specialists who investigate breaches do not typically become skilled offensive hackers, suggesting limited skill transfer between defensive investigation and offensive exploitation. This contrasts with domains like penetration testing where capabilities are inherently dual-use. The separation creates an opportunity to differentially accelerate defensive AI capabilities through specialized datasets, evaluations, and training environments without proportionally advancing offensive capabilities, though this window closes as models achieve broader generalization.
- •Jagged Frontier Strategy: Reinforcement learning creates predictable capability improvements in domains with verifiable rewards like coding and math, but lags in areas lacking clear evaluation signals. Organizations can intentionally shape the AI capability frontier by curating specialized datasets, building realistic environments, and developing high-fidelity evaluations in strategically important domains. This approach could be replicated across biosecurity, AI safety, and other areas where hardening defenses matters, but requires subject matter experts willing to encode their expertise into AI systems.
- •Distribution Through Insurance: Asymmetric enters the market through cybersecurity insurance carriers rather than direct enterprise sales, getting approved on insurer panels that dispatch incident response vendors when policyholders get breached. This distribution model solves the trust problem inherent in cybersecurity where effectiveness is difficult to assess, following the CrowdStrike playbook of starting with services to build relationships and data before productizing. The approach reduces investigation time from two days to one week down to a few hours.
Notable Moment
Carlier reveals that most technical vulnerabilities exploited in cyberattacks are known issues that organizations simply have not patched, rather than sophisticated zero-day exploits. Attackers consistently choose the path of least resistance, with social engineering and phishing comprising 70 to 80% of attack volume, because there is no reason to burn valuable unknown vulnerabilities when a convincing email works just as effectively.
You just read a 3-minute summary of a 73-minute episode.
Get Cognitive Revolution summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from Cognitive Revolution
Babysitting the Machine: Glean's Rebecca Hinds on the Hidden Human Labor of AI at Work
Jun 10 · 106 min
Invest Like the Best with Patrick O'Shaughnessy
William Hockey - Building the Operating System for the Dollar and Silicon Valley Heresy - [Invest Like the Best, EP.463]
Mar 17
More from Cognitive Revolution
AI in the AM — Week 1 Highlights (June 2026)
Jun 6 · 82 min
20VC (20 Minute VC)
20VC: Nebius Co-Founder on AI Infrastructure Bubbles | The Real Impact of Open Source on OpenAI & Anthropic | How Price Elastic is Demand for Compute | Could Nebius Sell 10x More Compute If They Had It & more with Roman Chernin
Jun 8
Books, tools, and gear mentioned in this episode
SignalCast may earn commission on purchases via these links. As an Amazon Associate, SignalCast earns from qualifying purchases.
Tools
“SPONSORS: Granola (granola.com)”
“SPONSORS: Blitsy (blitsy.com)”
“SPONSORS: Tasklet (tasklet.ai)”
company
“This services-first approach through insurance company partnerships provides both customer trust and the data flywheel needed for model improvement. This approach could be replicated across biosecurity, AI safety, and other areas where hardening defenses matters, but requires subject matter experts willing to encode their expertise into AI systems. The approach reduces investigation time from two days to one week down to a few hours, following the CrowdStrike playbook of starting with services t”
“Alexis Carlier, founder of Asymmetric Security, explains how his company automates digital forensics investigations using AI agents to detect cyber breaches proactively rather than reactively.”
More from Cognitive Revolution
We summarize every new episode. Want them in your inbox?
Babysitting the Machine: Glean's Rebecca Hinds on the Hidden Human Labor of AI at Work
AI in the AM — Week 1 Highlights (June 2026)
Nested Learning: Ali Behrouz on the Quest for Continual Learning & Illusion of AI Architectures
Inside Nathan's Second Brain: Daniel Miessler, Security Expert & Creator of PAI, Audits My AI Setup
Your Biggest Lever: Designing your AI Career for Maximum Impact, with 80,000 Hours founder Ben Todd
Similar Episodes
Related episodes from other podcasts
Invest Like the Best with Patrick O'Shaughnessy
Mar 17
William Hockey - Building the Operating System for the Dollar and Silicon Valley Heresy - [Invest Like the Best, EP.463]
20VC (20 Minute VC)
Jun 8
20VC: Nebius Co-Founder on AI Infrastructure Bubbles | The Real Impact of Open Source on OpenAI & Anthropic | How Price Elastic is Demand for Compute | Could Nebius Sell 10x More Compute If They Had It & more with Roman Chernin
Eye on AI
Jun 6
Every Enterprise Is About to Have a 100,000 Agent Problem | Oren Michaels of Barndoor AI
This Week in Startups
May 27
The Drone Company Quietly Taking Over Delivery
Latent Space
May 20
Railway: The Agent-Native Cloud — Jake Cooper
Explore Related Topics
This podcast is featured in Best AI Podcasts (2026) — ranked and reviewed with AI summaries.
You're clearly into Cognitive Revolution.
Every Monday, we deliver AI summaries of the latest episodes from Cognitive Revolution and 192+ other podcasts. Free for up to 3 shows.
Start My Monday DigestNo credit card · Unsubscribe anytime