Cyber Business Podcast

The Security Sidecar: Wrapping Code in Real Time Defense with Aby Rao - Ep 237

Written by Matthew Connor | Sep 15, 2026, 11:14:59 AM

Aby Rao is the Deputy CISO at Paylocity, where he leads a wide ranging cybersecurity operation protecting customer data across the company's SaaS platform. With 16 years in the field, Aby has built his approach around a clear hierarchy, talent first, then process, then execution, and now layers AI on top of that foundation to accelerate everything from new hire onboarding to vulnerability detection. He joins the show to talk about using AI to compress a year of business knowledge into two months, where voice agents belong and don't belong, and why he thinks the era of easy ransomware money may be closing. 

 



Here’s a glimpse of what you’ll learn: 

 

  • Why Aby built his security program around talent first, then process, then execution
  • How Aby uses AI to help new employees understand the business in two months instead of a year
  • The three layer framework Aby uses to turn scattered documentation into usable knowledge
  • Why Aby believes voice agents work well for routine calls but not yet for 911 or crisis situations
  • How Aby's security sidecar concept wraps every piece of new code with a business agent and a security agent
  • Why Aby thinks patch management alone can no longer keep pace with how fast code ships today
  • Why Aby believes the current window of easy ransomware profits may be closing because of AI


In this episode…

Aby opens by explaining how he approached his first years at Paylocity, prioritizing talent above everything else before layering in stronger processes and only then focusing on execution. He argues that AI now accelerates a step organizations have historically underinvested in, getting new employees up to speed on the business itself, and describes a three layer method for doing it: starting with public domain research, moving into technical documentation stored in tools like Confluence or ServiceNow, and finishing by validating that knowledge directly with business contacts. He believes this kind of onboarding, which traditionally took a year, can now happen in as little as two months.

The conversation turns to where AI agents genuinely belong in customer and public facing interactions. Drawing on his graduate background in human computer interaction, Aby argues that voice agents handle routine, low stakes requests well, but that situations involving physical risk, like a 911 call, still require a human who can read sentiment and respond with genuine urgency. He is candid that AI is not there yet on the emotional and contextual judgment those moments require, even as he agrees the underlying technology is improving quickly, drawing the same comparison to early self driving cars that has come up elsewhere in the series.

The back half of the episode focuses on where Aby thinks security is headed structurally. He describes a concept he calls the security sidecar, wrapping new code with two agents working in real time, one representing business logic and one representing security expertise, rather than relying on after the fact log review. He connects this to a broader argument that traditional patch management can no longer keep pace with organizations shipping ten releases a day, and that the real answer is AI monitoring systems that catch abnormal behavior the moment an intrusion happens, regardless of which vulnerability let it in.

 

 

Resources mentioned in this episode

 

Matthew Connor on LinkedIn
CyberLynx Website
Aby Rao on LinkedIn
Paylocity Website
Darktrace Website
Abnormal AI Website

 

Sponsor for this episode...

 

This episode is brought to you by CyberLynx.

CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.

We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.

Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.

 

Check out previous episodes:

 

Doing More With Less: A Department of Three Punching at Twenty with Tony Bryson - Ep 236

The Age of Human Judgment, Not the Age of AI, With Benny Zhang - Ep 235 

Why Patch Management Is No Longer Frontline Defense with Brett Price - Ep 234

 

 

Transcript: 

 

 

Cyber Business Podcast

Guest: Aby Rao, Deputy CISO at Paylocity Host: Matthew Connor

Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Aby Rao, Deputy CISO at Paylocity. Aby, welcome to the show.

Aby Rao: Thank you, Matt. I'm really excited to be here.

Matthew Connor: We're excited to have you. Before we get too far in, a quick word from our sponsors.

Sponsor Break — CyberLynx: Hackers are using AI to conduct machine-speed attacks. Is your security keeping up? CyberLynx sells industry-leading AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. That's cyberlynx.com.

Matthew Connor: And now, back to our show. Aby, for those who aren't familiar, can you tell us about Paylocity and your role there as Deputy CISO?

Aby Rao: Yeah, I'm a senior cybersecurity leader at Paylocity. I've got a fairly wide-ranging operational role there, you can think of any cybersecurity domain and we're actively working on it. I've got a very solid team that supports me in that objective and goal of protecting our customer data and making sure our SaaS product is safeguarded from cyberattacks.

Matthew Connor: Well, that's a pretty big job, and I think you're a pretty big target too. So how is it that you sleep at night? I mean, the guys at Chase, it's some astronomical sum they're spending, I think it's fifteen billion dollars a year they spend on cybersecurity alone, which, good on them, they've got the money, and they're a big enough target, they get more hits than the United States government does every day from hackers trying to get in. So I'd imagine Paylocity is very similar, you're kind of a big target too. How do you sleep at night? It's a stressful job, being in charge of that sort of defense.

Aby Rao: Yeah, no, I mean, I've been doing this for sixteen years, Matt, so I'll figure out the best sleeping pill I can find on the market. But jokes aside, I think it boils down to having really strong talent. You cannot emphasize enough how important it is to build the right team, and if it takes you a couple of years to get there, so be it. Finding the right talent with the right approach and agency to develop and deliver outcomes is super important, and that's what I focused on in my first couple of years. I feel like talent forms the foundation of any strong team, in any organization. The second piece is strengthening the processes, I can't emphasize enough how critical velocity is, and the value you need to build through strong processes. So once you have the people layer figured out and you build the right processes to engage with the business, then comes the execution part. That's how I focused on developing a fairly strong team. And again, I wouldn't claim we've reached the optimum state yet, but we're in the process, and with the advent of AI, it's just going to help us get there sooner. So I'm super excited about the kind of work we do, but it's really important to ensure you risk-prioritize on a daily basis. Otherwise, as you said, you can have a hard time falling asleep. It's really important to underline what's important to your business, what's important to you as a leader, and then reduce the noise around it and pick up the right signals.

Matthew Connor: Yeah, but you said a few things I think are really exciting and fun, because I couldn't agree more. Historically it's been about the people, right, people and process, those are just foundational and fundamental, and it's surprising how many people get that wrong, at any size organization. To me that's one of the fundamentals everybody should be focusing on, I suppose two of the fundamentals everybody should be focusing on. But I think what's really interesting is when you look at people and process, in the past that was so important on its own, and now you layer in AI and being able to leverage that, and what I'm seeing, and I'm curious from your perspective, let's take level-one help desk people, entry-level jobs, whether it's help desk or otherwise. Now somebody with a basic understanding and very little experience, with the assistance of AI, becomes supercharged and superpowered, they have such an easier time growing and performing than they did without it. I mean, any problem now, it used to be, without Google, you just needed experience, and if you didn't have it, you needed to ask somebody. Then Google comes along and you can look up and search and find stuff, great. Now that AI is here, it's amazing the effect that has on speeding that up for people to get to the solution they really need. So as you go up that ladder from entry level all the way up, having seen pre-AI and now post-AI, what kind of benefit are you seeing throughout your team?

Aby Rao: Yeah, I think AI is fairly strong and there's absolutely no denying that aspect. But one thing I feel like we don't talk about enough is business engagement. Whether it's AI or not, I feel like the strongest leaders are the ones who understand the business really well and have the right engagement with the right influencers within the business. So once you combine that business context with AI tooling, you really develop something extremely potent and strategic, because the business is growing, it has its own velocity, its own growth areas. Now you combine the AI aspect, which helps you deliver, gets you to a place no one else will. AI is fairly democratized at this point, anyone can go get AI tooling, but that business context, business data, business strategy, that's very centric to employees within an organization. So you get into a very unique area where you're overlapping business with technology and then delivering value, I think that's where the sweet spot is for strong delivery.

Matthew Connor: I couldn't agree more. And I think a lot of the challenges, the reason so many people fail, or get a bad impression of AI and its abilities, is they treat it like it's supposed to be an all-knowing, all-seeing solution provider, and that simply isn't the case, right? It depends on the context. If you don't understand the business, and you don't understand the task, and you ask it to solve the problem, well, you didn't understand how the problem fits into the business, so how do you expect it to somehow understand all of that and then produce the right solution? So this leads me to an interesting situation, I think, and I'm an AI optimist, and I think you are too, but I think what this ends up doing is, instead of replacing human thought and humans in the equation at all, I think it really starts to highlight how important the human is in relating to other people, in being a part of the business. And then AI is this tool that allows them to become that much more effective. Because I don't see it really replacing people for the most part, I see it supercharging people, I see that being a huge benefit, no matter how great it gets, at least until we ultimately get to some crazy level of AI, if that day ever comes. But prior to that, I think we're living in this day and age where when you provide it enough context, and you understand your business well enough, you get the greatest output and greatest assistance from it. I think that's where it is, and I think it becomes this helpful tool that people often misunderstand or misuse.

Aby Rao: Yeah, and to add to your point, I think the part that really excites me about AI is the acceleration and the possibilities it brings. I'll give you one example. Whenever a new employee joins the organization, it takes them a good year to understand the business and the key drivers of the business, and usually one attains that by reading documentation, meeting people within the business, building that relationship. Now you can accelerate that, you don't have to wait a year, you can tap into the right knowledge stores, whether it's human or data, and get there in two months' time, or even less than that. I think that acceleration piece, if you can tap into it, just speeds up the way you can achieve your objectives in a short period of time, and I don't know if there's enough focus on that. We often put people through training and introduce them to the right influencers within the business, but how do you tap into that, and how do you store it? I think that's the part one needs to really hone in on, and same thing with someone who's been in the business for a while, what are the drivers, how are we being influenced by external competition, what kind of benchmarking are we doing today with our competitors? I think some of that intelligence didn't exist as much before, or it wasn't as accessible. With AI it becomes a lot easier, and you can build things very quickly, which is what I've been focusing on in the past few months, this builder, operator, and distributor mentality, where you take on the agency to do things yourself, you don't wait on the cavalry to show up to help you with whatever the next thing is you want to build. That's been my focus within this space.

Matthew Connor: Well, I think that's a really brilliant idea, and I haven't actually heard anybody really talking about accelerating that learning curve for new employees. Can you walk us through that a little bit, more on the actual nuts and bolts of it? I get it conceptually, but where the rubber meets the road, how do you make that happen? What information, how are you tying it together, how does that actually work to reduce that learning curve for new employees?

Aby Rao: Yeah, that's a great question, and the way I think about it is in three different layers. Layer one is understanding the business at the public domain level, something you can look up, Google searches, whatever easy-access data you have, you start there, but that's public, that's easy to find, anyone can do that. The next layer is the technical documentation behind your services and product. In the case of a SaaS company, most SaaS companies do a really good job documenting their product and making sure it's private enough for employees to gain access. That's a key indicator of where you need to focus, on that technical documentation. And if you build the right connectors with this documentation, I'll give you one specific example, Matt: Confluence, or the Atlassian product suite, or the ServiceNow suite, these are some really good knowledge stores. There's a lot of information in there, it may not be as structured as you'd like, but that's when AI comes in, that's when the unstructured data becomes a lot more defined, and turns data into knowledge, and then into wisdom. I think that's the part you need to really hone in on. And then the third piece is the people connection piece, once you collect this technical documentation and business documentation, now you need to validate and vet that information with your business leaders, with your business contacts. If you can build this triad and focus on wrapping your head around your business, that's going to really elevate you within the first few months of your employment. So that's how I'd do it if I were to start again, really understand where the knowledge stores are, it could be support tickets, it could be a public knowledge base that our customers have access to, all of that is golden. Just bring that together and synthesize it, it adds value to the way you'll operate in the future.

Matthew Connor: Yeah, no, that's a really good point, because you look at things like ServiceNow, that's large and complicated, there's a lot to it. And I think on the documentation side it can be really overwhelming for somebody just getting into it. So if you're fresh to the organization and fresh to getting up to speed on that, you're right, that's like a year-long process to get there. But now with AI, because it is so kind of unstructured, it's all there, just go get it. But now, going and simply using AI and asking for that tutorial, run me through it, what do I need to know, who should I talk to, what do I do, for these things to really get up to speed so much faster than going through hundreds or thousands of pages of documentation.

Aby Rao: No, that's brilliant, and I don't think people are really doing that. I think that would be brilliant, day one of joining a company, first day there, it's time to start asking AI, show me around the place, what do I need to know, how do I succeed in this job, versus asking your boss, who's like, yeah, yeah, take a look at this, have these, but I can't hold your hand the whole time, I need you to get up to speed. And then you're waiting six months to a year for them to get up to speed, which is totally normal, right?

Matthew Connor: Yeah.

Aby Rao: But now this is classic agentic AI use case. I think AI chatbots are great if there's one knowledge platform and you ask questions and derive value from that. Agentic AI opens up this whole new universe, where let's say your organization has ten different knowledge stores, that's when you activate these agents to be your extensions. And that's the part I feel is going to grow over the next several months, the ability to connect and extend yourself beyond your capabilities, and derive, suck in information that's of value to you, orchestrated at such a level that you're able to dwindle noise down to signal. You just want to be focused, because it can be overwhelming. So yeah, I just wanted to drop that in here, it's like, how do you achieve this ability to be multifaceted and multipronged so you can bring in the information? Agentic AI, in my opinion, is the answer.

Matthew Connor: I think that's spectacular, and such great advice for the organization and for each individual in it as well, that's just great advice. And while we're on the topic, I think that when you're looking at AI now, whether it's agentic or generative, the bad guys are leveraging this too. And I think, and this is for me where it gets really exciting, not because bad guys are leveraging it, but because they are, there's this heightened awareness, I think, in every organization, that the bad guys have gotten so much better. No longer is it the poorly worded email from the Nigerian prince or whatever, I don't think anybody's falling for that now. They're phenomenal emails that look perfect, they look like they came from somebody, and often they do come from somebody you know, and it's all done first-rate thanks to threat actors leveraging AI. And I think this is where we get into some really cool things on the defense side of things for the good guys. You see products like Darktrace leveraging machine learning, a form of AI, to be able to see these things and understand that this is an anomaly, this email, while it's legit, is actually dangerous, and can take care of that so much faster and better than our traditional tools, whether it's email, network, or endpoint. Traditionally, setting up those filters, we've seen how that works, right, we know that's never been a great solution. Let's just stick with email for a second, it's never been a great solution, it was what we had. And now I'm really excited that we're starting to see products like Darktrace and Abnormal Security on the email side, because I think the end user, Jimmy or Jane in accounting, they're great at accounting, they're not great at IT, and no matter how much, and this is a hot button, people will disagree with me all day on this one, but no matter how much we try to train an accountant to be good at cybersecurity, they're not going to be good at it, they will always be the weakest link. So I think this is where AI comes in and levels that playing field, to where it shouldn't be their job anymore, it should be our job, as cybersecurity professionals, and we're now starting to get tools that allow us to take that responsibility away. And again, people are going to totally disagree with me on this one, but I think the day is coming, I think we see glimmers of this in products like that, where you see, oh wait, if we're so much better now with email, we're so much better now with network and endpoint, that it doesn't make sense even to be training, because no matter what we train them on, they won't be as good as the AI will be, so it just takes it out of there. So why are we even training anyway, hot take on that. I know people would disagree, but I get excited about that stuff because I think it's where we're headed. I'm curious what you think.

Aby Rao: No, I agree, because my philosophy around this is, you've got to fight AI with AI. So when we talk about cyber attackers, there's some element of AI usage that they're activating, and we have to get better at that. And we can get better at that because we understand our business, we understand the tools we need for our business, and we have some of those tools already. So how do you ensure there are layers of protection built in? I think what you were alluding to was more the business email compromise set of things, where our employees get hit with very sophisticated emails, which can compromise. So how do you add layers there, how do you activate AI agents at that level, and help our employees be that second voice that helps them make decisions? I think the decision-making aspect of AI isn't talked about as much, and what's important in this particular context is that decision-making at the right moment, within the right context. That's what we need to ensure is enabled, for our employees and even our customers. Right at that moment, how do you help them make that decision, how do you show the risk of clicking a button, or downloading something? If we can bring that to them at that moment and help them make that decision, I think that's a big win, because that's the piece that's missing right now. We do a lot of detective work, this is what you did and this is what happened, and we do full-on investigations, but that moment of decision-making is where we need to tap in and perhaps use AI for that.

Matthew Connor: Yeah, now I think you're spot on, and I look forward to seeing how this plays out, because as we see AI develop, it's been so rapid over the last less than four years now since ChatGPT hit the market, and the improvement has been incredible, and where we are today, at the end of August 2026, is incredible, and where we'll be in August of 2027, we'll dwarf where we are now. But with AI, and we see some really cool tools, it always leads us to this question of the balance between AI and humans. So I'll throw something out there for you, let's talk voice agents. Using a voice agent calling into an organization, where historically you'd call some big company, let's say United Airlines, you want information on your flight or to change your reservation, historically it wasn't great going through the traditional phone tree, trying to get to a real person, trying to get to an agent who could then help you. And now we're starting to see really sophisticated and realistic-sounding voice agents that can actually, through API, tie into your organization's systems and provide real service and solutions very rapidly. So I'm curious your take on that, and I think really where the human interaction portion comes from, because I get it on the tech side, I think it's the greatest thing ever, but I think we always have to balance that with the user's reaction. Is this something people enjoy, and does it provide a benefit? Or is it one of these things where people are screaming "agent, agent" at the AI agent, and it's like, I am an agent, so what's your take on this, where do we fall, is it moving in the right direction, or is this one of those things where we're relying too heavily on it? What's your take?

Aby Rao: Yeah, I do want to activate my experience in human-computer interaction, HCI, that's something I was very passionate about when I went to grad school. I think it depends on the context, Matt, it really matters under what circumstances you're engaging with this voice agent. I think for some low-hanging fruit, which I think sixty to seventy percent of these calls are, it's like, hey, tell me what the balance of my account is, or can you explain these fees you applied to my savings account, I think those are some pretty straightforward use cases for a voice agent. I think where it gets complicated is when there are physical aspects at risk. You make a 911 call, do you want to interact with an agent? Probably not, again, it depends, I think the very first layer could be, hey, can you tell me a little bit more about my local police station, yeah, that's okay to have an agent, but you have to really quickly pivot to a human who can gauge your sentiment, gauge your situation a lot better, and make sure they activate the right services for you. So in most cases I feel like, yes, voice agents will do a really good job, but thinking of it as a human and the cognitive load you may be going through during certain situations, you need a human to interact with, and have that very quick response and very contextual and sympathetic response as well, and that sympathy aspect, I'm still not sure if AI agents are there yet. Voice agents, I know it's moving in that direction with the whole sentiment analysis science behind it, but that's one area. The other area, Matt, where I feel there's value is multilingual agents, with us being global in nature, calls end up in other countries, people within this country speaking multiple languages, can agents pivot quickly to different languages? I think there are some really strong use cases, but there are some time-sensitive and physical-protection scenarios where we might want to have people deal with it. So yeah, I agree with you partially, but we have to put it in context.

Matthew Connor: No, I think you're right, and I think that becomes really important, because there are obviously situations where you want that human interaction, that's why you're calling, right? If you call your, I don't know, you call your lawyer and want to talk to them about your case, you don't want to be talking to their AI agent about your case, that doesn't, you know. However, when you said 911, that's actually a really interesting one, because I'm not sure on that one, and here's why, I think that timing is critical. And while the AI agent can answer the phone, maybe not today, I don't think we're ready for it, but I think at some point in the future it may make sense, in that the second they call in, even if there's a language issue, a foreign language, you can easily identify that, now there's no need for a translator. But on top of that, when it's an emergency situation, instead of putting them on hold and dispatching, that can happen at the same time, literally as that's happening, things can already be processing without it slowing down, because a human can only say one thing at a time, right, can only speak, I can speak to you, but I can't speak to two people and have two conversations at once, whereas the AI agent absolutely can. So in those time-sensitive situations, I could see there being an advantage there. You know, when AI gets to the level where it fully understands, we're not there yet, right, there's still a lot of things where it's not going to make the right decision, this is life and death, we're not at that stage. But if you look at self-driving cars, five years ago it drove like a drunk toddler, and it was not safe, and now today they're eight times safer than the average human driver, and that's really clear, and having experienced that transition, I can see this playing out in other aspects. I think this is a really great analogy, it helps to see where other parts of AI will be beneficial. Like maybe it is a 911 agent at some point, where it's like, yeah, obviously I want AI to do it, because it's going to be so much faster at dispatching, it won't get emotional. And maybe we see that like in air traffic control, right, right now that's a really difficult, challenging job, it'd be great if that were AI-powered as well at some point in the future. I think these are things where right now it's crazy talk, like this is life and death you're talking about, but so is driving, driving is probably the most dangerous thing we do, and we do it all the time, and people die every day from it, it's a very dangerous thing, and yet now AI has quickly become safer and better at it than us. So I don't know, interesting.

Aby Rao: Yeah, no, I mean, you've got a fair point in terms of where we are within the maturity life cycle, it may seem early, but it's looking positive. I think that's something that will feed into physical AI as it grows over time, robots, or quasi-physical AI, combining voice agents with robots. I think there's a lot going on within that space, and it's just a matter of time. And the other aspect we didn't talk about, Matt, is comparing it to our existing data. Do we have challenges with 911 responders today, hiring them, do we have twenty-four-seven coverage, what's their performance today that we can improve upon with the help of AI? When you compare AI versus human, maybe there are some data points that emerge that tell us a different story. So, a fair point about where we are within the life cycle.

Matthew Connor: Yeah, well, you mentioned robots, and I can't help but wonder, I mean, I think we're seeing, as xAI is developing their humanoid robot, I think that's going to be so profound in so many ways, right, in terms of, let's say, elderly care. If you're in your eighties and nineties, so much better to have a robotic assistant to help get you out of bed, help do all of the things. Same with personal security, how great to have a robot in your house that can keep you safe. I mean, I think the effect that has, let's not discuss the whole jobs aspect of it, but in a future where everybody had their own personal robot, let's just play science fiction here for a second, or not even science fiction at this point, right, fast forward a couple of years into the future, now everybody's got their own personal robot that can keep them safe, can help them when they need it, whatever it may be. What does that do in terms of society as a whole? I mean, you're not getting mugged, you don't have to worry about your house being broken into, does that reduce crime to the point where we're in this kind of amazing future where domestic violence is virtually nonexistent, homicide rates are almost zero? Is that the kind of future that having ubiquitous robots produces?

Aby Rao: Yeah, no, that's a fair point. Another area I'm very keen to dive into is responsible AI practices. As we progress towards engaging with robots and giving them more agency over time, how are we dealing with data, what's going on behind the scenes when it comes to ethics and transparency? As long as we march together on these two spaces, velocity of AI innovation coupled with responsible AI, I think we should be okay. It's just the piece that, when we're collecting so much information, and it's either distributed or hosted centrally, questions arise, how is this data being used, what's the future of this data, what kind of mining are we doing to prevent these things in the future, and it brings it back to the cyber attackers, how can they tap into this and derive value for themselves? I think these are the areas that, as much as we want to move in the right direction of human enhancement and augmenting human life, you also have to think about how do we ensure it's safe and secure from a data privacy perspective.

Matthew Connor: Couldn't agree more. And it's interesting, because we're starting to see some products coming out from manufacturers that are focused on that, as well as how do you govern your AI agents? And so, not to harp on Darktrace again, but they've got their new agentic AI safeguards, watching and guarding your agents. Obviously, a lot of these products, when they come out, you're like, yeah, obviously that's what you want, obviously we want AI watching AI and helping us govern it, because there's so much kind of black-box activity with AI, an AI moves so quickly, it's really hard for us to put on the guardrails, keep it. And we've seen it, when AI is put into a sandbox and tested, it finds a way out, because we're not good at it, and we don't find out that it got out until later. So it moves too fast, it thinks too fast, it's not an animal we can easily cage on our own. So it only makes sense that we'd be using AI to secure our AI, and I think we're now starting to see that, and I think that will be the future, how do we leverage AI to contain and safeguard, put the guardrails on, do proper governance, because it's challenging for humans, well, it is, it's just hard for us to think in all those terms, and at that speed. And then we find out, oh crap, it got out of the cage and now it's eating the neighbor. Okay, well, that's a caged animal that you're just not well equipped to handle, and I think that's where a lot of the fear comes from for people, well, this is a very powerful beast, are we really capable of containing it? So I think the answer is in AI containing AI, a product that can monitor it, put guardrails on it, it's not, I don't think we can use traditional methods alone to contain it, because it will be creative and find ways out of the cage we put it in.

Aby Rao: Yeah, and to your point, you made a statement about black box, you're absolutely right, so far it's been fairly proprietary in nature, the way it operates on the back end, but I think that's where the focus is today, it's about being more open, and that gave rise to open-weight models and ensuring there's transparency around how operations take place. As AI grows and we utilize it, I think it becomes really important to understand the inner functions of how it operates, something we can play with and ensure it applies to our use cases. So I'll be very curious to see how these open-weight models proliferate over the next few months, and how much ability we have to tweak and maneuver it to our needs, that's something I'll be watching very closely. But yeah, I don't feel very comfortable using phrases like black-box model as a security professional, because that's ripe for hacking, that's ripe for compromise. So if we can move in the direction of being more transparent when it comes to inner functions, that'll put us in a better place.

Matthew Connor: Well, that's interesting, because historically, that's the whole premise behind open source, the idea being that if it's open, and obviously everybody gets the idea here, Matt, okay, but indulge me for a second. If the idea is that it's open to everybody, so you can clearly see it, the reality is so few people have the time and expertise to really dive in and understand what's going on, right, you're talking about millions of lines of code, it's very complicated. Conceptually I want to have access to it, practically that doesn't make any sense, because I don't have the time or the expertise to really dive in and become an expert in one product, especially now that we have tons of products. However, I do think this is where AI comes in, because AI can then quickly go in, see these things, and be like, oh, this is a problem. So I think in the future, with AI helping us secure things, the open model makes a lot of sense, because we can then use AI to say, hey, go ahead and look at this, tell me where my vulnerabilities are, where my data is actually being stored, look for security issues, all kinds of great things. Right now, the closed models don't really allow us to do that, because they don't want to be used by the bad guys, so the problem is that's a double-edged sword, if the bad guys can't use it to find ways in, the good guys can't use it to secure it either, it becomes a challenge. Then you've got to get on a list with Anthropic to be one of the fifteen companies that get to use it. But it's really interesting, because I think that's where we need AI, we need to be able to say, hey, I need you to examine all of our software, I need you to examine our network, I need you to find the holes before the bad guy does, I want you focused purely on us, because the bad guys will be focused on everybody, they'll find one vulnerability. So I think, and that goes back to your open-model premise, it won't have those guards that Anthropic and Gemini are going to put on it, because they don't want it used by bad guys. But then does open source become the Wild West, where the bad guys and the good guys, or is that really just what we need, a level playing field that's open, so both good guys and bad guys can be using it, and the good guys win because you're focused on your organization, you're leveraging all the AI you can to secure it, and good luck bad guys, because my guys are working twenty-four-seven on our stuff, and you're working on the whole world, so we'll win strategically. Kind of curious what you think.

Aby Rao: Yeah, I mean, having that level playing field is how I'd approach it, and let me explain that from a cyber defender perspective. If you give us enough bells and whistles and knobs and levers to work with, I'm going to design my solution with the layers of controls I need to protect my data or services. I think that's the part I'm fairly excited about, what levers and knobs I can move in order to build the kind of structure I'm looking for, which some of these frontier models don't offer today. I mean, they're moving in that direction, but if you look at it inherently, they don't have adequate security controls I can activate. But if you give me those options, I'll come up with a fairly strong solution that will not only protect the way we're using our tools, but how we can forecast in the future as well. That's the part that gets me excited, and it's totally up to me to build that design that's centric to my business, and then challenge cyber attackers, and evaluate that, even before I challenge cyber attackers, using AI-detected vulnerabilities, that's the space I'm going to tap into. So imagine you're given this open-ended solution, you can just open and close doors as needed, I design my solution, I architect it, I bake in those controls, then I add a layer of AI-enabled vulnerability testing, see where my vulnerabilities are, see what the compromise points are. Now, once that's in place, it becomes a lot stronger solution that I can control when there's a cyberattack. But if you give me something that's fully baked, and I have like three things I can enable or not, that just prevents me from taking it to the next level.

Matthew Connor: Yeah, well, and you look at, you mentioned vulnerability, so vulnerability management historically was, okay, great, Patch Tuesday comes along, we're patching everything, we're fully patched, and now we're good. Well, clearly that doesn't work in today's day and age, because now there are more zero-day exploits than ever, AI is finding things that have sat around unprotected for many years. So patching by itself isn't the full solution anymore. And so I look forward to vulnerability management being an AI-powered thing, where it's finding those vulnerabilities much, much faster, finding holes in walls we thought were secure. And I think that's going to be the future, and I don't think it goes purely on the manufacturer, and it's great that it should, they should be using AI to secure their products, and we're early days, but I think while they do that, it'll be really fantastic for us to be able to look at our own products and services that we're using and say, okay, yes indeed, I feel good that that's secure. Because right now, since the dawn of software, we've just been trusting that the manufacturer is doing their job, and by having their hackathons, having people come in and try to punch holes in it, that was good, right, it did, you were incentivizing great people to come and try to poke holes and find holes, great, makes perfect sense. But in today's day and age, AI is far superior at finding those vulnerabilities. So again, double-edged sword though, right, if we get to do it, the bad guys get to do it as well. But I think that's where the playing field gets leveled, and we ultimately win, because if we're using the same tools and we're able to find the vulnerabilities and patch them, they're not able to exploit them. And I think ultimately this helps the good guys win, not the bad guys, but I am an AI optimist, so.

Aby Rao: Yeah, no, I mean, you're right on track. And one of the comparisons I want to offer is, if you talk to AI developers, they're very excited about pushing code more regularly. In the past, before AI, fifteen years ago, when I spoke to developers, they were like, we can do a quarterly push, a release every quarter, and that's fast-track, it takes a lot longer. And then they moved to a monthly timeline, a release every month, and that was mind-blowing, I was like, this is exceptional, people got promoted for that kind of stuff. But now they're having ten releases a day. And if I look at my developer friends, it's like, if you're pushing out ten releases a day, ten updates a day, why can't I keep up with that velocity from a patching perspective? Why isn't patching just in time, why can't I meet your pace so we can keep our code secure? I think that's how I want to think going forward, if they can do it, why can't we, what are we lacking today that will help us get there? I haven't solved this yet, Matt, but that's a thought I always have, how do we keep up with that velocity on the code push, because I'm sure they're pushing out vulnerabilities as well, as part of that.

Matthew Connor: So then is the solution not in the patching itself, but in the future of vulnerability management, having AI security products that are monitoring the network, the endpoints, all of the SaaS products, to say, oh, I see this, this is a problem, I don't know how they got in, and it doesn't matter how they got in, the fact of the matter is I immediately caught that this is now acting abnormally, I'm going to stop it and call an adult, because at the end of the day, I don't care, you could tell me the software and the firewall and all the hardware is fully patched and fully secure, great, but the only thing that matters is that a bad guy got in. So no matter how they found their way in, whether it was social engineering, so great, we got a back door, right, that's always been a problem, users are always leaving the back door unlocked and open, and the bad guys come in there, or they found a zero-day exploit in some software, I don't care how they got in. What I think the future is, or I'm going to propose, is a future where AI is monitoring every bit of activity, everything, to see that the bad guy got in, and then points out, oh, it got in through this vulnerability, and turns out it was in Adobe, okay, cool, it doesn't really matter, but the fact is, if it can quickly identify that, oh, this happened, and stop it at machine speed, that's the solution, the solution is AI stopping the bad guys as soon as they enter your fortress, boom, they're shot, they're stopped, boom, fantastic, cool, I don't care that they found a hole in the wall, cool, keep crawling through, I'm going to keep stopping you every time you come in. Eventually we'll patch the wall, but I don't care, because we catch you now.

Aby Rao: I guess that's just one point of failure though, right, the AI is going to be, however, technically, they got through all the other things, and then your last line of defense.

Matthew Connor: I'm not suggesting we put AI as the only line of defense, but your last line of defense is that it's monitoring everything and sees that abnormal behavior and immediately stops it. Is that the future of vulnerability management, because we can't expect the manufacturer to be patching and finding the vulnerability, we can and should, but when a vulnerability is found, the important thing is that we catch the bad guy the second they enter our kingdom.

Aby Rao: Yeah, no, I mean, I believe that's the future. And if I were to double-click on that a little more, Matt, the way I look at this is, imagine there's a chunk of code you're about to release, it has some capabilities, new functions that would enable your product. Imagine you wrap around a sidecar agent, actually, let's wrap around two sidecars. What that means is, this agent is an agentic representation of a business expert who understands the business logic within that code, okay, and then there's another agent who's a security expert, representing the security champion, the security evangelist, if you will, and they're sitting there watching everything. If the business perspective combined with the security perspective is utilized and applied to a certain piece of code, now you have real-time analysis, real-time watching, which we didn't have before. You would look at logs in our SIEM and it's like, okay, this is what happened, this is the lesson learned, too late, too late, we lost our data, we lost our reputation. So how do we have these wrappers around any code we build? And I think some people call it continuous security evaluation, there's continuous evaluation of security, you can call it whatever you want, but I call it a security sidecar, because you're always attached to the code, you're monitoring it. And I think that's what you're alluding to, as part of that conceptual framework, where it has to be just in time, it has to be in real-time execution mode, not just sit and watch as an auditor.

Matthew Connor: Yeah, I couldn't agree more, and I do think that's the future, how we secure the code for all the SaaS products, everything that's going out, it gets far more secure the more advanced AI becomes, and the better it gets at those things. And I think you're right, having those two particular sidecar agents, that's what you need, and it should be working with every developer as they're writing code and pushing it, yep, it gets evaluated for that, fantastic. And then on the consumer side, that's AI watching your network, so great, we've implemented this product we purchased, fantastic, and now you've got your AI agents, whatever product it serves, part of that is looking for that activity, and then I pity the poor bad guys, because how are you going to get through that? It becomes so much more challenging. And I think we saw that during COVID times, there was a rise of ransomware that sent so much money into the cybercrime industry, they're now well-funded, and they just so happened to also have AI, so they're well-funded and they can develop very quickly and find vulnerabilities very quickly. But I think as we move into the future, I think that all shifts, and it becomes so much harder for them to gain access, it'd be nearly impossible for them to get in and get that ransom and get the kind of money they've had. I think this was a short window of prosperity for cybercrime, and I know people are going to disagree with me on that one too, but I do think it was a short window for them, some managed to make hundreds of millions of dollars a year doing that, but I think those days are numbered, and I think it's because of AI and things like this we're discussing.

Aby Rao: Yeah, no, I think that's a fairly fresh perspective, in my mind I always look at AI as an enabler, it could be for the good guy or the bad guy, but it's very interesting the way you broke it down, comparing it to the COVID era versus how we look at it in the future. But it comes back to guardrails that frontier models define, open-weight models define, open-source models define. I think without those guardrails, it becomes a lot easier for them to tap into and just unleash the potential of these models. So I'll be very curious to watch these controls, the security, privacy, compliance controls being enabled within these models, so we can do a better job day after day.

Matthew Connor: Yep, couldn't agree more. Aby, this has been so much fun, I've enjoyed every moment of it. But before we go, can you tell everybody where they can find out more about you and more about Paylocity?

Aby Rao: Paylocity.com is our official site, we're a SaaS provider, so we really enjoy working with businesses of all sizes, please reach out to us through the website. You can find me and my work at abyrao.com. I'm fairly active on LinkedIn, expressing myself sometimes, having some very constructive conversations with others, so I'm happy to engage with anyone who considers themselves a security professional, or otherwise. But yeah, those are the two places.

Matthew Connor: Awesome, Aby, thanks so much for coming on. Until next time.

Aby Rao: Thank you, Matt, thanks for having me, pleasure.