This week on Dark Rhiino Security’s Security Confidential podcast, host Manoj Tandon talks to Dan Wachtler. Dan is the CEO of DarkLight Inc and an accomplished entrepreneur with over 20 years of experience serving in both executive and sales leadership roles. Previously, he was the President of root9B Holdings, Inc., a NASDAQ-listed advanced cybersecurity firm and creator of the first-ever commercial HUNT platform. Dan has led numerous capital raises and managed large corporate realignment efforts, including international expansion efforts.
Chapter Titles:
00:00 Disclaimer
00:09 Introduction
00:25 Our Guest
01:18 Journey into Becoming an Entrepreneur
03:44 What is success to you?
08:21 What’s the secret to bringing awareness to your startup?
12:22 How do you differentiate?
16:43 What does DarkLight do?
22:53 How does your system differentiate between industries?
28:30 Understanding Risk
31:09 Does A.I. have a role in this?
36:07 Getting a Demo with DarkLight
37:44 More about Dan and DarkLight
Audio:
Important Links:
Transcript
Manoj (00:00.619)
Hello everyone, welcome to another episode of Dark Rhino Security, Security Confidential. Today we are honored to have Dan Wachtler join us. Dan is a serial entrepreneur. He’s the CEO of Dark Light, Inc. And we’ll hear much more about that a little bit later. But as an accomplished entrepreneur with over 20 years of experience, he served in both executive and sales leadership roles, basically everything that makes a company work.
He was the president of Route 9B Holdings, which was a NASDAQ publicly traded advanced cybersecurity firm. And he is the creator of the first ever commercial hunt platform. He’s done multiple capital raises and managed large corporate realignment efforts and international expansion efforts. He makes the companies work in the world of cybersecurity. Thank you so much, Dan, for joining us.
Dan Wachtler (00:56.13)
Thank you, Manoj. Appreciate that.
Manoj (00:58.655)
You know, you got a heck of a accomplishment list there. So we wanna hear your story. How did you become an entrepreneur? It’s a, or how did this happen?
Dan Wachtler (01:13.458)
Luck, to be honest, I won’t bore the audience with too much history, but it was summer school Spanish class in college. I had thought I wanted to own my own business in Spanish class. I met someone who was about 60, still my mentor, and he owned his own business, but the way he operated, you would assume that it was a very small business and he was so low key.
And I asked him to go to dinner, took him dinner with he and his wife. And it turned out that he and his family owned a company that had 30,000 employees. And I was so blown away with how someone with such financial success could be approachable, not arrogant giving that. I wanted to work for him and he happily for me brought me into his company. A 50 year family company. They sold that.
spun a piece out, I ended up buying that from them, really taking a business that was…
Dan Wachtler (02:18.454)
needed to be turned around and took that over. And that’s kind of where my journey started in building and operating businesses.
Manoj (02:25.727)
Wow, what type of a business was that then?
Dan Wachtler (02:28.546)
So the original business was a security guard business. So security officers, literally people in uniforms at malls, at banks, what have you. The division we spun out that I ended up purchasing focused on higher level executive protection, robbery suppression, kidnapping, ransom, sort of some heavy duty stuff. When I bought it, that sounded pretty cool until one of our folks actually killed somebody.
Manoj (02:31.799)
Okay.
Dan Wachtler (02:56.27)
And then it’s not as sexy when that kind of real life scenario hits you when you have an economics degree from the University of Arizona and not from that law enforcement intelligence community world. So we began, I quickly moved the business to focus on anti-money laundering and counter terrorist finance investigation. Post 9-11, that industry was, was growing. So that was more luck. There’s nothing lucky about 9-11, of course, but being right place, right time for what.
the industry needed, our business provided.
Manoj (03:27.575)
Wow, there’s so many questions I could ask you about that, but I think we might run out of time there a little bit. But when you counter terrorism, yeah, well, that is, let me ask you this, a little side journey here. Do you think the world of blockchain has helped the world of counter terrorism as specifically around finance or?
Dan Wachtler (03:36.706)
There we go, yes.
Nothing to do with cyber yet. Yeah.
Manoj (03:56.191)
You have an opinion on that? Just curious.
Dan Wachtler (03:59.614)
I do. I certainly have tracked that. I stayed in touch with my old industry folks and the reality is blockchain and cryptocurrency, I don’t know that it’s a secret anymore, but the reality is that’s actually sometimes much easier to trace when you’re following the money for the bad guys than the regular money laundering using currency. So do I think we’ve…
really figured out a way to best utilize the blockchain? No, I think it has a place and will always have a place. I think cryptocurrency is also here to stay, but to suggest that cryptocurrency and blockchain is really making it much easier for criminals as compared to the past, I would say that’s no longer the case. There’s lots of great firms that can now track money easier than it was in the old days of just dollar bills.
or $100 bills. Correct.
Manoj (04:56.651)
Well, that was the whole promise of blockchain, right? That you can see every step of the process and movement of whatever it is that you’re tracking. And interestingly, most ransomware operators still like their payment in crypto, right? Which is…
Dan Wachtler (05:13.042)
It is, there are, I think reasons for speed, et cetera. And then, and then some of the, some of the advancements in technology, um, may end up changing that I don’t know to be seen, but you know, before chain analysis and there’s a group called and chain that really tracks these things before those came to the market, it’s not like the NSA or others are going to give up their sources and methods for a bad guy. That’s taking, you know, 500 grand from.
in a ransomware situation, as much as we’d like them to do so, they can’t give up sources and methods. But now that these things are becoming privatized, we’ll see what happens.
Manoj (05:52.435)
Okay. Getting back to entrepreneurship. And, you know, we have a lot of folks who are very young listeners. And, you know, in their mind, they’re like, well, I want to be a pen tester and I’m going to do my own thing. Or I’m going to, you know, be an ethical hacker of some kind and I’ll be a consultant, a securities consultant. They want to start their own business.
Dan Wachtler (05:57.195)
Yes.
Manoj (06:21.683)
What do you see as repeating patterns from your own experiences as an entrepreneur that keep coming up that you have to watch out for if you want success in your sites?
Dan Wachtler (06:37.334)
Well, to me, the first answer or first question that should be answered for yourself certainly was in my case, which I didn’t do a good job early in my career, was what is success to you? When you talk about financial success to what degree versus life balance, those are really heavy and important.
questions to think about before you make your decisions on.
Dan Wachtler (07:12.574)
And on the flip side, however, being an entrepreneur and loving people that have the willingness to take the jump, take the risk. If you have an itch to be an entrepreneur, go do it, especially if you’re young, because you’ve got lots of time to make up for things. But if you have that itch and don’t scratch it, you’ll always wonder. And some people love it, the independence, the wondering if you’re going to make payroll for yourself, let alone if you have employees.
those sorts of goods and bads, people are really gonna love it or they’re gonna hate it, but if you don’t try it, you’ll never know. And then you get to be, say, my age, 53, and it gets way harder. Kids, college, blah, it gets way harder to take that risk. So if you feel like you wanna do it, just do it. But I think I probably would have set some more guidelines on what success is to me.
between that financial success and life balance success.
Manoj (08:15.107)
How much of the entrepreneurship game, in your opinion, is mental versus the actual work of whatever business you’re doing?
Dan Wachtler (08:27.235)
Oh boy.
My instant reaction was to 80% because the grit, the resiliency, the ability to just take rejection, to be depressed, but yet keep going after it with a smile. Maybe that’s insanity, I’m not sure. I hope my wife doesn’t think so. But I think there’s a huge amount that’s mental. Just the…
The ability to be naturally resourceful and resilient, you just gotta have those traits.
Manoj (09:06.464)
Yeah, Dan, I would just counter with, and this is, I’ve done five companies. This is my fifth one. Um, is I’d say it’s 90%. I think that mental toughness, it, I can never tell you what today will bring. I don’t know. I, and I have never not been surprised. So to me it’s, um, it.
Dan Wachtler (09:19.576)
Hehehehe
Manoj (09:34.503)
If you have to have that, everything you said, I just up it a little bit from 80 to 90%, maybe. And then the rest of the things, surprisingly, you’ll sort out and there will always be challenges with whether you’re making payroll or contracts or delivery or whatever the case may be. But you can get through that if your mind can be stable enough to navigate those waters. And that’s…
Dan Wachtler (09:41.382)
Yeah.
Manoj (10:04.395)
But I’d rather have the audience hear it from someone with your success than with someone like me. So I appreciate it.
Dan Wachtler (10:10.777)
Well, that’s very generous. You’ve done five of these, so you’re at least as experienced as me.
Manoj (10:18.66)
So this is another one. This is not a question I got on one of our channels, but I’ve gotten this at many of the events that I’ve attended. And that is in the startup game. And you’ve done several product companies. When you have no clients, no references, nothing behind you other than you built a product and a name.
How do you sell that? How do you get early adopters? What’s the secret?
Dan Wachtler (10:54.31)
Ask for help. Hopefully, again, doing my situation with Darklight was very, very different than my situation with Ipsa or others because of my age. So Ipsa, I was 33. I got involved and took over Darklight at 48. I had a pretty good network that allowed me to.
Manoj (11:06.847)
Absolutely.
Dan Wachtler (11:21.366)
you know, make phone calls that people would know who I was. And that, that helped with some credibility. Has not been easy. We are still absolutely struggling. We’ve pivoted from DoD government work using the tech in a different way than we do now for cyber. But for those that are doing this younger, um, folks that may not have the network, don’t be afraid to ask for help.
Because if you truly care about your product, about the industry and about helping solve a problem, there are so many great folks out there, especially in cyber. One of the reasons I love this industry is, and same with anti-money laundering, counter-terrorist finance stuff. We have a bigger problem we’re trying to solve than just worry about investors, which we have to do, have to put food on the table.
but we’re trying to solve a bigger problem and you’ll find a lot of mentorship and people willing to mentor you in cyber and you use that by simply asking for help. I have an idea, I know you’re busy, but can you just take a look at this and tell me what you think in 15 minutes, half an hour? And then you start to learn and then people go, wow, this is cool, I wanna be an early adopter and you just grind it out.
Manoj (12:37.627)
What a novel concept. That is, that’s so very true. Ask for the help. And I think that’s the biggest thing, right? And I’d say don’t be in love with your own ideations all the time. Be willing to accept some guidance if people are telling you something, they’re not doing that out of malice or…
Dan Wachtler (12:40.866)
Yeah.
Manoj (13:05.407)
because they’re jealous or anything, they might, like you said, there’s a lot of mentors in our industry and they’re doing that in the best interest, most of the time.
Dan Wachtler (13:13.394)
Well, Minoj, that to me is one of the, especially when I’ve come to this industry and really product only, which I haven’t done. Different businesses had a mix of services and product, but this is a 12-person company where the only thing we’re selling is a product. So this one is slightly different for me. But that ability to balance, to hear that your baby’s ugly.
and not get offended and actually listen. But also if you’re doing something truly unique and different that maybe people aren’t understanding, straddling that ability to listen without being arrogant or ignoring with also not being deterred on what you believe is right, man, that’s the secret sauce. And I’m still trying to figure that out. Maybe you figured it out, but that balance is really, that’s the million dollar quality right there.
Manoj (14:04.519)
I haven’t.
Manoj (14:09.247)
Yeah, but you’re 1 billion percent spot on. If there’s such a, I can’t agree with that more. You really, you nailed it. I have nothing more than to say other than people, you might wanna go back 10 seconds and re-listen to what Dan just said, if you’re thinking about getting into this, because it is absolutely critical to your success. And now that you’re doing it, a product only company.
Dan Wachtler (14:13.646)
I’m going to go to bed.
Manoj (14:38.263)
How do you really differentiate? I mean, and I ask that because cyber security seems like there’s a ton of products out there, Dan. A lot of products. Is there room for one more? Or how do you make your blue ocean happen?
Dan Wachtler (14:58.634)
knows I’ve read all the books when I came here because I thought I was sort of done reading all the latest craze books when I was in my 30s and figured now I’m an experienced executive, I don’t have to read all that stuff. Clearly, I’ve done that here because I was getting my backside handed to me quite a bit early on in it.
Dan Wachtler (15:20.35)
Let me answer by saying what we’re in the middle of doing as opposed to giving advice to anybody else because we haven’t figured it out. I just got done with Black Hat last week. Uh, as we mentioned in our sort of preamble, um, I walked the floor. I’ve known this before. We, we do a very active review and different products that we think might be competitive or even budgetary competitive, you know, but, uh, competition for budget dollars.
Manoj (15:28.811)
Please.
Manoj (15:47.061)
Yep.
Dan Wachtler (15:50.226)
and we’re reading all the messaging. And I’m supposed to be a sales guy and communicating in a simple way is really important. But when you break down the solutions or the problems that we’re trying to solve and the how to solve it, it is so much noise out there. It’s very hard to differentiate, I think, from a surface level. So this piece we’re going to now is literally back to the old school way of we’re gonna grind it out.
service and proof even though we’re a product company. It will probably reduce how fast our hockey stick may be. Knock on wood we have one. But the idea is making sure we don’t over promise. We don’t BS the market and then good old fashioned word of mouth until we have a fundamentally sound product that’s proven with a large set of references. Then we’ll put the gas on it.
from a marketing perspective, because we can use some of the same words, but we’ll have the proof to back it, which that begins from my perspective to be the differentiator in cyber. Do you truly deliver what you’ve promised? Because just explaining your differentiator without getting way into the science and the tech, which can bore people to death, I haven’t figured it out yet.
Manoj (17:14.524)
Oh my God.
Dan Wachtler (17:17.782)
So may not be a great answer, but it’s our reality right now.
Manoj (17:21.119)
No, it’s a very, it’s a very practical answer. And it’s real. I think the model and the approach is very well proven. I mean, for what you’re trying to do, there’s been umpteen companies out there that proved out a services portion that productized it and have been immensely successful. So, and cyber, it’s credibility.
Dan Wachtler (17:45.27)
Well, when you start to, I agree. And when you start to look at a pattern that we’ve seen, I mean, we’re reducing our next raise based on the pattern that to me is so clear, which is you have a really good idea. You’ve got great early adopters and then you’re whatever that book is, Crossing the Chasm. You know, you’re trying to switch from truly the early adopters who want to experiment with new products to the ones that don’t want any experimentation.
Kind of like me, I’m always two iPhones behind. I wanna make sure they get their stuff worked out. And so to cross that chasm, you take a lot of money and then throw marketing dollars at it, and you may or may not be ready for the scale. And you may not be delivering on the promises that the new marketing folks are putting out there. And so making sure we have that foundation, right, to build the credibility, because these CISOs talk to each other. This market shares.
everything. And I do believe good old fashion, deliver what you promise, stand up for the responsibility and then don’t overdo it sales marketing wise. You can have a very large successful business if your product works. Let’s be real.
Manoj (18:58.187)
So let’s talk about that. What does dark light do?
Dan Wachtler (19:02.274)
We help companies identify and prioritize their risk in cyber so that they can quickly utilize limited resources to fix the things that should be fixed first.
Manoj (19:17.707)
How are, how do you guys stack against like risk lens? You know, or, yeah.
Dan Wachtler (19:25.726)
So good question. This is a great challenge in the marketing arena. So what we’re trying, what we’re doing is focusing on evidence-based risk as much as possible. So we’ll ingest vulnerability scan information, as an example. So a scanner is actually looking at endpoints, your environment, and giving you what.
Manoj (19:44.951)
Okay.
Dan Wachtler (19:53.502)
are known vulnerabilities. And then the company or service providers like yourselves have to go fix this or tell them what to do next. The risk lens is doing, there’s a lot of interview component to that. There’s not the evidence based fully on ingesting the scanners. Where we’re going is fusing a lot of different data sources and feeds to give a more complete and automated picture of where your risk is.
and not only what it is, but how to fix it.
Manoj (20:26.827)
So if you could walk us through the process, you’re first going to scan the entire environment for any open vulnerabilities, whatever they might be. That might be software missing patches. It could be open ports. It could be whatever, umpteen, ABC, PDQ, configuration. Yeah.
Dan Wachtler (20:44.342)
Configuration, CVEs, correct. And that, a key piece to us, for better for worse, which we’re learning as we’re going into the market, we wanna be scanner agnostic. So while we have a, quote, partnership with Tenable, you know, it’s like an MSSP partnership, anybody can really get it to some degree, but we support Rapid7 as well. And so the client or the MSSP will run the scan,
Manoj (21:06.728)
Right.
Dan Wachtler (21:13.87)
bring that into our environment and what we can show in our pilots or proof of concepts very quickly in 15 minutes, look at what the tools that are doing the scans are telling you should fix first versus what Darklight’s SIO tells you to fix first and right away you’ll see a difference. And that’s because we’re bringing in other pieces of information.
So updated NVD, National Voluntary Database, and CVSS scoring, not just the base, but the more advanced scoring. I won’t get too technical here, but there’s a lot of other, as you know, Manoj, there’s a lot of other ways to measure risk. And this is something that we’re dealing with, is risk is actually likelihood plus impact. Likelihood is somewhat easier to understand based on publicly available information.
is only maybe even whatever percentage, but less percent that you can get that from public, you have to understand your own environment to get the impact part. So we’re giving you a mechanism to quickly, truly measure risk based on likelihood and impact.
Manoj (22:25.491)
Okay, and in the end is your report putting out dollars and cents. It’s saying this is the likelihood of loss versus the magnitude.
Dan Wachtler (22:36.366)
We haven’t done that yet. I don’t, we’ve looked at the fair model. If you, you’ve probably heard of that. Audience may or may not have. Yeah. And we believe, yes.
Manoj (22:42.387)
know it well. Yeah. By the way, Wrist Blend sold for a big chunk of money recently. So that…
Dan Wachtler (22:50.218)
You know, I believe that those are good and bad because it’s good because it can sort of speak in terms of, oh my gosh, that’s a million dollar loss versus a hundred dollar loss potential. There’s so much subjectivity in there versus objectivity in trying to measure those things. I think it can sometimes distract and be the focus.
versus speaking in even more real terms, which is what our capability allows, hey, this risk could take down your payroll system. So we can speak in terms that a small, medium business person especially, they don’t need to understand or even hear a fair. They don’t need to, you know, thinking about a million dollar issue versus $100 issue is no, this risk could take down your e-commerce site, which is an information system based on the NIST.
guideline. There’s a definition for that. We’re operationalizing those definitions so we can speak in true business terms to the end user instead of overwhelming them with, hey, this is a CVSS 9.8, meet PSS score of X and blah, blah. And they’re like, what are you talking about? So we try to simplify that.
Manoj (24:03.991)
That is what you just said is what most SISOs or cybersecurity teams go to the board with when they’re trying to get money. And it’s like deer in the headlights versus you gonna need to fix your HR vulnerability or your supply chain. We have this problem and we need 300 grand to fix it. So you make the call. Do you think it’s worth 300 grand or not?
Dan Wachtler (24:33.742)
Yes, you’ve answered it. And even in the SMB world where there isn’t a CISO and sometimes they’re talking to the CEO, like, my wife’s an interior designer, good sized firm.
Dan Wachtler (24:46.75)
No offense to my lovely wife, but you just better tell her, hey, this is gonna take down. If this happens, your computer hasn’t been updated the next amount of time, you need to get a new one. And if you don’t, here’s your risk that your entire AutoCAD system will go down, which means productivity starts and stops in that instant. Oh, now I get it.
Manoj (25:08.619)
How does your system differentiate between industries? So what, and what I mean by that is, what may be a vulnerability that is critical in one industry because of the bad actors operating in that sector, may not really be a vulnerability. It may exist in another sector, but it’s often not exploited in that sector. And something else’s that is of a higher priority. So how do you account for that?
or how do you account for MITRE attack in this as well? So.
Dan Wachtler (25:43.87)
Well, so MITRE ATT&CK, well, let me answer your first question first. So today I would say we don’t really. The mechanism is there, but because of our limited pilot usage and sort of where we’re targeting and go to market, we don’t have to, but what we have already pre-built in the system is something we call vignettes. And so the vignette that you would choose is basically a slight
you know, to make it simple, waiting of different types based on your industry. So if there’s a, there’s a financial industry vignette, there’s an e-commerce industry vignette, there’s a manufacturing industry vignette. And those vignettes sort of, you know, dial the mod or dial the formulas a bit. Where we’re struggling with that, again, one of our core values is transparency. So while this is true that we’ve
thought of and have built in the vignettes. We’re not really using them because one of the things that we’re believers in is industry standards so that it’s easier to share information between companies, even competitive companies, so that you know you’re speaking as close to apples and apples as you can. And the more people create their own formulas and say this rating system’s better than this and there’s one rating system for every single product,
is tricky because how does that translate when you’re sharing for the industry that this threat, this new threat or this new adversary playbook could hurt blah, blah. You have your own scoring system. It’s really hard. So we’re working through that now. We haven’t had to fully address it because we can, you know, we’re still go to market with, you know, five pilot users at the moment. But that’s how we…
thought of it when we came to market as the vignette to just slightly alter based on industry.
Manoj (27:42.963)
That’s great. We had a guest on a couple weeks ago and he made a very interesting suggestion. And that was, he said, you know, go back to MITRE ATT&CK. And what he meant by that was, if you’re gonna build a defensive posture, look at your sector, look at who is really the bad actor in that sector, right? And then,
Determine what TTPs they use. And I think most people will know that’s tactic techniques and procedures, what they use. And as priority one, close those gaps because you’ve got a target on your sector, right? And that way you get something very focused for the business that you have. And I thought that was an interesting observation on.
Dan Wachtler (28:39.615)
I couldn’t agree more with him in the context of the small medium business or even the use of vignette. To me, the way to solve or to, I should say, implement that person’s suggestion is through maybe firms like yours or the MSSP that can go to their client and say, look, we’re assessing your risk. So take likelihood.
you know, if risk is likelihood times impact, you, we know that this particular CBE is now actively being used by PETA or, you know, whatever environmentalist type groups, and you are in that industry, your likelihood for that particular went way up versus what, you know, the humane society or whatever, something that’s not, that’s where the consultants come in to actually help do that. But we, we also
Manoj (29:29.065)
Right.
Dan Wachtler (29:36.958)
realize, I think all of us do, we have to have as much automation as possible if we can trust the automation because of the speeds and the amount of data we’re dealing with. And so I completely agree with that person and what we’re trying to do. And I think, you know, we’re going to talk about operationalizing these frameworks. And what that actually means is it’s going to be very key for us in the industry if we’re going to have a shot.
Manoj (29:58.281)
Yes.
Manoj (30:07.219)
And that’s the crux of the problem, is operationalizing them. And I’ll say the second part to that is that risk in our industry has become a four-letter word to some degree, in that everyone and their friends talk about it, right? They, every, I think there were 1500 MSSP firms in North America two years ago. If they’re in security, they will always talk about risk.
Dan Wachtler (30:19.426)
I agree.
Manoj (30:37.967)
It’s on their website. They always talk about it. But what the heck? How do I operationalize that, right? That is the, how do I turn that into practical actions that will make a material difference for my business?
Dan Wachtler (30:56.023)
That’s the question for me.
Manoj (30:57.703)
Yes. It’s an easy one.
Dan Wachtler (31:01.756)
Um, our, uh, our mission statement is basically, you know, instead of being an overwhelmed victim, become an empowered defender. And I want to focus on that word overwhelm for a second. I’m overwhelmed and I study this stuff every single day and have for the last six years and six years is I’m a lightweight in this industry for that six years, but it’s overwhelming.
Manoj (31:13.143)
Please.
Dan Wachtler (31:28.002)
So that’s the first thing we, and I think the industry can do a better job is, sometimes we use fear to sell and sometimes overwhelming people can increase the fear. But I think we’ve gone too far because there is some fear you should be concerned that you could have these things happen and without some block and tackle stuff, it will happen. But let’s not overwhelm folks, let’s calm it down a little bit and be practical.
If you’re a business owner and I’m not a cyber professional and someone comes and starts to overwhelm you, just like, I don’t even know where to start. Well, let’s start with the basics. Let’s understand who you’re serving. So get the industry situation. Let’s understand what could be catastrophic to your business. AutoCAD not working. My wife’s business is dead for that period of time. And she’s in.
hour-based business, blah, blah. So understand basics from a business perspective. And then the cyber professional’s job is to take the business context and reverse engineer, what are the most likely scenarios that could occur that we know about? And let’s start to solve for those things one step at a time. One step at a time with 200,000 vulnerabilities in the national
Manoj (32:52.837)
Oh yeah.
Dan Wachtler (32:53.794)
give me a break. So operationalizing risk is twofold. First, let’s make it more reasonable by reducing the noise and not overwhelming folks. And then let’s also, for those truly in the depths of what we’re doing, you and us and lots of others, use technology within reason, understanding it isn’t a silver bullet and you need people to…
Manoj (33:01.364)
Yep.
Dan Wachtler (33:22.766)
to reduce risk dramatically in terms that the client can understand without being overwhelmed.
Manoj (33:31.391)
Does AI have a role in this?
Dan Wachtler (33:35.194)
No question. There’s no question. You know, boy, what it is, is obviously the world changed December 1st last year. I mean, I cannot believe it hasn’t even been a year since JatGPT came out. I can’t believe what’s occurred. I mean, take our industry and I won’t get too into the weeds of the tech, but we’re using what’s called a semantic knowledge graph and the technology that
thought behind it came out of a national lab, Department of Energy national lab, east of Seattle here. And the way you can make knowledge grabs really sing is using something called ontologies, which is basically coding that replaces the old if-then statements. So the old days of, you know, if this occurs, do this. That’s a very brittle process at scale in cyber. Ontologies allow you to do things.
Manoj (34:16.83)
Okay?
Dan Wachtler (34:27.698)
You know, the ontologies are really about operationalizing trade crafts. So you take the MITRE ATT&CK TTPs, you build ontologies around that. It can review data using this knowledge graph and you get a tremendous amount of automation. I know I went down a rabbit hole here, but. But.
Manoj (34:42.619)
No, this is great. There’s gonna be a lot of people who are gonna love this. Please.
Dan Wachtler (34:47.094)
That is a real differentiator. And if you think about fusing the different types of data, sources and feeds and information, best practices that are available in cyber, if you’re not using a knowledge graph and probably a semantic knowledge graph, you are limited. And I’m not the techie person of most of our team for sure, but there’s no question the majority of the products out there are built on a relational database.
or even a lot of getting into graph, but it doesn’t quite allow you to fuse everything in a way to use automation and AI, for that matter, to the best of its ability. Now, I share all that because large language models may make it way easier to build ontologies. So for example, one of our.
challenges to move fast is there’s very few people that are in, I mean, literally very few people in the world that are great at writing ontologies. It’s an art form in and of itself. Combining that skillset with cyber expertise that you need to actually know what to write. It’s so finite. That’s a big challenge. Large language models, you take the cyber expert and use the large language models specifically for ontology development. And we can move.
way faster as industry. So it’s completely changed how we’re looking at this stuff. And that’s only in what Darklight sort of focuses on. When you think of instant response, you think of other things and all the tools they’re already throwing in, you know, their version of chat GPT or plugging into Bard or whatever they’re doing. I worry about how fast it’s going, which is a little bit weird because I’ve personally had hallucinations help or seen in chat GPT and Bard.
Manoj (36:27.743)
Yeah.
Dan Wachtler (36:38.722)
was something I thought was pretty benign, but there’s no question, and we have to use it. The speed in which things are changing and happening, we have to understand it. We just have to do it responsibly. Excuse my soapbox there, Minosha. Get excited about this stuff.
Manoj (36:52.519)
And no, that was perfect. I think responsibly is the key word here, right? So verifying those models are in fact correct and they’re being updated in a correct manner. And that, you know, just as easy as it is for the good guys to use these models, it’s as easy for the bad guys to use these models, right? So the thing with the robot.
Dan Wachtler (37:15.85)
And you mentioned blockchain earlier, by the way, you know, I think we think blockchain could be a really good way to, you know, legitimize, am I using the latest model that I’m supposed to be using? You know, cause there’s some pieces in there on how the latest software gets delivered or even from SBOM or supply chain, you know, stuff. I think there’s some real use case for blockchain to have the integrity. Am I using the software I thought I was using?
Manoj (37:18.516)
Yeah.
Dan Wachtler (37:44.918)
whether that’s a model or an ontology or open source, whatever, in a way, different topic, but that’s part of the responsibility piece that has to be worked out.
Manoj (37:54.887)
Yeah, absolutely. One thing is for sure that it’s the speed, and I think you mentioned that the speed at which things are changing and the way these vulnerabilities are gonna get exploited, I think are gonna ever increase. I mean, you look at dwell times now, right? I mean, we were 200 plus days a couple of years ago, right? It’s sub 90 days right now. And the ransomware deployers are trying to act.
in sub-90-minute increments at this point.
Dan Wachtler (38:27.502)
The speed is unbelievable. And you know, just this part allow me to fix something in your deduction because you mentioned that I was the creator of the first hunt platform, commercial hunt platform. That was the team at Route 9B, came out of RIC. Those guys are now all owned by Deloitte. Unbelievable capabilities. And what those capabilities do is to proactively try to find, obviously,
Manoj (38:29.643)
Right?
Dan Wachtler (38:57.694)
Many of the folks will know what hunt is, some won’t. Proactively find those breadcrumbs to prevent something happening in 90 minutes is really hard without technology, AI and automation. It’s just, I don’t think it’s doable unless you’re having those capabilities.
Manoj (39:19.311)
Yeah, it’s an uphill fight for the everyday organization. I mean, you really need some professional oversight on that if you’re gonna make a play at it. So do you folks at Dark Light have a, if people wanna learn more about the tech and whatnot, is there a way, how do they get in touch? How do they learn more? How do they get a demo or what would you suggest?
Dan Wachtler (39:47.382)
Well, obviously, thank you for that. You just go to darklight.ai. Uh, there’s a button there for pilot. If you’re sharing my email address, I mean, we are a 12 person startup company. We’re, we’re very focused on getting our first 10 clients. We don’t even have our first 10 clients yet. Uh, we have some very big brands that I can’t share, but I will say fortune 52 that are design partners, cause they’re interested in what we’re building based on the
those fancy tech terms I hope I said correctly earlier. But right now we’re looking for a cross section of small MSP, good size MSP, small MSSP, good size MSSP, and maybe one or two direct clients for our first 10 to really prove out product market fit, kind of vote on our roadmap decisions. So we’re gonna be limited to those first 10.
but darklight.ai and I’ll talk to anybody, get their opinion like I mentioned earlier. We need all the help we can get. We’ll show you a 15, 20 minute demo, give us your opinion. If you think our baby’s ugly, I won’t be offended. I’ve had worse things happen to me. So darklight.ai anytime.
Manoj (41:07.423)
While you’re at it, go ahead and plug anything else you would like to do, Dan. You have the floor. I, you know, what else is going on?
Dan Wachtler (41:11.378)
Hehehehehehe
Dan Wachtler (41:16.618)
You know, I will say one thing. What I am hoping for from the industry, and I have an article coming out about this soon, about threat intelligence and sharing. One of the things I think we in the industry have to be careful of is creating individual solutions so that we can differentiate at the expense of the greater good. So.
If I can share my individual score and say it’s proprietary and speak a different language, instead of using APT one, use some randomly created, you know, name for an APT that allows you to market that you have. You’re the only one that has this information. That’s good for marketing in the short run. It is not good for the industry. So I’m hoping, and there’s mostly incredible people in this industry, but
We really need to work together and following standards whenever possible. It’s not always possible. Please do.
Manoj (42:22.095)
That’s really good advice. I think I’d be curious, we’d love to have a VC on the show and ask them what their thoughts are because they’re all about differentiation, right? And how do I get my money back? So.
Dan Wachtler (42:36.866)
They are, no offense to them, because I’ll be pitching them, they are part of the problem. The reason that we have 71 tools on average is because what the VC community generally wants, not all of them, there are some great ones out there, especially the cyber focused ones, but they want you to give a very specific problem and solve for that very specific problem with a solution that solves that problem. Cyber doesn’t work like that.
That’s why we have so many silos of information that when you talked about some things that your firm does and this need that buying widgets, A, B through F without integration, part of the reason that we have that as many silos is because we don’t have a lot of creative and visionary VCs that realize this isn’t a one silo, you know, problem or solution issue.
Manoj (43:31.099)
I think you’re absolutely right. And I think the insurance marketplace is gonna be the one to drive the change. Watch what happens here. That’s my personal prediction as of August 14th, 2023, but I think they will be the ones that are gonna, money talks, it always has. And, right.
Dan Wachtler (43:51.458)
question. And I actually, I agree with you, Manoj. And, you know, there needs to be some, unfortunately, some lawsuits that flow through to understand really where does liability fit? How do you ensure? How do you even? But I agree, it will be the insurance companies that force this issue.
Manoj (44:09.919)
They will. And risk is foundational to them. So I wouldn’t be surprised if you guys become part of a very large insurance organization in the not too distant future. As we have seen, every insurance carrier in this past year has their own scan tools to issue a cyber liability policy. And none of them are very good. I’m just gonna say it. They, in fact, they kind of suck.
Dan Wachtler (44:13.546)
Yes.
Manoj (44:40.063)
But they invented them. I think maybe one or two were sourced from a real cybersecurity company, but a lot of them, yeah, most of them are in-house and they don’t know what to look for. They’re not going through the process that you described, Dan. And that’s what they need to be doing if you’re gonna assess the risk on a client.
Dan Wachtler (44:49.194)
Yep, I believe so too.
Dan Wachtler (45:01.806)
Bowie.
Dan Wachtler (45:06.054)
I agree. We’ve had a couple MSPs that wanted us to integrate their scanner. And it’s not that big of a deal to set up an integration. But when we did the homework on some of these scanners, and one of them was really built to be a reseller for cyber insurance, I had to go back and say, you know, we can’t support that because one of the tenants that I believe in, and I think I can say we believe in,
It’s better to know you don’t have good security than to have a false sense of security. And some of those tools are giving results that do not paint a real picture. So we just won’t support those.
Manoj (45:51.155)
I’m going to stop on that note, because I wish you would have said that at the beginning. Those, that is worth the price of admission. I hope people listen to that. Very wise words there. Dan, thank you so much for being on the show. We deeply appreciate your time and your knowledge. And best of luck to you.
Dan Wachtler (46:13.366)
Minos, thank you for, thank you and thank you for having me. I’m very happy that Dark Rhino’s doing this for the industry and I wish you and your firm well. And I look forward to getting to know you and staying in touch.
Manoj (46:25.971)
Absolutely. You’re welcome anytime. If you’ve got a new development, something new happens, let us know, even if it’s a, we don’t have to do a 40 minute thing. We can do a quick 10 minute short and let the world know about what’s going on. Thank you, Dan.
Dan Wachtler (46:41.442)
Thank you very much.
Manoj (46:45.655)
Wow, that was really good.
Dan Wachtler’s Linkedin
Check out the other episodes in Season 12:
Ep. 0 Dark Rhino Security – The IT Security Money Pit
Ep. 1 Marius Poskus – Tech talk overwhelms the nontechnical
Ep. 2 Robert Black – Who is responsible for Cybersecurity?
Ep. 3 Eric Allard – Your Guide to SBOMs
Ep. 4 Ryan Leirvik – Understand, Measure, and Manage Cyber Risk
Ep. 5 Dan Wachtler – Building Awareness About Your Startup
Ep. 6 Peter Warmka – A Seniors Survival Guide
Ep. 7 Susan Bennett – More than the Voice of SIRI
Ep. 8 Frank Riccardi – The Human Factor is the Weakest Link
Ep. 9 Dmytro Bielievtsov – What is Vishing?
Ep. 10 Chris and Rory – Bourbon Breakdown
About Dan Wachtler

Dan Wachtler is the CEO of DarkLight Inc and an accomplished entrepreneur with over 20 years of experience serving in both executive and sales leadership roles.
Previously, he was the President of root9B Holdings, Inc., a NASDAQ-listed advanced cybersecurity firm, and helped create the first-ever commercial HUNT platform.
Dan has led numerous capital raises and managed large corporate realignment efforts including international expansion efforts.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
