Rick Caccia

speaker
57 appearances 1 recordings 1 series first heard Jul 2024 last heard Jul 2024

Rick Caccia’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
We started this company thinking about the security of AI use in a way that most security startups also do, and we got it wrong. So we had to revisit and trade some things off. So we looked at this and said, oh, this is going to be like any other new type of security issue. You're going to have new types of attacks. AI-oriented attacks are going to be the big deal.
Let's figure out how to talk about those and prevent them. And then we went out and we talked to maybe a dozen CISOs. And the interesting thing was none of them cared. Nobody cared. They thought that was years away. And instead, they cared about much less sexy things. My name is Rick Katcha. I'm the CEO of Witness AI.
The company is Witness AI. We enable companies to adopt AI safely and effectively. I've probably spoken with more than 100 CISOs, Chief Information Security Officers, in the past year, and I would say almost every company we've spoken with is in the same boat. The employees want to use all these cool new AI tools so they can be more effective.
And the security and privacy teams are worried about the risks. And most of these companies are stuck. They're trying to figure out how or if they should let employees use this stuff in a way that doesn't put the data at risk. Our software gives the user activity guardrails to ensure that people can use these cool new Gen AI tools in a safe way while also being productive. We're pretty early.
We're just in beta now with a bunch of Fortune 500 companies. We were incubated inside of a venture firm called Ballistic Ventures starting about a year and a half ago. I knew the Ballistic guys, known them for well over a decade. We were both acquired into a large company. We were in other startups a long time ago.
They asked me to come in and work with a CTO co-founder and figure out where this company should go, and we've done that. I guess the product, the way I would say, gives customers visibility. Where are my employees going relative to AI? What are they doing there? Should you care as a company? In my career, this is probably the first time I've never had to explain the problem to a potential buyer.
We just talk about risks around AI. They get it and they get right into how the product works and can they buy it.
Once we had a clear idea of what we wanted to do, from that point to the first beta, Proof of Concepts was about six months. It's built as a set of Kubernetes microservices. We stand them up as a new instance for each customer. When we talk about these guardrails that we have around user activity, they're really separate microservice-based AI policy engines.
So like one of them might look at your prompts in a chat window to detect jailbreaking. Another one might look at prompts to detect use of confidential data. We use a mix of standard technologies and we use a bunch of custom built stuff as well. All the AI engines are custom trained. We've also incorporated a lot of open source stuff.
I think AI is interesting because there's a lot of open source stuff available. There's new stuff popping up all the time. We've also been using some early stage platform technology from some other early companies and that may or may not work out for us over time. We're trying to sort that one out.
We started this company thinking about the security of AI use in a way that most security startups also do, and we got it wrong. So we had to revisit and trade some things off. So we looked at this and said, oh, this is going to be like any other new type of security issue. You're going to have new types of attacks. AI-oriented attacks are going to be the big deal.
Let's figure out how to talk about those and prevent them. And then we went out and we talked to maybe a dozen CISOs. And the interesting thing was none of them cared. Nobody cared. They thought that was years away, and instead, they cared about much less sexy things like visibility. Like, I don't care about some crazy new attack.
I care about just seeing, are my employees using some new LLM-driven chatbot that happens to be hosting data in China? How do I enforce acceptable use? We ended up having to make decisions to trade off the kind of whizzy, sexy security features for things that are much less whizzy, like visibility and policy enforcement. And when we made that trade off, the results were just crazy.
We went from not being able to get a single design partner, early customer, to getting 25 design partners in a month after we changed that decision and saying we're going to trade off the sort of sexy security stuff for the boring visibility, compliance, governance stuff. And the uptake was just amazing. It was like we flipped a switch.
With enterprise products, you have this interesting combo, right? You're rolling out some sort of platform that has to run inside some large company. So first off, you have a combination of speed and scale of the platform itself. Will this thing work at a fast enough speed that they'll actually deploy it? Then you have this set of enterprise use features.
Then you have a set of features that are your actual differentiated features. And so for version one, for MVP, you have to get some level of all three of those working at once. And we're actually at that point now. And so we're maturing each of those different pieces at different rates now that the basics are there. So enterprise features might be things like, does it work with Active Directory?
Does it work with Okta or whatever single sign-on they use? And you either have that or you don't. And if you don't, no company is going to deploy this. So you have to get that there. That's part of the MVP. Then speed and scale are things like how much latency do you add? How do you get that to an acceptable level? What happens when the employee user count goes from 10 to 100 to 1,000 to 10,000?
And if the product is too slow, then they view it as being broken. You also don't get deployed. And so then when those two things are working, then you also have to have the features that are why people looked at the product in the first place. They don't buy a generic product that works fast. They buy a product that does something for them.
We've had to make sure that trio of platform speed and scale, enterprise features, and then the differentiated capabilities around AI guardrails are all there. We're at that level now, and now we're going to make sure that as we go from 100 users to 1,000 users, The latency doesn't drop.
Make sure that all the cool new things that the engineers have wanted to do around AI classification and risk analysis, all those things are coming. But first, we had to get those basic things there. I couldn't build a product that didn't have any single sign-on or way to protect user activity. That had to be there. And that's part of the MVP.
Showing 1–20 of 57 · page 1 of 3 Next →