The Canada Nation

Your Trusted news Source

Cybersecurity vendor Field Effect growing fast with new tool targeting ‘shadow AI’ at companies

Cybersecurity vendor Field Effect growing fast with new tool targeting ‘shadow AI’ at companies



Open this photo in gallery:

Field Effect CEO Matt Holland, pictured in 2021, estimates his company will add 3,000 more customers this year and aims to raise US$100-million in 2027 to fuel expansion.Blair Gable/The Globe and Mail

Matt Holland started his career with Canada’s cybersecurity espionage agency, writing code for offensive security missions and breaking into information technology systems of the country’s enemies following the attacks of Sept. 11, 2001.

The cyberspy-turned-cybersecurity entrepreneur is still targeting threats, but he’s no longer going after al-Qaeda. His new pursuit is artificial intelligence – specifically, AI that lurks undetected within companies or is misused by employees.

In June, Mr. Holland’s company, Field Effect Software Inc., introduced an AI detection-and-response tool to help its small and medium business clientele. It prevents employees from unwittingly uploading sensitive corporate data to platforms like Claude or ChatGPT, blocking use that violates corporate policies, and will soon track prompts – the instructions users provide to generate AI content.

The program also stops so-called “shadow AI” programs operating within corporations – such as AI features added to cloud software they’ve used for years – from unknowingly accessing and transmitting their data to places they aren’t supposed to go. Mr. Holland, Field Effect’s chief executive officer, said in an interview his AI tool is “like a chaperone with a grimace and a large stick to smack the AI when it’s gone off the rails.”

That is what many companies want. In less than four months, privately-held Field Effect has seen its user base jump by about one-third, to 12,000 companies from about 9,000, largely driven by demand for its AI-targeting tool. The Ottawa-based company’s annualized revenues are approaching $50-million, up from $26-million last year.

Bell, Cohere release AI model designed to aid cybersecurity investigations

Mr. Holland estimates Field Effect will add 3,000 more customers this year and aims to raise US$100-million in 2027 to fuel expansion. Field Effect also plans to launch the AI tool this fall as a stand-alone product for companies of all sizes.

“Once we start to put that money to use on the commercial side, I will be shocked if we don’t grow 80 per cent to 100 per cent a year for the next five years,” he said. Recent stories that AI bosses themselves worry their tools are dangerous “are creating the business case for us in real time.”

Field Effect is one of several companies offering digital nannies to help organizations ensure the proliferation of AI applications within their operations won’t cause harm.

Toronto’s Signal 1 has developed an AI management system for health-care organizations to oversee all the new tools and making sure, for example, that AI-generated draft e-mails from doctors to patients conform to hospital standards. Teramind Inc. of Aventura, Fla., polices employee activity on computers, networks and other digital “end points” to ensure they aren’t using unapproved AI tools or uploading corporate data. Nvidia Corp. NVDA-Q this week announced a security platform that will set boundaries it says could stop rogue activity by AI.

“A lot of organizations haven’t figured out how to utilize AI correctly, let alone what is it being given access to, and there’s virtually no real controls around it,” said CEO Jeff Farr of Dallas-based Sera Brynn LLC, which manages cybersecurity services for companies and deploys Field Effect products to customers. Its new AI tool, he said, “has been eye-opening for several of our customers when they actually look” at the issue. “The light bulbs are going off in a big way, because almost nobody has a clue.”

Rob Schenk, chief strategy officer with Las Vegas-based Intelligent Technical Solutions, another third-party cybersecurity services provider that deploys Field Effect to about 800 clients, said “AI is becoming a driver of additional revenue for companies like ours.” Field Effect’s AI tool, he said “complements the direction that clients need to go. It’s accelerating the conversation.”

Canada’s plan to counter the U.S. and China in AI is taking shape. Will it work?

Mr. Holland joined the federal Communications Security Establishment’s Tailored Access Operations (TAO) group in 2000 after studying computer science at University of New Brunswick, earning a reputation as one of the best in the trade at understanding operating systems, and how to defend and exploit them.

After the Sept. 11 attacks. TAO’s profile within the cyberespionage unit swelled. Mr. Holland left in 2007 to start Linchpin Labs, which built software for Canada and its “Five Eyes” intelligence-sharing allies – the U.S., Britain, Australia and New Zealand – to run cyberintelligence operations. He self-funded the company and sold it to defence giant L3 Technologies in 2018 for US$200-million.

Mr. Holland decided to focus next on helping small companies protect against threats from cyberattacks. With Field Effect he set out to create an all-encompassing, affordable and simple product for small businesses offering the kind of protection large companies get. That platform combines a range of internally built capabilities to comprehensively monitor a client’s vulnerable digital assets, including network, computing devices, connected sensors and cloud operations.

Mr. Holland believed its holistic approach and “zero trust” modus operandi (as in never trust, always verify) would serve Field Effect well as it developed its AI detection tool. Now, he said, “We have the technology that guards against AI going off the rails.”