The Humans at Our Helm: Meet Rich Buractaon, Director of AI

Rich Buractaon, Andesite’s Director of Artificial Intelligence, is a data scientist who spent two decades working in defense at the MIT Lincoln Lab, the Pacific Northwest National Lab, and DARPA. He views AI as a natural cybersecurity partner and is excited to use data science to support cyber defenders. Rich recently led the development of our ROI Calculator to give organizations the ability to quantify the impact our product can have even before getting to a proof of value. 

As Head of AI, What Is Your Role at Andesite?

I’m responsible for three broad areas:

  • Innovation and Research – We’re  looking at the broader scope of AI, where it can go, and making sure we’re innovating in the right areas.
  • Development – These efforts are focused on creating new products.
  • Compliance – In everything we do, we are always making sure what we ship is responsible, auditable, and trustworthy.

What Drew You to Data Science? Tell Us a Little About Your Background. 

I studied electrical engineering during my undergrad at the University of Portland. After that, I decided to take a deeper dive and completed my M.S. in Electrical and Computer Engineering with a specialty in Control Systems and Statistical Signal Processing at Northeastern University. Throughout my studies, I specialized in finding signals in the noise, building signals that survive degradation through noise, or hiding signals in the noise. 

When I worked on the network defense program at DARPA, the field of data science had begun to emerge and take shape. Databases were growing exponentially at the time (2011-2015), which caused everyone to grapple with effectively searching through big data. While data science had always existed, we didn’t have a name for it until the volume of data we were dealing with reached a tipping point. This work gave me the opportunity to apply those statistical signal processing techniques I had studied to exponentially growing military databases. For example, during operations in Afghanistan, we used data science for counterinsurgency, discovering a correlation between food prices and locations with insurgent activity. From there, we were able to apply the same techniques to other challenges, like human trafficking, narcotics, and financial crimes in various parts of the world.  

How Did Your Background in Defense Lead You into Cybersecurity and the Private Sector?

As the field of cybersecurity was growing, my team was bringing in people from different disciplines to solve the problem of signal processing in cybersecurity data. I think of cyber as a language. Things like PCAPS (network packets) and NetFlow (flow data) are how computers talk to each other, so we build grammars and vocabularies across that language and use Natural Language Processing (NLP) techniques to uncover insights and behaviors. The same way you can read more into a friend’s text message than just what their words say, we use data science techniques to read between the lines of cybersecurity data. Once you understand those structures, you can apply them to any language or data set.

That early work with NLP was the precursor to the kinds of generative AI models we’re working with today and the vast knowledge bases that make up the foundational or frontier models developed by industry leaders like OpenAI and Anthropic. At Andesite, we’re helping today’s security teams by applying data science techniques so they can do three things at scale:

  • Find the signal in the noise.
  • Correlate that signal across more sources than a human could possibly manage.
  • Test hypotheses to determine if signals are malicious, anomalous, or just weird. 

What is Andesite’s Approach to Data Science?

At Andesite, our priority is reducing the cognitive load for cybersecurity analysts, who are literally drowning in data. We’re applying data science to frontier models of generative AI to make sure we’re analyzing the right data. Andesite integrates data science through configurable agents, which are baked in with specific methodologies. Human experts write the configuration instructions, and the frontier model uses that set of instructions to perform the way a human would, lightening the cognitive load for SOC analysts. We also have data scientists partnered with SMEs, cybersecurity experts who know the specifics of our customers’ organization, the methodologies, etc. These people  are constantly interacting to course correct the path,  so there’s always that element of human interaction and  input.

In addition to delivering day-to-day operational advantage, we’ve also used our deep grounding in data science to help potential customers evaluate the Andesite Human-AI SOC before implementation. The ROI Calculator for instance gave prospects an additional way to assess the value that Andesite can bring to their cybersecurity operations. 

How Do Human Experts Partner with AI When You’re Operating at this Scale?

Our guiding principle at Andesite is humans at the helm. We’ve built a human-machine partnership in our bionic AI SOC that combines configurable agents with subject matter experts to maintain human oversight. This means you can course correct in real time because we’ve essentially baked a data scientist into the product, so the configurable agents have the methodology. 

At the same time, the design incorporates “human-in-the-loop” responses to balance automation with essential oversight. The agent can interject and ask for clarifications on open-ended queries, which helps guide the investigation and prevents pursuing the wrong line of questioning. This approach also facilitates tribal knowledge transfer and ensures high-fidelity AI investigations. 

What Sets Andesite Apart in Terms of Our Approach to AI?

Right now, there are competitors that have gone fully automated, plug-and-play, which has generated backlash. A fully automated SOC needs to operate at subsecond speed — faster than the speed of human conversation. An agentic tool can’t live there, so you have a built-in limitation. 

At Andesite, we believe that robustness is as important as speed. We purposefully keep the data where it is to avoid migrations, delays, and their risks. We avoid the risks of an AI black box by taking an evidentiary approach, with a repeatable process where mistakes can be surfaced and corrected. And we ensure that the humans are the ones making critical decisions, for true accountability. AI is good at repeatable tasks, but not at strategy, which is why it’s essential to keep people in the mix. Plus, because frontier models are token prediction models, the AI will reinforce your beliefs or bias. Humans at the helm sets us apart.