Resources
- -
- Solutions
- RadiantOne
- Why Radiant Logic
- Company
- Support
- Resources
© 2026 Radiant Logic, Inc. All Rights Reserved. | Privacy Policy
In this special episode of Radio Logic, we sit down with OTW (Occupy The Web), founder of Hackers Arise. OTW has trained US military and intelligence teams in hacking and cyber security, and has run the Hackers Arise training program for over 10 years.
Anders Askasen: Welcome to RadioLogic, the monthly podcast where we talk identity with the people that matters, that are in the industry, and that can solve the problems that you might have. Today, it’s a special episode.
We’re not in the normal studio, and the reason for that is I’ve got the prominent Master OTW with me today, and we’re going to talk about agentic security. We’re going to talk about frontier models, how that’s being used in security, where identity plays a role, and then we’re gonna finish off by talking about a very interesting tournament that Hackers Arise are running.
OTW, welcome to the podcast, and I wanna hand it over to you just to briefly introduce yourself, who you are and who Hackers Arise are.
Master OTW: Well, thank you, Anders. Thanks for inviting me to do this with you. And also thank you for volunteering to be one of our judges and we’ll get to that in a little bit.
So I’m OTW, Occupy the Web.
I’ve run a website training program since 2016, so ten and a half years or so.
Before that, I trained primarily US military and intelligence and hacking and cybersecurity before I started my own firm. And today we still do that. That’s what we do. We also do pen testing. We do forensic investigations. We’re a team that’s spread around the world. I think we have five different nationalities in five different locations on our team.
And so what we’ve decided to do is that we’ve decided to create a contest for the best agentic AI. And so we can talk more about that in a little bit, but that’s what we’re up against right now.
Anders Askasen: That’s incredible. Tell me, OTW, I mean, you’ve been doing training. Obviously, that comes from an empirical background where you’ve actually… You know, you you you live the craft if if, I’m not mistaken. And I always the craft. You live the craft. I live the craft. You the craft.
Master OTW: Don’t know how much we wanna go into the depths of how much I’ve lived the craft because Well,
Anders Askasen: should we should definitely touch on it because I think the audience is curious.
But at the same time, I wanna touch on the sort of training aspects of hackers arise, and and it’s definitely something I keep, you know, monitoring. What… What’s what’s there? What type of courses are there?
I’m sure things have changed from a couple of years ago, till now where, you know, you have the emergence of of these different tier models that, you know, come out of a… OpenAI and Anthropic and all the rest that that are really capable of finding security vulnerabilities, etcetera. Is that something that’s impacted, Hackers Arise, and is that something that you’re making part of the curricula or or thinking about?
No, yes, definitely.
Master OTW: I think that everybody in cybersecurity is fixated on AI right now. That’s all they want to talk about. We have a series of courses that we have begun right now, just three courses. We’ve completed number one on AI in cybersecurity.
We publish a lot of articles on the subject as well. We’re constantly tracking and experimenting with new models and new agents with the idea that in 2027, we’re going to release our own agentic AI for defensive purposes for small to medium sized companies, maybe into big companies as well. But the idea is that, you know, those companies who don’t have necessarily the budget for the frontier models, who don’t want to give away their information for frontier models. Every time you do anything with the frontier models, they’re collecting your data.
And so it’s our belief that you should not be sharing that with them. That’s basically you’re giving away as some people call your alpha, know, your intellectual property that makes you different. So as you’re querying those models, they’re collecting that information and then using that in the next revision of the model. So the next time somebody comes along and asks the same question, they’re gonna get the answers that you have basically provided to them.
And I think that Alex Karp from Palantir put it best that, you know, this is kind of, it’s across purposes of your company to be able to have to give up that information, that intellectual property, that alpha and just confidentiality of your information. So every time you have any conversation with one of these models and maybe we should not say frontier models, but say remote models, know, models that are not in your facility, not under your control. So part of the criteria that we’re looking for in our cyber security applications is that the data stay on your site and you, you control it, not somebody else remotely.
Anders Askasen: We LTW, do you think that’s the trend that we’ll see within large scale enterprises that they’re… They will invest in the necessary infrastructure on prem or in a secure data center with, you know, bring your own keys or what have you to run their own models?
Master OTW: Well, you know, when I first put out, wrote what I call the Hackers Arise Manifesto a few months ago and laid out some principles of what we think the cybersecurity AI should look like.
And since I’ve written that, not that I had any influence at all, but it appears that the world is moving in the direction that I laid out a few months ago, where we should be moving to the idea of open weight, open source.
We’ve had Nvidia has endorsed Jensen Huang has endorsed that. He went and purchased Hugging Face, right? And so he has put the weight of Nvidia behind open source. And of course, Nvidia also has their own models that are open source. So that’s one of the things we want.
Jensen Huang uses the term sovereign, meaning that you own it, right? That’s your application. We use the term local. So basically we’re talking about the same thing, local or sovereign.
In other words, everything is on your site, right? And you control it. You’re not connecting to OpenAI, you’re not connecting to XAI, you’re not connecting to Anthropic. Now, one of the things that we have seen, and I’m sure most of the people in the industry have seen is that the open source models are not necessarily exceeding what people call the frontier models, but they’re so close, right?
And Jensen Huang said it best. He said, you don’t have to be a frontier model. You only have to be close to the frontier.
And I agree with him a 100% on that. You don’t have to be the frontier because the frontier is going to have a lot of its own issues that as a company, as a business, you’re going to have to deal with.
But for medium to large scale businesses, I think that the expense is relatively acceptable. I mean, it’s an expense that you don’t have to have a data center, right? You don’t have to have a one gigawatt data center. You can go out and buy yourself a AI server and have your people set it up and run it.
It’s not that difficult to do. And that’s what our contest is about. These are people who are not necessarily AI people, they’re people from AI and security who are putting together their own servers and their own models. What people are using, they’re using…
People may not know this, but there’s hundreds, thousands of models. There are thousands, there’s thousands of AI models and each of them are a little bit different. And so what you need to do is you need to find that sweet spot of where the model is going to do what you want. You don’t have to have a model to do cybersecurity that is going to give you the history of the middle ages, Right?
Yeah. Yeah. That becomes…
That’s really irrelevant.
Anders Askasen: That’s pointless. But but, you know, reading through your manifesto, it it seems like you’re you’re kinda drawing some of the important lines there. And and, you know, radiologic, we released our argentic capabilities within our platform, and that looks for guardrails. And, obviously, that’s something of of interest to to guard and making sure that the LLM did… Well, the the model delivers what you expect it to do shouldn’t. But then also, whether these models are being used in sort of like an agentic workflow, if you will, where the LLM or the model is the brains, but at at some point, you might wanna have the human in the loop, to make decisions. Where do you draw that line?
Well, we should not be delegated to, an LLM to make a decision.
Master OTW: Well, it depends upon the application, obviously. But we… In the manifesto, I point out that we believe that human beings should always be in the loop semi autonomous. Because once you make it autonomous, then you’re turning over essentially the security for your company to a machine, to an AI.
We need to have people involved to make the key decisions about, you know, do I block this traffic here? Right? Yes, I recommend this looks like it’s malicious traffic. Okay. The AI tells me and then I can decide to block it.
Believe that’s really what needs to be done.
As long as you turn everything over to the AI, I think you’re going to have collateral damage to use a term for warfare, right? You’re going collateral damage and the collateral damage is going to be possibly your customers or it’s possibly going to be your employees.
And so you need to have that human being in the loop who has the judgment that can make those kinds of key decisions. So, I mean, using another example, one of the issues that’s come up with the frontier models is using them in warfare. All right. So if you use an autonomous model in warfare, if they murder somebody, okay.
Who’s held responsible? Obviously nobody’s held responsible because the machine made the decision. The same applies to cybersecurity. There has to be a human who can be held responsible, but also bring human judgment to those decisions that the AI models lack.
Anders Askasen: I wanna look at your sort of black fedora a little bit, your black hat, if you will.
And and, you know, just just imagine this… Because I I see it on a daily basis. We have enterprises. They… They’ve actually cut back a lot of the security spending in favor of, you know, more tokens, experiment more, more LLMs, more models, more AI. That… That’s what’s being driven from top down approach.
Master OTW: We’re seeing the same. We’re seeing Yeah.
Anders Askasen: And and that… That’s what I’m seeing, which is… I think that’s dangerous in itself, but putting on and looking at your sort of black hat here, where…
Assuming you have an enterprise, they’ve rolled out a whole bunch of agents, and honestly, I think a lot of them have lost control. They they have an agentic AI sprawl.
Where would you focus in? Where would you zoom in first to to sort of penetrate, attack, exploit that vulnerability and and lack of control, lack of governance in in these enterprises?
Master OTW: Well, there’s one of the things that, you know, as an attacker, what I would look at is I would want to probe the site, okay, and get a feel for how the system responds to me.
And that’s going to give me some clues. So everyone, every LLM AI, I mean, technically they’re all LLMs, right? We don’t really have AI yet. These are all LLMs and they all are going to interact with the outside world differently.
So like any reconnaissance effort, I want to know how you’re going to react. I’m going to probe you, I’m going to probe you, I’m to probe you and see how you react. And then based upon those probes, I might even be able to figure out what LLM you’re using, okay? And then if I know what LLM I’m using, I’ll know what the weaknesses are, what the vulnerabilities of that LLM.
So there’s no single answer. It’s like all hacking is that you’re just looking, you’re probing to find where the weaknesses and where the vulnerabilities are. And because you put up an LLM doesn’t mean you don’t have weaknesses. You will have weaknesses with an LLM as well.
And me as an attacker, I will look to try to decipher where those weaknesses are and maybe even go so far. And we haven’t gotten to the far yet. I mean, is the future where I can determine what LLM you’re using by how you respond. So similar to like, when I probe a website, I can determine what technologies you’re using in that website.
And then based upon what I know about those technologies, then I can put together an attack plan because I know what the vulnerabilities are of those technologies.
Anders Askasen: So walk me through. I mean, this sounds like a existing pattern in how we sort of do reconnaissance. We look at vulnerabilities. We try to map the target, and then we zoom in on what we think we can exploit. Is is there any difference in the modus operandi, how we, sort of attack the, AI agentic, enterprise?
Or is
Master OTW: it…
Think it’s still…
We’re still in early stages here. So, you know, this is still developing, but the overall plan is still the same, is to probe, determine what what the defenses are, what the technologies are, and then develop a plan from there. What has changed is the speed, right? And that if you can turn loose an LLM on a website and it can do things that would take me maybe days, okay, to determine and it can do it in minutes.
So the speed is definitely going to change. It’s also, you know, any human being has some limitations into amount of knowledge and information that we can process. The LLM is much better at that than we are. So, think we’re sitting right now at a time where one, the LLMs are going to become much more effective at attacking.
We’ve seen this, this is what’s happened. We’ve heard it’s all in the news. It’s one of the reasons why we have focused on the defensive side. We’re going to help companies put together systems, agentic AI systems that will be able to protect them from the agentic LLM systems attacking them.
And so this is our mission is to put that together. But I think the process is not that much different than what we’re doing right now, except that the timeframe is going to be very compressed and you can get attacks, multiple attacks in a matter of minutes versus, you you might be looking at attacks today, another one in a week, but now we’re gonna see attacks coming, like multiple attacks coming daily from all over the world.
Anders Askasen: Yeah. The speed is just different. One one thing that I’ve discovered with a lot of the customers that we’re engaging with, and that’s one of the reason why we built out the capabilities that we we launched, is the fact that there’s so many different initiatives happening within AgenTic AI.
They spin something up, and then, you know, the the owner of that, he just disappears. He he leaves the company or or moves to a different role or forgets about it. And then you have this rogue agent that is connected to an LLM. It has a whole bunch of different, you know, OAuth claims and and and tokens and and API keys that it can use to do all kinds of stuff. And and no one really has, you know, governance and control of it. So it’s… I think that’s, that’s something that in my mind at least is interesting for enterprises to zoom in on and focus on when it comes to securing the estate. Right.
Master OTW: I don’t
Anders Askasen: know if you agree with that image.
Master OTW: I do. I do agree. And that’s why, one, we are taking our time. We’re watching everybody else make their mistakes and we’re learning from their mistakes. We haven’t put out a product yet, but when we do put out a product, it will be with a service contract. And so that if that person leaves or dies or whatever, you still have a service contract with us who understands how it works and and what it needs to what needs to be done to optimize it.
Anders Askasen: OTW, one of the reasons why we are… Why I invited you to the podcast is because you you invited me to be judge of a tournament that Hackers Arise are are running, and and you call it the Wittgenstein’s tournament, if I’m not mistaken. That’s correct. Wittgenstein’s? Tell me about that, and then tell me what the purpose is of this tournament.
Well, it’s
Master OTW: Ludwig Wittgenstein.
He was a professor at Cambridge. He’s a famous philosopher.
And what he did is he basically built the framework of how we understand languages, right? How we understand language. And basically he built the foundation of what the LLMs work with is that he referred to language as a game. And so every word only has meaning in the context of the words around it.
That’s what an LLM does. So Wittgenstein was famous for this. This is his primary impact upon the world. And so the LLMs are built upon his work.
And then we want to build upon the LLMs work to give companies a robust LLM based defense. And so, that’s why we named it after Wittgenstein.
Wittgenstein, he, well, we don’t want go too deep into what his work is, but that’s why we named it that. And the idea was to put together, we’ve created a contest and the contest we’ve already have over 200 contestants. Wow. Two zero five as of today.
You’re to keep me busy for weeks evaluating. Well, first of all, I want to thank you. I want to thank you for volunteering to do this. No, I think the process is going to be is that we’re going to try to narrow it down to a few and then we’ll send those to you. So you don’t have to watch, you don’t have to view every one of them. So we’ll narrow it down to 10 or 20, and then we’ll work from those 10 or 20. Cause I suspect some of them are going to be much better than the others.
So you’re not going to have to appreciate evaluating 200
Anders Askasen: of them.
I appreciate that. I really do. But at the sort of rules and we kind of touched upon this before when we started the podcast, and that was, you know, there… There’s two different types of models. You have the sort of, closed model, the Anthropic and the OpenAI’s of the world, with with a few exceptions. I mean, OpenAI has a… Has an open model, but, and then you have the sort of open weight, open source type of model. The rule says that it needs to be based on an open source model.
Master OTW: Is that correct? Well, what I did is I put together those rules as to what we would prefer to see. Right. Those are recommendations.
And the more that the contestant complies with those rules, better, the higher score they’re going to get. So I would like to see an open source, open weight model just because, and once again, this is something that Jensen Wong has touched on is that in any type of environment, when you do open source, open weight, or just open source in general, you tend to include all the people of the world as developers, everybody can be a developer, right? And that opens up a whole dynamism in that environment that allows for greater dynamism and technological development. You get more rapid development if everybody can.
And the other thing is that we know what’s under the hood, right? So if you don’t know what’s under the hood, then it’s more difficult for you to actually tailor it to the environment that you’re working in.
Anders Askasen: No, I totally agree. I think that model actually resonates quite well with how the academic world works in general, where you have peer reviewed articles and Exactly. Research where you can actually probe into what you put out there and replicate the same examples. And it kind of resonates with the open source world.
And I think both you and I are prominent, advocates for Linux and and other types of, you know, open source initiatives of of both small scale and large scale. So I’m I’m really looking forward to looking at these different, contributions to the tournament.
Master OTW: One of the things that I want to point out is that the reason that Linux has been around now for what, thirty three years and has created such a robust environment is because it’s open source.
If Linus Torvalds had kept it closed source, it probably would have died off. Okay. Similar to, well, not that it, Unix had a really different, you know, remember the Unix way back when, you know, it was closed source and very expensive. And that’s what Linus Torvalds was basically trying to replicate.
He created an open source environment and look at what it’s done. It’s changed the world. Oh yeah. And so this is the model that we want to work from.
Anders Askasen: Yeah. And I think that’s very admirable, and that’s one of the reasons why when you reached out to me that I said, absolutely, I’ll I’ll I’ll support this in in whatever capacity that I can.
But looking at the sort of submissions that I… You you mentioned that you got over 200 different submissions already, and and it’s growing. We we have applicants.
Master OTW: Not submissions. Yeah.
Anders Askasen: Applicants. Okay. Not submissions. Yeah. But applicants. Right. But what do you what do you expect from these applicants in terms of…
What do you think their contributions are? Do you do you think you’ll see a different set of themes, a different set of problems that are all tackled, some patterns, some trends, or do you think it will be all over the place?
Master OTW: Well, hope it’s all over the place.
I hope it’s all over the place because that’s what we want. We don’t want to just focus on, once again, we’re focusing on the defensive side, right? So we want people to look at various aspects of defending corporate assets. And so, and this means that we might actually end up with an integration of different agents and models as a total package. That’s still to be seen. We’re not closing ourselves off to any possibility.
Anders Askasen: And that’s not narrowing anything down into like a soft corner. It could literally be all over the place.
Master OTW: Could be all over the place. We don’t know what that’s going to be. We do have some prominent universities who also have signed up around the world.
And so we’re hoping that we end up with something, well, we’re pretty confident we’re going to end up with something that’s really robust and it’s going to be really valuable to companies, but we don’t know what that looks like yet, right? So all we did is put together some basic principles and say, please try to stay within these principles. It’s not a requirement, it’s an advisory.
So, and there may be more than, well, what we’ve set it up is that there’s going to be three semi finalists and then there’s going to be one finalist. And so we’re hoping that, you know, maybe one finalist does everything that we need done. That would be simple and clean, but we suspect that we’ll be working with multiple finalists or applicants to put together a final product that people can feel confident is going to protect their enterprise.
Anders Askasen: I think this is a very admirable tournament, and I’m so glad I’m part of it. At the same time, I feel the weight on my shoulders to be able to pinpoint and sort of be part of the judging panel to find the right winner of this competition. But I’m sure there will be some very interesting ideas, and I’m happy to support that. Before we wrap up OTW, and I appreciate your time, is there any advice that you would give to, the the sort of, applicants, that are participating in the in the contest in terms of, what they should focus on? Mean, they start with an empty repo with an idea potentially, but any advice that you can give them, before we wrap up?
Master OTW: Well, I think that probably what I would recommend is that you look at multiple models and multiple agents, okay, or agent frameworks and see what works best. Don’t get locked into one. Right. And try working with different, see how they work. Remember that these agents are going to have to operate in real time.
That means that speed is going to be critical. So the hardware underlying it is going in, communication to the agents is going to have to be robust and rapid, but there’s a lot of really rapid, relatively small models that can do this. Right.
And, but they don’t know, there’s, they can be small and can be tailored to this particular situation. Once again, you don’t need a frontier model that can give you, you know, the physics of a black hole. What we need is we need the information that’s critical of being able to detect attacks against a system. And that’s a much smaller world than what the frontier models are trying to model.
So try to, you know, one, keep in mind that it’s going to have to operate in real time. Trying to keep it small and on robust hardware is important because these models and these agents are going to have to react in real time.
But don’t go in with any preconceived notions as to what’s the best. Go in, experiment, try them out, see how they work and then work from there.
Anders Askasen: I I think that’s great advice. Otw, thank you so much for attending the podcast. Like I’ve said, I’m I’m super thrilled about this tournament. I think there will be some really interesting ideas coming out of it.
And, by the time this hits all the different channels, Spotify, and all the different podcast, environments out there, hopefully, you will get an influx of even more ideas, to the tournament that that I can be part of judging and and…
Together with the other judges. So I really appreciate your time and, looking forward to it. I’m gonna challenge you. Once we’re done and we’ve picked a winner, I’m gonna invite you back to the podcast, and we’re gonna talk about that.
Master OTW: We can demonstrate it. We’ll demonstrate it on the podcast. Sounds good. Did we say that we pushed back the deadline to October 31? So right now on our website, it says September 30, right?
We’ve moved it back. We’ve had so many people in the last couple of weeks, we’ve had so many applications and people are asking us for more time. So we’re going give one more month to the end of October, which is Halloween. I don’t know if there’s any significance there, but, and we’ll give people, so we have like two zero five applicants right now. We have one more month or a month and a half left to get everybody to get their applications in and submit by October 31, your application to win the Wittgenstein Award.
Anders Askasen: That’s great. Now, hopefully, this will be something that we’ll see on a… More than this year, so an annual thing coming up. And if you want to sign up for the tournament, you go to Hackers Arise website, and I’m sure you can navigate from there. We’ll put the link in the description below for anyone who wants to participate or just monitor the tournament because this is this is huge. And, OTW, thank you so much for your time, and I’ll be seeing you.
Master OTW: Thank you, Anders. I really appreciate it. And we appreciate not only being on your podcast, but also being a judge in this really important, endeavor that we’re undertaking.
Good stuff. OTW, over and out.
Anders Askasen: Thank you.
Listen to Radio Logic using one of many popular podcasting apps or directories: