Darren Anstee, CTO for Security, NETSCOUT: “DDoS attacks have become a pervasive threat to every organisation that participates in the Internet’s digital ecosystem”

Having spent the early part of his career working with network switching and routing technology, Darren Anstee stepped into cybersecurity with a deep understanding of how networks operate beneath the surface. That foundation shaped his next three decades in the industry, taking him from systems engineering to his current position as CTO for Security at NETSCOUT.

In this exclusive interview, Darren explains that one of the greatest challenges facing cybersecurity leaders is simply in understanding where it is that risks are coming from. Digital environments have seen a large increase in “opaque inter-dependencies”, while an expanded range of threats making it harder to build a picture of an organisation’s full exposure surface.

Then we come to the AI arms race. Threat actors can now use AI to orchestrate attacks that once required significant expertise, significantly lowering the barrier to entry. For Darren, the takeaway is simple: “adaptive and automated offensive measures will overwhelm traditional defences, so those defences must become adaptive and automated to counter this”.

For those now considering expanding into the field of cybersecurity, Darren advocates for understanding the industry from multiple directions. Professionals should learn how technologies work in practice, whilst also understanding the underlying systems and operations that drive them. As he puts it, “understanding how things work top-down AND bottom-up is key,” allowing professionals to make proper use of existing tools, and more importantly knowing when these tools fall short of the task.

That all-perspective understanding from Darren is significantly more than just preaching, as it mirrors his own career experience. So to get a better understanding of how this philosophy came about, we started by asking about his path into the world of cybersecurity.

Could you please introduce yourself to our audience and share how you ended up working in cybersecurity? 

I am NETSCOUT’s chief technology officer for security – I work with our CEO and founder Anil Singhal to help define the strategy for our security products. As the market leader in both distributed denial-of-service (DDoS) defence and service assurance, NETSCOUT’s strategy is uniquely focused on providing enterprise and service provider customers with broad and deep network visibility. It also supplies businesses with the advanced defensive technologies and actionable intelligence they need to protect the availability of their key assets from sophisticated cyber-attacks. 

I came into network security just as I turned 30 – sadly a long time ago – with about ten years of experience of working for vendors of network switching and routing technologies as a network engineer. This background gave me a deep understanding of network infrastructure, routing and traffic analysis, particularly focused on how large-scale carrier environments operate. Understanding how data is accessed across networks, the architecture and infrastructure components made transitioning into security a very natural step for me. 

I joined Arbor Networks in 2003 as a systems engineer, with Arbor’s focus being on delivering scalable network visibility and DDoS detection to ISPs. Over the following years I moved into the role of a solutions architect, and then managed the solutions architecture team across the world. When NETSCOUT acquired Arbor Networks in 2015, I stepped into the role of chief security technologist before transitioning into my current position. Today, I use my 30+ years of industry experience to help NETSCOUT keep global network infrastructure secure and resilient.

What are the biggest cybersecurity challenges those in leadership roles are facing? 

To me, the biggest hurdle for leadership is getting a consistent picture of the risks that different threats pose across the business, so investment can be focused appropriately. A second challenge is gaining visibility into whether risk-management investments are actually delivering business value.

Looking at the first challenge, the infrastructures and digital ecosystems every business relies upon have become hugely complex in recent years, with a threat surface that is not always easy to map given opaque digital supply chains. And the threats businesses face are constantly evolving, with more sophistication and a broader set of adversaries, each with differing motivations. 

Geopolitically motivated hacktivist groups – collectives of threat actors who aim to disrupt the critical infrastructure of events, organisations, and nations they see as acting in opposition to their ideological vision, have been a key driver of risk in recent years. This is especially true when it comes to DDoS attacks, which is one of the areas where I specialise.

DDoS attacks consume the resources within networks, infrastructure and application services, rendering them inaccessible to genuine users. In the past couple of years, we have not only seen more hacktivist groups leveraging DDoS attacks than ever before, but also (Turbo Mirai) botnets made up of millions of IoT devices generating larger attacks than ever before. What’s more, AI chatbots are being integrated into DDoS tools to allow attacks to be launched using natural language instructions, obviating the need for any technical knowledge. DDoS attacks have become a pervasive threat to every organisation that participates in the Internet’s digital ecosystem. 

Moving on to the second challenge, this is around bridging the gap between the reporting generated by a business’ deployment of technology, threat intelligence, services etc., and the value these investments deliver (or risks they reduce). This has been an issue for a long time, with many organisations coming up with their own internal, often costly, mechanisms to achieve this. However, we are on the cusp of change here, as AI LLMs are now being seen as a way to integrate, correlate and report on data (in a tailored way) to solve this problem. These tools rely on the right data being available in the right format – and that requires the right technology to create it.

What are some prevention strategies you believe every business should adopt? 

This is difficult as there is no one-size-fits-all answer. Nevertheless, I would say what’s important is that any strategy is built around a continuous process that evaluates security as business needs, technology and threats evolve. People often talk about the value of preparation – Proper Preparation Prevents Poor Performance, after all – and this is true, but this can imply that risks can be managed one-and-done – rather than within an iterative process. 

The other key to success concerns ensuring that top-down business needs meet bottom-up capabilities in a constructive way. If this can be achieved, then the whole cycle of technology selection, investment, reporting, monitoring etc., is much smoother for everyone.   

To achieve the above, organisations must select vendors and partners that can advise on best practice, provide relevant threat intelligence at multiple levels, and deliver consistent visibility of what is going on across an organisation’s environment – ideally with that visibility driving multiple business use cases (to avoid ‘gaps’ across responsibility domains). 

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good? 

The appeal for threat actors is largely the same as those of us who use generative AI in our everyday lives: automation and multiplication of capability. For example, AI-enhanced DDoS attack tools have given novice actors the ability to launch attack campaigns that would previously have required both technical knowledge and experience. With these tools, the actors need only request a desired outcome, with AI orchestrating the reconnaissance and attack vector selection. 

Looking at the other side of things, organisations also have AI at their disposal. AI derived threat intelligence is now available, providing more accurate and timely data that can be used to accelerate both threat detection and mitigation. Machine learning is being integrated into many tools to help security professionals both identify a broader range of threats and shorten the time between threat detection and response. And, of course, there’s the integration of co-pilot chatbots into monitoring tools, assisting lower-skilled staff with more complex tasks, multiplying their capability. 

There needs to be an acceptance that adaptive and automated offensive measures will overwhelm traditional defences, so those defences must become adaptive and automated to counter this.

What role do you think governments play when it comes to cybersecurity? 

Governments must establish frameworks and regulation that provide clear guidance for the controls needed to protect confidentiality, integrity and availability of digital assets – and they need to do this without stifling innovation and/or creating a check-box culture. The key is to involve businesses of varying scales in the definition of best-practice, so that the risks and realities of business stay front and centre. 

On top of this, governments should also facilitate open exchange of information between organisations so that knowledge on identified threats and successful defensive mechanisms can be shared. 

Governments must also capitalise on their unique ability to pre-empt large-scale threats. By driving open discussion and actively collaborating with one another, international leaders can pave the way for more coordinated, resilient, and durable defences worldwide.

What’s something that has drastically changed about cybersecurity since you first got started in the field? 

I think the biggest changes are in the level of complexity of the digital ecosystems we have to defend, with many (opaque) inter-dependencies. What’s more, the threats we face have also evolved significantly, with large-scale botnets, sophisticated attack mechanisms and AI being used against us.

What advice do you have for aspiring professionals wanting to work in cybersecurity? 

This is probably an old-fashioned view, but understanding how things work top-down AND bottom-up is key for me. This means coming at new technologies, and threats, from two directions. From the top-down, understanding how the tools available can be used to solve problems, their strengths and weaknesses, and the contexts in which they are most effective And, from the bottom-up, understanding how those tools, threats and networks actually work, what is happening beneath the surface, and the mechanisms that drive their behaviour.

As an example, I have spent a lot of time working with different LLMs to ensure I can take full advantage of their capabilities and use them to do more, more efficiently. But I also enrolled in a course to understand how AI works from first principles, including the underlying mathematics and theory.

To me, the two approaches complement one another, allowing quicker identification of the best-path to complete a task. In the event the available tools can’t help, you know what to ask for (or can build your own).

More interviews

About The Author

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.