Where Science Meets Art: Navigating the Chaos and Order of Research

0
4

Key Takeaways

  • Ophir Kelman leads a 12‑person security research team at Reco, blending deep technical expertise with a customer‑obsessed, production‑grade mindset.
  • His career began early: a BSc in Computer Science at 15, leadership in Israel’s Unit 8200, and a stint as Research Team Leader at Hunters before joining Reco in 2020.
  • Kelman views research as a balance of science and art—chaos for innovation, order for delivering tangible business value—using an exploratory phase followed by structured implementation.
  • The Reco research team functions like “Sherlock Holmes to Scotland Yard,” ensuring the company stays ahead of threats, detects attacks early, and prevents breaches.
  • A recent highlight involved uncovering a novel attack chain that abused Salesforce’s Lightning Web Runtime UI‑API via GraphQL and an undocumented ServiceNow endpoint (/api/now/sp/search), showcasing original threat‑hunting rather than reliance on public tools.
  • The team’s “Moby Dick” is solving the emergent AI security challenges posed by AI sprawl, which lowers the attacker barrier, accelerates exploitation, and introduces risks unrelated to user intent.
  • Kelman believes security research is a collaborative field where knowledge is shared across competitors to collectively defeat attackers.
  • In the AI era, a skilled researcher becomes a force multiplier—AI can make them up to ten times more productive—but success still hinges on rigorous planning, problem definition, and methodology.
  • As AI generates more security work, demand for human experts will rise, reinforcing the strategic value of teams like Reco’s in safeguarding enterprise AI agents, apps, and identities.

Introduction to Ophir Kelman and His Role at Reco
Ophir Kelman serves as the Head of Threat Detection and Security Research at Reco, a cybersecurity firm founded in 2020 that protects enterprises as they adopt AI agents, applications, and identities. He leads a dedicated team of twelve researchers, each bringing distinct expertise to the table. Kelman likens the research team’s function to that of Sherlock Holmes in relation to Scotland Yard: the group provides the insight and ingenuity needed to keep Reco at the forefront of threat detection and prevention.

Early Academic and Military Background
Kelman’s fascination with technology began early; he enrolled in a BSc in Computer Science at the age of fifteen. After completing his studies, he joined Israel’s elite Unit 8200, where he served as a Group Leader in the Cyber Center, overseeing research and development across multiple cybersecurity domains. Prior to his current role, he spent several years at Hunters as a Research Team Leader, focusing on identifying and neutralizing sophisticated cyber threats. This trajectory equipped him with both deep technical foundations and leadership experience in high‑stakes environments.

Philosophy of Security Research
For Kelman, security research is “a mix of science and art; a balance between chaos and order.” He advocates embracing chaos during the exploratory phase to foster novel ideas and unconventional approaches, then imposing order during the implementation stage to ensure the work delivers concrete business value and can be scheduled reliably. This dual‑mode methodology allows the team to innovate while remaining accountable to product timelines and customer expectations.

How the Research Team Operates Within Reco
Unlike academic research groups, Reco’s security research team operates “on hard mode,” meaning every output must be production‑grade and directly address customer needs. The team follows an agile scrum framework, working shoulder‑to‑shoulder with product, R&D, and field teams. This close collaboration ensures that detection rules, threat models, and mitigation strategies are not only technically sound but also integrated seamlessly into Reco’s platform and aligned with real‑world risk prioritization.

Impact of the Research Team on the Company
Kelman’s analogy of Sherlock Holmes to Scotland Yard captures the team’s strategic value: they uncover hidden threats, devise detection mechanisms, and enable Reco to stop attacks before they materialize. By continuously surfacing emerging risks and refining detection logic, the research team helps the company maintain a low false‑positive rate while capturing high‑signal events, thereby protecting over 100 customers—including Fortune 100 enterprises across finance, tech, health, and cybersecurity.

Notable Security Discovery
One of the team’s most significant achievements involved a previously undocumented attack campaign that abused Salesforce’s Lightning Web Runtime UI‑API via GraphQL and leveraged a hidden ServiceNow endpoint (/api/now/sp/search). Unlike the well‑known Aura/guest‑user exploitation used by groups such as ShinyHunters, this chain required original research, as no public write‑ups or offensive tools existed for the abused interfaces. The discovery underscored the team’s ability to identify novel vectors and prompted the rapid creation of detection rules to safeguard Reco’s customers.

The “Moby Dick”: AI Security Challenges
Kelman describes solving the AI security challenges posed by today’s AI sprawl as the team’s “Moby Dick.” He warns that the proliferation of AI tools has lowered the barrier for attackers, allowing even novices to exploit complex systems at unprecedented speed. Moreover, AI agents operating with incorrect instructions or excessive permissions can cause unintended, severe damage—risks that arise irrespective of the user’s original intent. Tackling these issues demands continuous research into AI‑specific threat models, behavior analysis, and mitigation strategies.

Collaborative Nature of Security Research Community
Contrary to a zero‑sum view, Kelman believes security research thrives on shared knowledge. He observes that researchers across competing organizations often exchange insights, indicators of compromise, and defensive techniques to collectively raise the cost of attack for adversaries. This cooperative spirit accelerates the diffusion of effective defenses and helps the entire ecosystem stay ahead of evolving threats.

Future of Human Security Researchers in the AI Era
AI, according to Kelman, acts as a force multiplier: a skilled researcher who leverages AI effectively can become up to ten times more productive. However, this amplification also raises the stakes for proper planning, problem definition, and methodological rigor—much like the difference between an unskilled driver in a Formula 1 car versus a seasoned one. Paradoxically, while AI automates certain tasks, it also generates additional security work, increasing the demand for human experts who can interpret AI outputs, refine models, and address novel attack surfaces.

Conclusion: Vision for Reco’s Research Team
Looking ahead, Kelman envisions Reco’s research team continuing to serve as the organization’s Sherlock Holmes—proactively hunting threats, shaping detection capabilities, and enabling customers to adopt AI‑driven technologies with confidence. By maintaining a disciplined balance of exploratory creativity and structured execution, collaborating closely with product and field teams, and staying attuned to the evolving AI threat landscape, the team aims to keep Reco—and its clients—secure in an increasingly complex digital world.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here