Ophir Kelman, Head of Threat Detection & Security Research, Reco.
Security Researchers: Digital Fighters Series

Reco: “Research is a mix of science and art; a balance between chaos and order”

Ophir Kelman, Head of Threat Detection and Security Research at Reco, explains how AI sprawl is pushing the industry into unfamiliar territory, as part of CTech’s Security Researchers series.

“Research is a mix of science and art; a balance between chaos and order,” says Ophir Kelman, Head of Threat Detection and Security Research at cybersecurity company Reco (and active Vipassana practitioner). Kelman started his BSc in Computer Science at the age of 15, served as a Group Leader in the Cyber Center of Unit 8200 and worked for several years as a Research Team Leader at Hunters before landing at Reco. Today, he works alongside a team of 12 researchers, each with their own distinct security research expertise. "A good analogy," he explains, “is that the Research team to Reco is what Sherlock Holmes is to Scotland Yard.”
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
1 View gallery
Opher Kelman Reco
Opher Kelman Reco
Ophir Kelman, Head of Threat Detection & Security Research, Reco.
(Photo: Courtesy)
According to Kelman, one of the greatest challenges facing the security research field today is “solving the AI security challenges the world is now facing.” He mentions how AI sprawl has “pushed the world into unfamiliar territory.” Specifically, he warns: “The bar for attackers is very low, enabling anyone with malicious intentions to abuse complex systems, [and] the speed of exploitation has accelerated dramatically.”
You can read the entire interview below.
ID Card Company name: Reco Founders: Ofer Klein (CEO), Tal Shapira (CTO), Gal Nakash (CPO) Year of founding: 2020 Current number of employees: 100+
Company Description:
Reco secures the ecosystem so enterprises can enable agents, apps and AI with confidence. The Reco Platform discovers every agent, app, and identity across your environment, prioritizes real risk over raw alert volume, and remediates before exposure becomes a breach. Reco serves over 100 customers, including Fortune 100 companies across financial services, technology, healthcare and cybersecurity.
About Reco's Security Research Team:
The team is composed of 12 researchers each with their own security research expertise. The team is responsible for solving the toughest cybersecurity challenges our customers face today and will face in the future. More specifically, the team detects emerging threats, creates and tunes threat detection rules and deep-dives into AI Applications and Platforms to provide security protection.
What is your background in cyber, and what led you to specialize in security research?
I was always attracted to technology and started my BSc in Computer science at the age of 15. Later, I served as a Group Leader in the Cyber Center of Israel's elite Unit 8200, leading research and development teams across multiple cybersecurity domains. Before Reco I worked for several years at Hunters as Research Team Leader, identifying and neutralizing sophisticated cyber threats.
I find threat detection engineering really fascinating. I know it may sound weird, but this area combines both cyber challenges and data analysis. You can get good results by being good at one of them. But when you combine both you get really good detections, and there is a thrill in deploying a new version of a detection rule with high SNR which now catches only suspicious events.
What does your security research team look like in action?
Security Research teams at product companies simply “play on hard mode”. Unlike other research teams, we are customer-obsessed and everything we produce must be production grade. In order to meet that standard we have our own agile scrum methodology and work shoulder to shoulder with Product, R&D and the field.
Research is a mix of science and art; a balance between chaos and order. We embrace the chaos to innovate and come up with novel solutions and balance it with order to make sure we deliver business value to our customers.
For example, given a research subject we allocate an exploration period to reduce risks and unknowns, and to figure out everything about the task at hand. At this stage the researcher is “freestyling” completely, pursuing directions intuitively or methodically according to their decision. The results of the exploratory research are then used for a more structured stage of research and implementation where we are able to deliver business value while also being confident about the delivery date.
How does the research team influence your company at large?
A good analogy is that the Research team to Reco is what Sherlock Holmes is to Scotland Yard. The research team ensures that Reco is at the forefront of cybersecurity. Simply put, we make sure that Reco prevents breaches and detects attacks as early as possible. It is the research team's responsibility to figure out how to deal with cyber threats and attackers.
What has been your team’s most significant security discovery to date?
We just published an ongoing emerging threats campaign targeting Salesforce and ServiceNow endpoints: The “City-Forum” Campaign - An advanced attacker is targeting Salesforce and ServiceNow instances worldwide.
This campaign stands out mainly for the novelty of its tooling: rather than the well-documented Aura/guest-user abuse used by actors like ShinyHunters, this attacker also targets Salesforce's Lightning Web Runtime UI-API via GraphQL and a native, undocumented ServiceNow endpoint (/api/now/sp/search). Neither has any public write-up or known offensive tool behind it, indicating original research rather than off-the-shelf scanning.
Who or what is your 'Moby Dick'?
Solving the AI Security challenges the world is now facing is our “Moby Dick”. “AI Sprawl” has pushed the world into unfamiliar territory: The bar for attackers is very low, enabling anyone with malicious intentions to abuse complex systems. Not only that, but the speed of exploitation has accelerated dramatically.
Additionally, “AI sprawl” introduces risks that are unrelated to the intention of the user. An ambitious AI agent with wrong instructions or permissions may have a severe impact on an organization.
How would you characterize the competition between research teams today?
Actually, I feel that security research is a field where knowledge is shared across competitors in order to defeat attackers.
What is your take on the future of the human security researcher?
AI is a force multiplier. A good security researcher, when using it correctly, becomes 10 times more productive. But that means it is even more important for the researchers to invest in the planning process, problem definition, methodology, etc.
A fitting analogy would be the difference between driving a commercial car and a Formula 1 car. An unskilled driver in a Formula 1 car can do a lot of damage, but a skilled one can achieve greatness.
Another point worth mentioning is that AI also creates a lot more security work, which in turn increases the demand for security researchers.