Why Antivirus Fails at File Scanning | OPSWAT CEO Benny Czarny on CDR
Security Unfiltered PodcastSeptember 28, 2026

Why Antivirus Fails at File Scanning | OPSWAT CEO Benny Czarny on CDR

Antivirus is built to protect the device, not to judge a file. OPSWAT founder and CEO Benny Czarny explains why file scan detection lands somewhere between 5% and 40% even with AI engines, why 99.9% detection isn't good enough for a nuclear plant, and how Content Disarm and Reconstruction (CDR) protects critical infrastructure by assuming every file is malicious and rebuilding it clean.

We get into:
- How Benny bootstrapped OPSWAT and built a common language that let antivirus, VPN, firewall, and encryption products talk to each other
- Testing every antivirus on the market with live malware, and what it showed about real-time protection vs file scanning
- Why multiscanning with 30 engines still let malware through
- How CDR rebuilds JPEG, PDF, and Office files to strip buffer overflow exploits before they land
- Data diodes, one-way optical firewalls, and securing file flow into air-gapped networks
- Offline patching, and why critical infrastructure teams need their own training (OPSWAT Academy)

Benny's book, Cybersecurity Upside Down, covers the statistics and architecture behind all of this.

Find Benny and OPSWAT:
OPSWAT: https://www.opswat.com
Benny Czarny: https://www.bennyczarny.com
OPSWAT Academy: https://learn.opswatacademy.com

Chapters:
00:00 Welcome Benny Czarny
02:22 How Benny got into cybersecurity
04:58 Big company vs small company lessons
08:20 First hires and scaling from generalists to experts
08:59 The problem that started OPSWAT
12:01 Testing every antivirus with live malware
13:42 Why antivirus file scanning fails, even with AI
17:36 Multiscanning file flow into critical infrastructure
19:45 Why 99.9% detection isn't good enough
20:09 Assume every file is infected: CDR explained
23:52 How CDR strips buffer overflow exploits
26:50 Dolly the sheep and distilled water analogies
28:16 From 15 file types to hundreds of formats
29:51 Data diodes and one-way optical firewalls
32:05 What CDR can't rebuild: executables and sandboxing
33:48 Walled gardens and unpatched networks
35:32 Offline patching and OPSWAT Academy
39:12 Where to find Benny and his book

#cybersecurity #criticalinfrastructure #OTsecurity

Affiliates
➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh
➡️ OffGrid Coupon Code: JOE

➡️ Unplugged Phone: https://unplugged.com/
Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout

*See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions.

Tesla Referral Code: https://ts.la/joseph675128

Follow the Podcast on Social Media!

Instagram: https://www.instagram.com/secunfpodcast/
Twitter: https://twitter.com/SecUnfPodcast
Benny Czarny, OPSWAT, content disarm and reconstruction, CDR cybersecurity, critical infrastructure security,