Documentary recordVideo, presentation and full transcript.
ORC4 on stage
Malte Liedtke presents Genetic AI at the Cybersecurity Summit 2025 in Hamburg.
Hello, dear reader. You have met Malte Liedtke already. If not, start here. Today I was going to introduce you to his brainchild, ORC4, although on second thought there is no need, because in a couple of minutes Malte is going to introduce it himself, and I suspect that will be far more entertaining than anything I could say in advance.
Orca Cyber Security's recently closed website described him as CTO & Inventor of ORC4, the mastermind behind ORC4's groundbreaking Genetic AI system and a man redefining the future of digital defense.
Having watched the presentation, I came away understanding that every problem in cybersecurity has now been solved by this product. Because it does everything. Remarkable, then, that none of us has heard of it. There are surely reasons for that, and we will come back to them another day.
For now, just watch him presenting on stage at the Cybersecurity Summit in Hamburg, 15 May 2025.
One more thing, a personal observation and nothing else. I am no great expert in cybersecurity, but I am a reasonably good one in public presentations. And it strikes me as slightly odd to watch the creator of a unique world-first product glance uncertainly at the screen each time, wait for the next slide to appear, and then offer a light comment on it. My personal view, purely a value judgment: an inventor, in my experience, does not look at the slides at all. He speaks to the room with his eyes alight, because he is speaking about the thing he built himself, and wants the world to hear it.
But please, see for yourself and draw your own conclusions.
With that, I take my leave. Enjoy the viewing.
Video record
The complete presentation
Source material
ORC4 presentation





































Original language
German transcript
Gross transcription errors corrected. Spoken structure retained.
So, was mache ich hier? Ich will uns vorstellen als Cybersecurity-Firma ORC4. We are based in Dubai, Katar, GCC general. Wir haben das erste Genetic AI entwickelt. Wir sind damit an den Markt gegangen im März diesen Jahres, hauptsächlich im Bereich GCC. Mit Partnern in Europa starten wir jetzt zusammenzuarbeiten, um es weiter in Europa zu vertreiben.
Wer sind wir? Henrik Christiansen, der auch hier sitzt im Publikum, und meine Wenigkeit. Was ist Genetic AI? Genetic AI ist der nächste Schritt der Evolution von AI. Es ist selbständig, es ist autonom, es ist selbstheilend, selbstentwickelnd. Wir brauchen kein menschliches Eingreifen mehr, kein Deep Learning. Es macht es bei sich selbst, über Mutationen, über verschiedene Angriffe, Angriffsmodelle.
Es führt regelmäßig Penetrationstests bei sich selbst durch, um sich weiterzuentwickeln, um verschiedene genetische Algorithmen einzubauen, damit es verschiedene Bereiche gegen Angriffe absichert. Es ist virenbasiert. Ich mache mal ein bisschen weiter hier. So, es lernt von jedem Angriff in den einzelnen Mutationen.
Wir können es in Firmen einsetzen, es ist höchst flexibel. Im Prinzip basiert ORC4, also die Genetic AI, auf genetischen Strängen in der Programmierung, wo wir inzwischen Antivirus-Parts drin haben. Wir haben eine Firewall included, wir haben auch verschiedene Bereiche.
Also es prüft auch nach, woher Angriffe kommen. Dadurch, dass wir mit Bots arbeiten, unter Genetic, sammelt es im World Wide Web die verschiedenen Daten, arbeitet sie ein und entwickelt sich dadurch weiter. Es sagt Angriffsmodelle voraus. Und deswegen ist unsere Sicherheit, also wir sind momentan bei 97 Prozent. Wir arbeiten mit verschiedenen Firmen in Dubai zusammen, mit den ersten Firmen in Deutschland, die testen, wie das Programm läuft.
Ja, also adaptive behaviour-based AI-powered penetration testing kommt immer wieder. Self-healing network, was wirklich interessant ist in dem Bereich. Natürlich gibt es Angriffe, es wurde auch geknackt, aber in dem Moment hält es den Angriff auf. Also wenn es ein Virus ist, Ransomware, stellt es ihn in Quarantäne, macht eine Mutation und heilt sich selber.
Und da sind wir momentan bei Sekunden, und es ist halt der nächste Schritt. Es ist auf Endgeräten. Momentan läuft eine Testphase mit 60.000 Endgeräten, gleichzeitig ist ORC4 im ganzen System vertreten.
Also vom Stand her sind wir most advanced im Moment. Es ist weltweit noch nicht von den großen Firmen weiterentwickelt worden, nur von uns. So, das 100 Prozent Autonome, das ist das Interessante für Genetic AI. Wir haben kein menschliches Eingreifen mehr, bedeutet auch, dass wir den Faktor Mensch rausnehmen können.
Wir haben natürlich einen Administrator, der Kontrolle über das gesamte Programm hat, aber die Endnutzer haben keine Kontrolle darüber. Das macht ORC4 autonom, autonom, ja, autonom. Nur einem Administrator in einer großen Firma, in einem Layer, werden die Angriffe gezeigt. Aber auch er braucht nicht einzugreifen, weil ORC4 sich durch Self-Learning selbst heilt und in den verschiedenen Mutationslehren weiterentwickelt.
So, hier haben wir einmal eine kleine Aufstellung. Wir sind nicht statisch. Es kommt nicht vom Deep Learning, weil es das selbständig macht. Keine static rules, requirements und [unverständlich]. Hier haben wir die verschiedenen Aufstellungen.
Wir arbeiten mit zwei anderen Firmen zusammen, die wir mit aufgenommen haben, Invisinet und XIID. Mit denen zusammen haben wir auch Weiterentwicklungen gemacht, wodurch wir die Genetic AI einsetzen und erfolgreich nutzen konnten. Also Network Security, Endpoint Security, Incident Response, Cloud Security, Application Security, Identity Access Management, Penetrationstests, die es selbständig regelmäßig durchführt, um sich selbst zu testen.
Wir machen auch Security Consulting, Security Awareness Training für die Firmen, aber hauptsächlich strukturieren wir uns um ORC4, um das Programm. In welchen Bereichen sind wir? Wir kommen ursprünglich aus dem Bereich Renewable Energy. Ich komme aus dem Bereich Renewable Energy, habe dort in Katar gearbeitet, habe dort Elektromobilität für das Königshaus errichtet.
Da war halt der Case: Wir wurden vor drei Jahren gehackt, eine Ladestation von einem großen Anbieter. Meine Aufgabe war herauszufinden: Gibt es eine Lösung dafür? Ich habe natürlich in den USA angefragt, in Europa, Asien, und es gab zu dem Zeitpunkt keine vernünftigen Lösungen für Renewable Energy. Also ORC4 war ursprünglich dafür gedacht, erneuerbare Energie zu beschützen, Solaranlagen, Ladestationen, Windparks et cetera.
Als wir ORC4, die Vier ist drin, immer weiterentwickelt haben, von ORC1 zu ORC4, war der letzte Schritt Genetic AI, das wir quasi in den ORC4-Server einspielen. ORC4 verteilt sich selbständig im System, übernimmt es und übernimmt die ganzen Sicherheitsfunktionen. Momentan können wir dadurch fünf bis fünfzehn verschiedene Security-Programme in den verschiedenen Bereichen ersetzen.
Daraufhin hat mein Geschäftspartner gesagt, wir müssen das noch ein bisschen erweitern. Wir sind dann in Healthcare gegangen, Logistik, Bankensysteme, Telekommunikationsdaten und Government. Momentan, wie gesagt, sind wir hauptsächlich im GCC und in Asien unterwegs. Und jetzt hier in Hamburg das erste Mal, dass wir uns auf dem europäischen Markt vorstellen, dass die Leute uns langsam kennen und wir mit Partnern vor Ort arbeiten.
Hier sind noch einmal die verschiedenen Bereiche, in denen wir momentan tätig sind. Ich entschuldige mich auch, ich bin hier mehr oder weniger so ein bisschen reingesprungen. Im Healthcare-Bereich haben wir jetzt die ersten Erfahrungen in Katar mit einer Privatklinik gemacht, die auch einen Hackerangriff hatte und lahmgelegt wurde. Die Daten der Patienten wurden gestohlen. Wir konnten das Problem beheben, indem wir ORC4 in ihr System geladen haben, als sie es getestet haben.
Im Moment machen wir das. Genetic AI ist für viele Leute nicht wirklich greifbar, weil es komplett neu ist, ein neues System ist. Viele vertrauen dem System noch nicht, weil es autonom ist und man nicht wirklich eingreifen kann. Wir bieten Firmen an: OK, wir kommen zu euch, ihr baut eine Sandbox, wir geben euch das Programm, ihr habt vier Wochen Zeit, das wirklich zu testen, wie weit ihr selber kommt, einen Pentest durchzuführen.
Bis jetzt haben wir sehr gute Erfahrungen damit gemacht. Die Firmen sind zufrieden und ja, das ist momentan der Stand von ORC4. Natürlich ist es schwierig, es ist nicht wirklich greifbar, weil es Genetic AI ist.
Zurzeit sind wir auch in einer Testphase mit einem großen europäischen Mobilfunkanbieter. Die testen es vier Wochen und wir warten da jetzt bis Mitte Juni, nein, Mitte Mai. Nächste Woche ist der Test beendet und dann werden wir da weiter voranschreiten.
Natürlich ist in der heutigen Zeit Defence und Military ein großes Thema. Ich komme vom Militär, von der deutschen Bundeswehr. Da hatten wir sehr große Probleme mit den Daten. Das Knowledge ist natürlich mit eingeflossen, ist aber nicht unser Main, das ist eher an der Seite. Wir wurden auch von Polizeieinheiten angefragt, ob man das nutzen kann, aber auch vom GCC.
Krypto ist momentan ein ziemlich großes Thema, was wir auch mit [unverständlich] abbilden können. Da gibt es verschiedene Mutationen, die zum Beispiel eine Decryption von Bitcoin-Wallets machen können, was auch ein größeres Thema ist. Based sind wir, wie gesagt, in Dubai und Katar. In der Schweiz haben wir jetzt ein Büro für den europäischen Markt eröffnet und gehen ab nächsten Monat auch nach Singapur.
Und das war es eigentlich auch schon von der Präsentation. Ja, vielen Dank.
Also ich muss sagen, ich habe so zwischendurch gedacht: Wenn das alles so funktioniert, was machen dann die anderen? Was braucht es wirklich noch? Niemand macht es mehr selbst, Self-Healing hieß es.
Ja, das macht es selber, es entwickelt sich selber weiter. Es braucht keine Menschen fürs Deep Learning mehr, Deep Learning mehr. Das haben wir komplett ausgemerzt. Wir haben auch nur ein kleines SOC-Team, fünf Mann, das reicht vollkommen aus.
Und alle Daten, das Gute an ORC4 ist auch: Wenn es in einer Firma installiert wird, bekommen wir keine Daten von der Firma, weil die Mutation quasi von der Mutter, von der Mutter, immer nur rausgeht. Aber wir bekommen keine Daten von den Kunden. Die Angriffe werden uns natürlich reportet, wir haben das auch dokumentiert, allerdings keine tieferen Informationen, was sehr wichtig ist für große Firmen, dass keine Informationen zu uns kommen.
Des Weiteren sind es nur Daten, die von uns, die Mutation, zu unserem Programm gehen und keine Daten, die wieder bei uns gespeichert werden. Wir können das Programm auch vor Ort auf Servern installieren. Wir haben damit nichts zu tun, es depends ganz davon, was der Kunde von uns möchte.
Full text
English transcript
Translated from German. Gross transcription errors corrected; repetitions, false starts and spoken structure retained.
So, what am I doing here? I want to introduce ourselves as the cybersecurity company ORC4. We are based in Dubai, Qatar, the GCC in general. We developed the first Genetic AI. We launched it on the market in March this year, mainly in the GCC region, and are now starting to work with partners in Europe to distribute it further in Europe.
Who are we? Henrik Christiansen, who is also sitting here in the audience, yours truly, and what is Genetic AI? Genetic AI is the next step in the evolution of AI. It is independent, autonomous, self-healing and self-developing. We no longer need human intervention, no deep learning, it does it itself through mutations, through various attacks and attack models.
It performs penetration tests on itself regularly in order to develop further, to incorporate various genetic algorithms so that it can secure different areas against attacks. It is virus-based. I'll continue a little further here. So, it learns from every attack in the individual mutations.
We can use it in companies; it is highly flexible. In principle, ORC4, that is, Genetic AI, is based on genetic strands in programming, where we now have antivirus parts included. We have a firewall included, and we have different areas as well.
So it also checks where attacks come from. Because we work with bots under Genetic, it collects various data from the World Wide Web, processes it and develops further as a result. It predicts attack models, and that's why our security is currently at 97%. We are working with various companies in Dubai and with the first companies in Germany that are testing how the program runs.
Yes, so adaptive behaviour-based AI-powered penetration testing comes up again and again. Self-healing network, which is really interesting in this area. Of course there are attacks, it has also been hacked, but at that moment it contains the attack. So if it's a virus or ransomware, it puts it in quarantine, mutates and heals itself.
And that's where we are right now. We're talking seconds, and it's just the next step. It's on end devices. We're currently running a test phase with 60,000 end devices, and at the same time ORC4 is represented throughout the entire system.
So, in terms of status, we are the most advanced at the moment. It has not yet been developed further by the big companies worldwide, only by us. So the 100% autonomy is what is interesting for Genetic AI. We no longer have human intervention, which also means that we can remove the human factor.
Of course, we have an administrator who has control over the entire program, but the end users have no control over it. That makes ORC4 autonomous, autonomous, yes, autonomous. Only an administrator in a large company, in a layer, is shown the attacks, but even he does not need to intervene because ORC4 heals itself and develops further through self-learning in the various mutation theories.
So, here we have a small list. We are not static. It does not come from deep learning because it does it independently. No static rules, requirements and [unclear]. Here we have the various lists.
We work with two other companies that we have included, Invisinet and XIID, and together with them we have also made further developments, which then led to us being able to use Genetic AI and use it successfully. So: network security, endpoint security, incident response, cloud security, application security, identity access management, penetration testing, which it performs independently on a regular basis to test itself.
We also do security consulting and security awareness training for companies, but mainly we structure ourselves around ORC4, around the program. What areas are we in? We originally come from the renewable energy sector. I come from the renewable energy sector, worked there in Qatar and set up electric mobility there for the royal family.
There was a case where we were hacked three years ago, a charging station from a major provider. My job was to find out if there was a solution for this. Of course, I inquired in the US, Europe and Asia, and at that time there were no reasonable solutions for renewable energy. So ORC4 was originally intended to protect renewable energy, solar panels, charging stations, wind farms and so on.
As we continued to develop ORC4, the four is in the name, from ORC1 to ORC4, the last step was Genetic AI, which we basically feed into the ORC4 server. ORC4 independently distributes itself throughout the system, takes over and handles all the security functions. Currently, we can replace five to fifteen different security programs in the various areas.
My business partner then said we needed to expand a little further. We then moved into healthcare, logistics, banking systems, telecom data and government. At the moment, as I said, we are mainly active in the GCC and Asia. Now, here in Hamburg for the first time, we are introducing ourselves to the European market, slowly getting people to know us and working with local partners.
Here are the different areas in which we are currently active. I apologise, I more or less jumped in here. We have now had our first experience in healthcare in Qatar with a private clinic that also had a hacker attack and was paralysed. The patients' data was stolen. We were able to fix the problem by loading ORC4 into their system when they tested it.
At the moment, we are doing that. Genetic AI is not really tangible for many people because it is completely new, a new system. Many do not yet trust the system because it is autonomous and you cannot really intervene. We offer this to companies: OK, we'll come to you, you build a sandbox, we give you the program, and you have four weeks to really test it and see how far you can get on your own, to carry out a penetration test.
So far we've had very good experiences with it. The companies are satisfied, and yes, that's the current status at ORC4. Of course, it's difficult, it's not really tangible because it's Genetic AI.
We are currently in a test phase with a large European mobile phone provider. They are testing it for four weeks and we are now waiting until mid-June, no, mid-May. The test will be completed next week and then we will move forward.
Of course, defence and the military are big topics these days. I come from the military, from the German Armed Forces, where we had very big problems with data. So that knowledge has naturally been incorporated, but it's not our main focus, it's more of a side issue. We're working on it. We've been asked by police units whether it can be used, but also by the GCC.
Crypto is currently a pretty big topic, which we can also map with [unclear]. There are various mutations that can, for example, decrypt Bitcoin wallets, which is also a major issue. As I said, we are based in Dubai and Qatar. We have now opened an office in Switzerland for the European market and will also be moving to Singapore next month.
And that's pretty much it for the presentation. Yes, thank you very much.
I have to say, I was thinking to myself in between: if all of this works, then what will the others do? What do they really still need to do? No one does it themselves any more; it's called self-healing.
Yes, it does it itself, it develops further by itself. It no longer needs people for deep learning, deep learning. We have completely eliminated that. We only have a small SOC team, five people, which is perfectly sufficient.
And all the data, the good thing about ORC4 is that when it is installed in a company, we don't get any data from the company because the mutation, from the mother, from the mother, only ever goes out. But we don't get any data from the customers. The attacks are of course reported to us, we have also documented this, but we don't have any deeper information, which is very important for large companies, that no information comes to us.
Furthermore, it is only data that goes from us to our program and no data that is actually stored back with us. We can also install the program on site on servers; we have nothing to do with it. It depends entirely on what the customer wants from us.
So, watched it? Listened to it? Good. I have a feeling we will be returning to this transcript for a long time, line by line, both for the quotes and for the fact-checking.