Generative AI: Embrace It, But Put Up Guardrails episode artwork

EPISODE · Sep 19, 2023

Generative AI: Embrace It, But Put Up Guardrails

from Info Risk Today Podcast · host InfoRiskToday.com

In this episode of CyberEd.io's podcast series, "Cybersecurity Insights," Daniel DeSantis, director of CISO Advisory at Cisco, and Pam Lindemoen, CISO adviser at Cisco, discuss how generative AI will change and elevate the role of the CISO as well as what the future holds for network security.

Episode metadata supplied by the publisher feed · Published Sep 19, 2023

Embed this episode

NOW PLAYING

Generative AI: Embrace It, But Put Up Guardrails

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast for the cybered.io learning community. Our goal is to bring cybersecurity practitioners the latest and most relevant education and training to upscale and dive deeper into topics that matter in today's modern cybersecurity world. Good day, everyone. This is Steve King.

I'm the managing director at cybered.io. And on today's podcast, I'm joined by Dan DeSantis and Pam Lindemann, who are part of the CISO advisory crew at Cisco. Dan is the director of the America's version, I believe, of that. And Pam works with Dan as a chief information security officer in that group.

And on today's podcast, we're going to discuss the impact on CISOs with the advent of generative AI and, you know, amazing market dominance since product GA was six months ago or something insane like that. There must be 100 million concurrent users. That may be an understatement. I don't know.

So welcome to both of you guys. And thanks for thanks for joining me today. It's our pleasure. Thanks for having us, Steve.

Sure. So talk to our audience about the difference between generative AI and discriminatory AI on the defensive side of cybersecurity. In other words, we see a lot of bad actors using generative AI in their attack vectors and we know that there's probably good use cases for generative AI on the defense side. But I haven't personally seen any in a production mode.

So maybe you guys could share your insights and view of that for us. Well, so, Steve, again, thanks for the team that we run here, the Cisco advisory team. We have the luxury of running all over the place and hosting wonderful dinners as a part of our Cisco Connections efforts with CISOs. And I have to say that the AI topic continues to be top of mind everywhere we go.

It's right up there with things like third-party risk, talent acquisition, liability, all that fun stuff. So I find it interesting. I mean, I think obviously the sea change that's happened has been the democratization of AI. And this is the point you're talking about with generative is now it's out there and it can be leveraged to expedite malfeasance.

And I think what we're going to see just on that front, at least the initial take on it is, this is from our Talos team, our intelligence team here at Cisco, is that we're going to see refinement of things like phishing attacks. We'll see that's an email that's crafted by the Nigerian prince or whoever he is, that's asking for money. It's probably not going to be broken English. It's probably going to be more tailored.

It will probably scrape from social media and other interesting tidbits and it will leverage the capabilities of the LLMs to make it a bit more targeted and honed, more believable, I'm sure. And so I think that's right out of the gate. One of the things that we're already seeing that. I would really divide this conversation into three core areas in terms of what we're talking to CISOs about.

The first is concerns around what I just described, that is threat actors leveraging AI to make more effective attacks and automate those attacks and perhaps an emerging class of hackers that didn't really have the coding chops to build a lot of the malware or command and control infrastructure, what have you. You know, sort of giving them confidence in a way that they didn't have confidence before because they didn't have the skill set that AI can replace, quite frankly. So I think there's that element of it. To be clear, and I think everybody that listens to this knows this.

AI has been used for a long time on both sides of the fence, right? So it's just, it's changed because of the democratization of it. The second bucket is, I think, the, or the second topic or area that we're talking about pertains to how it can be used for defense. And that really kind of divides into two areas.

One of which is, can AI help my SOC team or my threat Intel team be more effective at interpreting the massive data sets of telemetry that they're requiring from various sources? And I think the answer to that is an unequivocal yes. And I would say that that capability has been around for a bit. It's going to evolve quickly again in light of some of these new AI capabilities and some of the emerging companies that are leveraging it.

But I don't know that I'd go so far as, I heard one CISO say in a recent meeting that, you know, he believes that AI, generative AI is going to replace SOAR. I'm not sure I would go that far. But I think it is fair to say that AI is going to take up a more prominent role in security orchestration automation. And because we all know this, it's just, there's not enough talent and there's too much data.

The third and final area that I'll comment on and then I'll hand over to Pam is that the other sort of topic of conversation is, you know, putting guardrails around this, right? And it's how do I know that the LLMs aren't being misappropriated? Information isn't being injected into them. They aren't being manipulated.

How do I make sure that PII, ePHI, consumer data, intellectual property, isn't being put into the LLMs? So, you know, having that degree of control for CISOs and those who have to police that data, for lack of better terms, that's an area of concern, right? Because any of the technologies, and by the way, Cisco is investing in some of those with our VC arm to police that are still nascent. And there's some good companies out there in that space that are helping to put guardrails up around that, but it's still very early phase.

So those are the three big topics that we're hitting on. Pam, what are you seeing? Yeah, I would say my worries and like-minded CISOs, you know, typically agree. Generative AI is, you got to worry about deepfake.

So, you know, train people to understand what that means in your environment, even like the layman's in the world, like your family should have a safe word these days because deepfakes are going to get harder and harder to see through. Phishing and spam, that's another area. And then data manipulation under generative AI, thinking that synthetic data might be real data. And when that subtle change is not managed very well, like those guardrails aren't there, like you were talking about, Dan, I think we can get into some serious, serious issues in that space.

Other AI, I think, you know, we've been working towards, you know, what is that doing for us and to us long-term. When I think about AI, I think of it in the sense that we need diverse thought. We need guardrails and we need to go responsibly and thoughtfully in this space. And that's why I think Dan said it best.

The way Cisco approaches this is something that's near and dear to my heart. And they're cautiously moving towards, you know, what does that look like? Where do we put AI? Where are we using it?

Where are we leveraging it? We're making sure that we're thinking through that appropriately. Yeah, yeah, sure. And, you know what, you're absolutely right.

I mean, thoughtfulness and caution are called for. The only problem with that is that, well, you know, caution and thoughtfulness sometimes take a while to get to where you're going. In the meantime, these people are like blasting ahead, you know. I mean, I've never seen, personally, never seen an arc that is this, that has been this steep to get to, you know, whatever it is, a billion users, essentially overnight.

I mean, you know, it was only, I mean, if they released in November, no one knew about it until January. People were talking about it in March. All of a sudden, it's everywhere in April. You know, so it's only been really a handful of months before folks got there.

And I got the mitts on it, you know. So I. I think it's really important to call out that you've got to, you know, that's part of the whole third-party risk in my mind. Like, who do you do business with and making sure that they're, they have ethical AI practices and that they're trained to, to ensure that their products are being built with that in mind.

So it's something to really think through your portfolio, in my opinion. Indeed. And, you know, it's, that's one of the big downsides here, it seems to me. I mean, not only did we expanded the threat landscape by whatever it is, 10x, but we now have serious trust issues across the board.

I mean, who do you, how do you believe and who do you believe? You know, so it's a, it's a sticky problem, I would say. The, if you compare the upsides, well, to your point, if you compare the upsides of the opportunities to the downsides of the threats that are sort of released by generative AI, what's your take on it, on the net, you know, on the net outcome? I say, I'm practically scared.

And so I try not to freak myself out, but I can tell you, like, even with my family, I've created this concept of, you know, a safe word because it's just the reality we live in and you're not going to stop it. You've got to embrace it. And you've got to really build your teams around you that understand it. So that's, that's my take is it's scary, but it's, it's happening.

And so ignoring it and putting your head in the sand is not going to help you. So that, that characterization has been our sort of standard posture for several years now. But, and you're right. And I, I come at this, you know, shamefully responsible for the education program over here, but it seems to me that, you know, when I We need to have an open communication with our business units, with real world examples, case studies of incidents that have happened.

And I think we need to clearly outline the risk and the data privacy concerns around these decisions within your organizations. Like you just got to understand what that could mean. And then if you think about if you're coding, right, and your intellectual property is generating code and is there malware already present in it? Are you proliferating that and who is responsible there?

I mean, it just, there's just a conversation you can, like I said, you can go down a rabbit hole, but that's why you have to have a strong security organization to articulate the risk in the space. And I would say even privacy and ethical leadership in your organization to help you determine if you are going down the right path in terms of how you're approaching this and how your business is leveraging this type of technology. Yeah, you know, I mean, so there's a kind of in the vein of these questions, Steve, one of my favorite movies is Midnight Run and Charles Grodin, Robert De Niro. And Charles Grodin says to Robert De Niro, there's good and bad everywhere, don't you think?

And then De Niro looks at him and says, well, I'd say there's bad everywhere, but, you know, good I don't know about, right? So a bit more pessimistic. Having said that, to reference another movie, I just saw Oppenheimer. And while I'm not drawing a parallel between the atomic bomb and AI, I think there are some interesting actual and philosophical parallels.

And, you know, especially if you look at the father of the hydrogen bomb, Edward Teller, a lot of the research he did contributed towards, you know, building a nuclear reactor that could be used in medical research and helping patients. And so a lot of the fruits of the Manhattan Project actually ended up benefiting humankind. But a lot of what happened as a result of the Manhattan Project, which we haven't necessarily had the equivalent of that with AI was the advent of the Atomic Energy Commission, right? And, you know, having a regulatory environment around such a powerful capability that had the potential to, quite frankly, destroy the world.

And I'm not saying AI is going to do that, but what we do know, I think pretty solidly is that AI has the potential to disrupt things substantially and it's only going to grow. So, you know, I think it's, I think I agree with him. There's a, legal's got to be involved, regulation, you know, government's got to be involved. There's got to be regulation here.

There's got to be a very strong moral compass around this. And there's got to be this notion of due care that I learned many years ago when I got my CISSP. Due care takes on a whole new meaning now. It's not just due care of intellectual property and source code and other things.

It's due care of, you know, building these AI models that could potentially become self-aware, right? Indeed, yeah. And I think you nailed a huge part of the issue here. And of course, while we're being ethical and moral and struggling with all of that, I don't think the Chinese are really giving a hoot one way or the other here.

I think they're going to continue to do what they're going to do. And that's, of course, the bugaboo in this whole thing is that whatever legislation we end up passing is going to be ignored by, you know, the rest of the global leadership crew who are going to do whatever they want, you know. And we aren't, you know, we're not at cyber war with Brazil yet. We're at cyber war with the Russians and the North Koreans and, you know, China and Iran.

And those guys aren't too big on legislation. So. Yeah, I think any hackers, like that's the thing. They don't have to worry about patching and keeping a compliant environment.

They're focused on hacking for whatever reason, whether it's making money or espionage, whatever it is. We do. And that's a part of our role is to make sure that we're compliant. And this is no different.

We have to really address specific stakeholder needs and we have to, you know, we're in security. We have to explain the risk to our organizations and we have to be transparent with them. And we really should foster that open dialogue and maintain transparency throughout the whole process so that our businesses can run and adopt great technology, but with risk in mind. And what's that trade-off?

There are trade-offs, and it's our job to express those trade-offs when asked. And potentially there could be some grave trade-offs in this space. Oh, Pam, I think you just nailed it right on the head here. It's the real opportunity from my point of view is for the is for the CISO community or the senior practitioner professional, however you want to characterize that individual.

We can, this advent of GAI gives us a chance finally to go to address the C-suite and the board level and say, guys, you know, you need to. And due care is a big part of this huge part, Dan. It's a great point because, you know, we, you now have this responsibility. And so, you know, I think it's going to change the game and it's going to elevate the game.

And when I say game, I mean the business of being a CISO and being the person in the organization who's got the responsibility and accountability for what's about to go on here. So, you know, this is, so it's good in a way that it's such a significant game changer. It's not just another threat vector. It's not just, you know, you know, somebody figuring out how to crack the endpoint security puzzle, you know what I mean?

So, or break into a firewall or, you know, it's way beyond, way, way, way beyond that. And speaking of that, as long as we're looking at the more positive side, what, what is the one potential use case that each of you guys think will, will have the biggest impact on the labor markets? Because people are all worried like, oh my God, my job's going to go away. What's the one that you guys think about or that comes to mind for you?

You know, I'm not hearing, oh, my job's going to go away. I'm hearing, oh, wow, this could help us really on the detection side and speed up some of that work that's very difficult to manage with human resources. So, you know, I, I see it in a, in a different light, like how can we repurpose individuals that were, you know, leveraging process work? And if you think about it, like over time, technology has helped us with that, you know, and has helped us be better at our positions because of technology.

So I see it as, you know, really speed and evaluation of the, in the detection space. Yeah, I mean, I think the, it's interesting. I hosted dinner the other night in Boston and had a number of CISOs there, one of whom was in the federal government for many years. And he made a reference back to before we're processing, before computer technology, you know, there were lunch, there were a bunch of clerical people that, you know, would literally their whole responsibility, hundreds, hundreds, if not thousands of them were responsible for, you know, typing mundane.

It was mundane work around typing memos and other such things for, you know, various officials in the government. And many of them went away when computers and word processing came along and there were a lot of efficiencies gained there. But, you know, did they just go away? Did they disappear to the ether?

Did they take on other jobs? They moved into other domains. And I think that's always a question about any evolution of technology that, you know, we all fear is going to replace us humans. I think there are certain things like writing basic copy.

I mean, I think journalism and a lot of copywriting will evolve. And that doesn't mean humans are going to be removed from the equation. You know, for me, and I, you know, to echo Pam, what I'm hearing mostly in the security circles is that it's going to make our lives easier. I think it's like there's almost this welcome.

Oh, my gosh. I mean, I can't get talent fast enough. And I'm dealing with all this noise and I can't separate the signal. If AI can help me separate the signal more quickly, then that's huge.

Right. But I would be remiss if I didn't leave. I don't know where we're going from here, Steve, but I want to get this positive thought out there. If AI helps us cure cancer, if it helps medical researchers focus more of their time and energy on less mundane tasks and higher level thinking to help get us to something that's going to help humanity, then dear Lord, bring it on.

Right. Absolutely. And you're spot on. I agree.

It's I look at I'm kind of a glass half full guy anyway, so I always look at the upside and think this is fantastic for a whole bunch of great reasons. And now if we just have some strong leadership in various places, it would be even better. Talk to me a little bit about I don't want to leave the AI conversation entirely, but I'm also conscious of the time. But talk to me about the future of you guys are in the network security business, right?

So tell me about the future of network security, if you will, for a little bit. Okay, well, so we are. I mean, I think the network as we know it has evolved significantly and, you know, a lot of the, everyone's running around talking about the cloud and hybrid work. And so, you know, the network isn't what it used to be.

And I think Cisco has kept pace with that with a lot of our investment strategy. You know Advertising campaigns where you were very outcome-based. And the only mention of technology as you described the solution, whether it's getting clean water to the residents of Vietnam or some other contribution to the national security crisis, was the fact that you're called Cisco. Beyond that, there was no mention of product features, function, device numbers, any of that stuff.

And it was great advertising because it really set the tone, right? And it really said, hey, this is our why, not our what. And so I'm not sure why you went away from that, but I've used your advertising in the past as examples of the right way to communicate with your audience. Because that's actually all people care about.

They don't actually care how many corners you turn and how fast you turn. Let me say this, yeah, and whether people believe this is marketing or not, but our purpose is, and I've heard it said many times, and I see evidence of it, of how we do interact with the world. But it is to power an inclusive future for all. And that's based on the technology that we build or buy or invest in.

And, you know, I've been here two years and I've pressure-tested a lot of things, and there are some things we do better than others, right? But I'm really proud of what we do and how we act boldly and ethically build products and how we're looking for a sustainable future. I mean, that's what it's all about. And I believe we walk that walk.

I've seen it. So, you know, it may sound like a tagline. It's not. It's still our purpose.

I've been a Cisco customer for a lot of years, Pam, so I agree. That's my feeling about the company as well. Oh, that's good to hear. And I am conscious of time here, so one final question I have is, you know, you guys know I've been involved with a recent project.

In fact, I interviewed 16 CISOs in the last few weeks, and I think only one of them actually knew that Talos was a Cisco company. So it's kind of a two-part question. How do you best integrate that emerging threat intel with detection technology? And secondly, how do we get everybody to understand that you have this incredible threat intelligence capability?

So it is the best kept secret in the world. But it is the backbone of our products. So, and that to me is something that is incredibly important. So if you think about the signatures that we supply into our product line and, you know, it's just invaluable, right?

And it can be within seconds that they're implemented. But that to me says a lot. The reputation of Talos typically helps us in terms of that exchange and that thought leadership that we try to leverage from that group. But you're right, it feels like the best kept secret, but it certainly is an advantage for Cisco and our unique product line from that.

Absolutely. It truly must be. Dan, do you have closing thoughts? Yeah, I mean, I'll just, you know, it's, we run into a lot and you know, I think we'd be the first to say that, you know, we, we haven't spent the energy that we, we might need to on marketing that facet, that very important and large facet of our security portfolio, which of course is Talos.

You know, there's a lot of people that don't know that we've had boots on the ground in Ukraine well before the war. We were involved heavily with some of the initial research on things like NotPetya and Dark Energy. And, you know, we, we knew that, that Ukraine was being used as a test bed by nation state threat actors. And I think what's interesting to me is, and I, you know, I'd ask this question at Steve at dinner the other night with a bunch of CISOs.

And I said, how, how important is attribution to you? And because, you know, I used to work for a Cisco competitor and, you know, great company. And it, and that would be very clear with some great people. They're doing some very good works and good research, but we all know that they made their name on, you know, attribution, right?

They, they, and now several others have kind of piled on with, you know, calling out names in some, in some instances, funny names for the threat actors. When I, when I pulled the CISOs in the room, I said, hey, how many, how many of you really care about attribution? They're like, I don't care. It doesn't matter to me whether it's China, Russia, North Korea, Syria, or Iran, or whomever that's doing this.

It's being done. I have to, I'm really more concerned about business disruption. And, and, you know, depending on the industry, I mean, maybe patient safety and that sort of stuff. So, you know, that these are, there are others that are not necessarily security decision makers that might find that interesting, you know, well, China tried to get in.

But I have to say that a lot of, I think intelligence providers have made a name for themselves because they're very good at calling out the enemy. I just don't know how much value that has. So we've invested a lot of our time and energy on understanding the enemy, understanding the tactics, techniques, and procedures of the enemy, and taking that telemetry and feeding it into our products so that the customers that buy our stuff will benefit from those capabilities, if that makes sense. Yeah, sure.

Now that's, that's exactly right on. So you guys have been great today. Thank you. Thanks for taking the time out.

I know you've got a crazy schedule, both of you. And, but I do, I do appreciate it. I'm sure our audience appreciated it as well. We learned, I think, some, some informative stuff here today.

And, and I'd love to have you guys back on maybe four or five, six months from now and kind of see where the world's gone since, since today. And, but, you know, as you point out, Pam, it'll be an interesting ride one way or the other, right? That's right. All right.

So once again, thank you, Dan DeSantis and Pam Lindenbaum. And thank you to our audience for spending, whatever it's been, 38, 40 minutes with us today. And I hope you enjoyed it as much as I did. Until next time, I'm Steve King, your host, signing off.

Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook, or send us an email at social at cybered.io. For more information about the podcast, visit cybered.io forward slash podcast. Until next week, stay safe and secure.

And we'll see you on the next episode of Cybersecurity Insights.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on September 19, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!