The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Cyber Compliance & Beyond
Cyber Compliance & Beyond artwork

32 - When AI Attacks - Part 2

Cyber Compliance & Beyond · 2026-07-22 · 30 min

0:00--:--

Key moments - from our scoring

Substance score

58 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality11 / 20
Guest Caliber14 / 20
Specificity & Evidence10 / 20
Conversational Craft11 / 20

This episode shifts from threat understanding to actionable leadership strategy in an AI-driven security landscape. Speaker C, a national security attorney advising multinationals on AI governance and export controls, explains why regulatory risk begins with policy ideas - citing his work on the Uyghur Forced Labor Prevention Act and FCPA as examples where policy discussion preceded legislation by years. He advises leaders to monitor congressional hearings, agency speeches, draft legislation, and national security reviews rather than waiting for published rules. The conversation introduces a framework for distinguishing signal from noise: bipartisan support, alignment with long-term national strategy (not single-administration priorities), and multiple institutions moving simultaneously in the same direction. For the defense industrial base specifically, Speaker C highlights AI supply chain risk as a new compliance exposure, warns that "shadow AI" represents unmapped insider threats, and emphasizes that organizations currently have a temporary defensive advantage to reduce technical debt and find vulnerabilities faster than adversaries. He stresses responsible leadership requires sound judgment over expertise, educating executives who still view China through an outdated manufacturing lens, and building resilience as organizational discipline rather than compliance checkboxes.

Key takeaways

  • →Regulatory risk emerges from policy signals - congressional hearings, agency speeches, and draft legislation - months or years before rules are published, so organizations should follow threat trends rather than waiting for formal regulations.
  • →Distinguish signal from noise by assessing bipartisan support, alignment with long-term strategic interest across administrations, and simultaneous movement by multiple institutions like Congress, agencies, investors, and industry leaders.
  • →AI supply chain risk is now a compliance issue: if you deploy an AI system without understanding training data sources and model capabilities, you face regulatory exposure and counterintelligence risk.
  • →Shadow AI - employees using AI tools without governance awareness - constitutes an insider threat and represents unmapped data flow risk that must be addressed by CMMC 2.0 (through 2026).
  • →Organizations should aggressively reduce technical debt and use AI for vulnerability discovery now, while they have a temporary defensive advantage before adversaries gain access to the same capabilities.

Topics in this episode

shadow AIAnthropicCMMC 2.0Export controlsAI supply chain riskUyghur Forced Labor Prevention ActGTG1002 (Anthropic model)Insider threatUS-China strategic competitionFCPA

Questions this episode answers

Why should companies pay attention to policy ideas before regulations are published?

Regulatory signals typically appear months or even years before they become law, so organizations that track congressional hearings, agency speeches, draft legislation, and national security reviews consistently outperform competitors waiting for regulations to drop.

How can leaders distinguish real policy trends from noise in today's geopolitical and AI environment?

Apply three tests: Does it have bipartisan support? Does it align with long-term strategic interest (not a single administration's priorities)? Are multiple institutions - Congress, agencies, investors, and industry - moving in the same direction simultaneously?

What is shadow AI and why is it a compliance risk in the defense industrial base?

Shadow AI is unmapped use of AI tools by employees without governance oversight, which constitutes an insider threat and uncontrolled data flow risk; it must be addressed under CMMC 2.0 requirements through 2026.

Why should organizations follow threat intelligence rather than compliance regulations?

Many current regulations codify yesterday's problems and lag behind actual threats; threat intelligence provides regulatory foresight, as demonstrated by companies responding to Anthropic's GTG1002 research before government advisories exist.

What is the current defensive advantage in AI security for the defense industrial base?

AI can help defenders find vulnerabilities and reduce technical debt faster than adversaries can exploit them, but this advantage will not last indefinitely as advanced capabilities eventually diffuse.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains several substantive policy frameworks (signal vs. noise framework, policy-before-regulation model, AI supply chain risk framing) that would be novel to many B2B operators, but the delivery is often repetitive and padded with throat-clearing. The guest restates points multiple times (e.g., 'follow threat not regulation' appears several times), and there is considerable abstract discussion without concrete depth. For a cybersecurity compliance audience, the ideas are moderately useful but not densely packed.

most regulations don't emerge suddenly as I often tell them. The signals usually mere month or even years in advance
follow the threat, not the regulation. Uh because um, not only we don't have a regulation but some of the regulations today are outdated

Originality

11 / 20

The core insights - that policy precedes regulation, that organizations should monitor signals early, and that AI poses supply chain risks - are increasingly common in compliance and national security circles. The framework for distinguishing signal from noise (bipartisan support, strategic alignment, institutional convergence) is sensible but not novel. The Uyghur Forced Labor Prevention Act and FCPA references are illustrative but well-worn examples. The AI supply chain risk framing is somewhat fresher but still emerging consensus rather than contrarian thinking.

Regulatory risk starts with policy ideas, not published rules
does it have bipartisan support? Does it align with a long term strategic interest?

Guest Caliber

14 / 20

The guest (identified as Nuri) has genuine credibility: he is a national security attorney with active security clearance, worked on the Uyghur Forced Labor Prevention Act with Senator Rubio's team, has run a federal agency, and is cited in WSJ and Foreign Affairs. However, he is primarily a policy/legal advisor rather than an operating founder or practitioner who has built and scaled AI systems or cyber defense operations. His insights come from vantage of counsel and policy circles, not from direct operational experience managing AI in production environments or defense contractors.

He holds an active US Government security clearance, is a lifetime member of the Council on Foreign Relations, and is recognized by Time and Fortune as one of the world's most influential leaders
I've been in the government, I've been in a private, uh, law firms and I've been in a policy circle

Specificity & Evidence

10 / 20

The episode lacks concrete numbers, named companies (beyond Anthropic, OpenAI, and academic research papers), specific metrics, or timelines with detail. The Uyghur Forced Labor Prevention Act is named but not deeply analyzed with numbers. Statements like 'signals usually mere month or even years in advance' are vague. CMMC is mentioned but only in passing. The threat landscape is discussed in abstract terms rather than with specific attack vectors, breach sizes, or dollar impacts that would ground the advice operationally.

if you have an AI system in your stack and you don't know where the training data come from, what the model can be prompted to do, you have a compliance exposure
Anthropic project putting their most capable model in the defender's hand

Conversational Craft

11 / 20

Host Cole French asks solid opening questions and attempts to bridge abstract policy to practical business operations (e.g., 'how do we distinguish signal from noise'). However, he rarely pushes back or probe deeper when the guest makes sweeping claims. For example, when the guest says 'the question is whether they can compete responsibly,' there is no follow-up asking what responsible competition looks like. The guest's rambling responses (e.g., the lengthy answer on responsible leadership) are not interrupted for clarity or compression. The conversation feels more like a platform for the guest's prepared talking points than a genuinely exploratory dialogue.

how do you counsel organizations on identifying strategic risks before they become compliance obligations?
So how should they be thinking about AI systems that increasingly have access to sensitive information and critical workflows?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C56%
  • Speaker B30%
  • Speaker A14%

Most-used words

policy29compliance27regulatory21threat20today17leadership16risk16china14leaders13regulations13security13insider12organizations12national12world12attention11

Episode notes

Following Part 1's deep dive into GTG-1002 and the rise of autonomous cyber operations, Part 2 shifts toward what leaders must do to get ahead of next-generation AI-enabled threats. Guest Nury Turkel explains how regulatory risk forms long before official rulemaking, often emerging first through congressional hearings, agency speeches, draft legislation, and national-security analyses. Nury argues that organizations gain an advantage by tracking long-term trendlines - such as bipartisan momentum and multi-agency action - rather than reacting to headlines, and by cultivating geopolitical literacy and responsible leadership. The conversation concludes with emerging AI-related risks to the defense industrial base and practical steps leaders can take to reduce technical debt, strengthen resilience, and stay ahead of next-generation threats. References: Wall Street Journal: China Tells Its AI Leaders to Avoid U.S. Travel Over Security Concerns (paywall) Bloomberg: China Expands Travel Curbs to Top AI Talent at Private Firms (paywall) Reuters: China Restricts Overseas Travel for Top AI Talent at Alibaba, DeepSeek

Full transcript

30 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: After setting the stage by showing how AI is reshaping cyber operations and global competition in Part one, today in Part two, we shift from understanding the threat to understanding what leaders must do about it. Today's conversation dives into the policy signals that quietly shape future regulations, the difference between noise and meaningful trend lines, and the leadership mindset required when technology is evolving faster than governance Frameworks from regulatory foresight to AI driven insider threatened defense industrial based risk focus on the practical steps organizations need to take to stay ahead. Welcome to the Cyber Compliance and Beyond podcast, a Kratos podcast that brings clarity to compliance, helping you leverage compliance as a tool to drive your business's ability

Speaker B: to compete in any market.

Speaker A: I'm your host Cole French. Kratos is a leading cybersecurity compliance advisory and assessment organization providing services to both government and commercial clients across varying sectors including defense, space, satellite services and healthcare. Now let's get to today's episode and help you move cybersecurity forward. In Part one, we explored how AI is transforming the threat landscape from GTG1002's autonomous operations to the emerging US China technology power struggle. Today in part two, we shift into the operational and compliance realities leaders now face. Nury explains why regulatory risk starts with policy ideas, not published rules, and why organizations that track congressional hearings, agency speeches, draft legislation and national security reviews consistently out outperform those waiting for regulations to drop. Policy signals appear months or even years before they become law, and companies that study trend lines, not headlines, get ahead. Nuri also offers a framework for distinguishing signal from noise, including bipartisan momentum, alignment with long term national strategy and whether multiple institutions are moving in the same direction, a critical skill in an era of rapid AI announcements, shifting export controls and geopolitical surprises. He emphasizes that strategic risk must be identified before it becomes a compliance obligation, urging leaders to follow threat intelligence rather than wait for outdated regulations to catch up. From there, the conversation turns to responsible leadership, making sound judgment the foundation of influence, recognizing China's evolving role as a strategic competitor and educating executives who still view China through an outdated manufacturing only lens. As the defense industrial base adopts more AI driven workflows, Nury highlights the rise of AI supply chain risk. Shadow AI is an insider threat and the need for organizations to use their temporary defensive advantage to reduce technical debt, leverage AI for vulnerability discovery and build resilience into daily practice, not just as a compliance checkbox. This episode brings our series full circle. Leaders must prepare for next generation AI enabled threats by becoming AI literate, staying level headed amid political noise, balancing national security with innovation and guiding their organizations with judgment, not fear. It's a clear roadmap for navigating a rapidly shifting future. And a powerful close to our two part conversation with Nuri, who is a national security attorney and strategic advisor who helps multinational companies navigate AI governance, export controls, sanctions, supply chain risk and US China strategic competition. He holds an active US Government security clearance, is a lifetime member of the Council on Foreign Relations, and is recognized by Time and Fortune as one of the world's most influential leaders. His analysis appears in the Wall Street Journal, Foreign Affair and the New York Times. We hope you enjoy this episode.

Speaker B: I thought something you said was uh, really interesting to me, which is that regulatory risk, which is something companies look a lot at and are really trying to keep their finger on the pulse of, you know, where are things going from a regulatory perspective because regulations ultimately end up being a business cost. Right? That is something that costs me money as a business owner is whatever the regulatory landscape is and how that applies to me. But regulatory risk starts with policy ideas. So kind of getting practical here on what we've been talking about. What are some policy signals that you're seeing out there that you think business leaders should be paying attention to as it relates to, you know, AI and, and kind of what we're talking about here today.

Speaker C: Thank you for that question. I've been um, an unconventional lawyer. I've been in the government, I've been in a private, uh, law firms and I've been in a policy circle. Oftentimes when I talk about these things, I focus more on the policy, uh, trend line than the legal uh, requirements because everybody can look up uh, the regs in the book and go one way the other. But as you perfectly pointed out, um, the regulatory risk, uh, rarely begin with the regulation. I witnessed, um, during the time that Senator Rubio, uh, was leading much of the China legislative initiatives, I worked with his team and helped to put in place something very important called Uyghur Forced Labor Prevention act, uh, which puts 80 more than 80 global brands on notice about the products they're importing to the country. Uh, um, presumably, uh, everything coming here is negative unless proven with the documentation that they are not made with slave, ah, labor or forced labor. So that policy idea, the policy idea we shared at the time with Senator Rubio and his team is that this is one of the best ways, this is the most effective ways. Just telling companies everything you bring is negative. Uh, rebuttable presumption is the term until you prove that you're not using modern day slavery to uh, pollute global supply chain. And that policy idea become a law and now that companies uh importing, you know today like uh 301 investigation on forced labor has some connection to it. So that piece of legislation was based on the Tariff act and old law but within modern uh the issues to the modern concerns which is the modern day slavery. So that brilliant um idea uh of policy discussion uh created a law, uh, I've done a lot of FCPA uh work uh that's also very similar, has uh a similar background which is uh, should we allow American companies to bribe foreign officials because the local culture, local uh business environment uh requires so. And the answer is no, uh we should export best practices, ethical business practices uh to other countries not to adopt the local culture, uh business culture or corrupt culture. So all of the uh regulatory risk begin with a regulation and it's almost begin with the policy idea. So um, and companies need to pay attention as I always tell them, um, uh, watch what policy, uh before they watch the regulation I ask them to pay attention to congressional hearings, pay attention to speeches by senior officials, pay attention to think uh tank reports. I've done a few of them myself. Uh, pay attention to draft legislation, pay attention to national security review. Most regulations don't emerge suddenly as I often tell them. The signals usually mere month or even years in advance. And the organizations that consistently outperform their peers are the often ones that recognize policy trends before they become a legal requirement. So it is very important. Uh, you know I live and work in Washington. Um, I pay attention to those things so that I can give a sound advice to my clients so they can be ready, uh, they can be quickly adjusted. This is particularly important today where there are a lot of uncertainties in the issues that we deal with in the um uh policy initiatives coming out of the exact branch. And once it is out it takes time for it to be validated or overruled as we have seen a number of things including the tariff. But at the same time we need to be able to help the businesses uh to adjust quickly and be ready to the regulatory uh risk uh that are being formulated. Ah, just like the way that the Congress tried to address this um, advanced uh chip export. There are a number of bills being introduced. It's not going anywhere right now because the political uh inbox the current political environment. But in the end these policy discussions um, I believe uh as I have seen and participated and contributed will become something um a uh legislative mandate. So it's important to pay Attention to policy discussions or policy statements.

Speaker B: And I would say cmmc, which I mentioned earlier, you know, our uh, work in the compliance, cybersecurity compliance space. CMMC really is a great example of exactly what you're talking about. It's a policy that came into play many, many years ago and the regulation has followed behind it. Our regulations have followed behind it. So exactly to your point, the policy was there. Most people, or I don't know if I want to say most, but a

Speaker A: sizable number of people, enough people or

Speaker B: enough organizations, decided that the policy was essentially optional or really the regulation, the initial set of regulations were optional or there really wasn't teeth to enforce that. So over time, as you said, to add to what you're saying, really a policy idea becomes regulatory and it can become regulatory in many different forms. The policy, the initial policy itself is one thing, but over time the regulations evolve to fit sort of that initial policy objective. So if we start with a policy and then we implement regulations, but we find out, uh, oh, those regulations don't work quite right, then there's a rulemaking process to enact additional regulations on top of that. So it kind of becomes this thing that grows over time. So following those policy ideas, paying attention to those signals is important. And to that end I would say beyond that, you know, what do you, how do you advise folks when it comes to distinguishing, you know, what's real and what's noise? When we hear AI announcements, you know, export control measures, cyber incidents, geopolitical surprises, all those kind of things, how do we distinguish that this thing is going to go somewhere from a policy standpoint based on different things we hear in the news? And this thing is maybe not going to go somewhere. This is just kind of noise in the background. Like how do you, how do you help folks determine what to listen to and kind of what to put to the side?

Speaker C: Isn't it important to pay uh, attention to the uh, difference between signal, uh, and noise? And especially today, in today's political environment, uh, geopolitical surprises. If I could, um, so I would ask three questions. Uh, for example, um, does it have bipartisan support? Does it align with a long term strategic interest? Not a single administration's priorities. When you look at uh, the AI related, uh, technology related policies, uh, coming out of White House sometime, uh, some companies are making this mistake because of their relationship with uh, senior officials in administration that are listening more to them. They think this is just one single administrator. Administration priorities. That's a mistake. You need to look beyond, um, one administration that Is really important signal. Ah, multiple institutions move in the same direction simultaneously. This is also an important signal. And also the last one I would say, uh, when Congress, national, uh, security officials, uh, regulatory agencies, uh, investors, industry leaders all converge on the same issue and this is definitely signal. So the headlines create noise, uh, in today's society people read the headline, um, that is based on the noise and trend lines create strategy. Um, so headlines create noise, uh trend lines create strategy. Um and those are the things that I would watch out when I'm distinguishing uh, signal from noise.

Speaker B: I think those are three really good lenses through which to view what we see in the headlines on a, on a really, on a daily basis. So if I'm a leader uh, of an organization and I want to say hey, like I want to make sure I get ahead of my compliance obligations, this is something we navigate or help customers navigate all the time is you know, how can I stay ahead of what the compliance obligations will be? How can I make sure that I'm operating in a way today that when the compliance obligations change in 18 months I don't have to go re engineer my whole organization, my it, all of that kind of stuff. So how do you counsel organizations on identifying strategic risks before they become compliance obligations?

Speaker C: Uh, it's a great question. Um, we talked about uh a lack of um the regulatory requirements or governance um on AI um safety. So I would do this, I would follow the threat, not the regulation. Uh because um, not only we don't have a regulation but some of the regulations today are outdated. Um so regular regulations codify yesterday's problem. Um, organization that read anthropic GT GTG1002 for example or method disclosure and immediately ask um could this happen to us Are ahead of organizations waiting for uh cybersecurity, uh uh the CISA advisory, uh that organization is in a major leadership shift. But uh, we should not wait for a uh government advisory. Threat intelligence is a form of regulatory foresight. So following the threat, not uh, the regulatory or government advisory is something that ah, companies should do um, uh, in the cybersecurity uh areas in a broader global regulatory compliance. From my past experience um dealing with multinationals, uh, uh, European, uh, uh and Asian companies, oftentimes the leadership uh C suite folks think that the uh, regulatory enforcement trends, for example in the case of um, the entity listing by BIS during the Biden administration and previous administrations, the FCPA antitrust um uh enforcement actions, they think that they believe that it's not coming to them. Uh, it's a hyped up situation in Washington, not really appreciating uh the seriousness of the uh, uh trend line in Washington and thinking that it will not happen to them uh and or thinking that the company is too big for the United States regular um regulatory agencies to go after is a mistake. So um, and then the third thing is that um, the companies should look at the policies and procedures already in place and proactively uh, updating them and using those updated PMPs to raise awareness within the company. At the end of the day the companies will not be able to comply with US or European uh regulatory requirements uh in the technology space and in the national security space and AI sector uh uh, without adequately um, uh equipping the company employees with the knowledge. The AI tools should not be used for uh grammar checking, quick research. It should be used for efficiency. It should be used for creation of a better uh more advanced product that today the AI is uh, in a very preliminary uh, uh primitive used by majority uh public. It should not be only used for finding out if AI is good or not but AI should be used for raising uh awareness within the company, the training and it essentially just making everybody ahead of the game or be prepared uh with a sudden quick policy uh regulatory changes.

Speaker B: Yeah, it does take, it does take a gifted leader, a gifted set of folks to really kind of be able to envision what the future looks like both from a compliance landscape but also the threat landscape and what actually is out in the world and kind of where things are going, where things are heading. You do need both of them I think sometimes you know there's this weird sort of relationship with compliance in the operations world where there's a tension point and there's some bitterness, resentment, things like that for against compliance frameworks and governance frameworks and things like that. But at the same time they're sitting back and waiting for these compliance frameworks to essentially in a way dictate what's required. And then there's uh, weeping and gnashing of teeth about oh we have to do this, we have to do that. But the reality is that in many instances like you just said, the compliance frameworks are behind what's actually out there in the real world. So we should be looking at and operating from what's in the real world, what's actually out there. And we use the compliance frameworks as guidelines and as sort of anchors to base what we're doing on. But if that's what we're waiting for then yeah as organizations we're going to be behind so you know, if you want to speak on or add to that from a responsible leadership perspective, like, what do you think responsible leadership looks like when the world in which we live advances so much faster than governance frameworks?

Speaker C: The responsible leadership, um, I think the leadership, um, I've been in a leadership role. I ran a federal, uh, government agency. Um, the things that I've learned over the years is that uh, the influence, uh, comes from judgment more than expertise. Uh, when a leadership being chosen or appointed, they often look at the uh, expertise more than that person's ability to make a sound judgment. Uh, the people's advice, um, uh, especially in the trusted advisors, uh, comes from consistent, uh, thoughtful, credible, reliable ability to make a sound judgment. And you know, the one other thing that I've observed in my interactions with the senior leadership, uh, is that not appreciating that every issue deserves the same level of urgency. You know, you only get eight hours a day, uh, and so much you can be able to accomplish. So, um, the sound judgment, uh, to be able to make a sound judgment and influence others are some of the key uh, aspects of leadership. The influences accumulated slowly and spent carefully. And also going back to the uh, China concern, most of the corporate leadership today treats what our number one adverse adversary, uh, or competitor, um, in diplomatic uh, sense is up against or up, up for. This is something that requires a lot of education. So in other words, uh, there's a generation of executives who came up with, came up with when the China was primarily manufacturing story. The idea that the China is a strategic competitor in AI and cyber and technology standard, that is still counterintuitive to some of those people. You know, when you look watching CNBC or the interviews that they give, um, this is what demonstrate they think of what we're dealing with. China is a kind of a manufacturing hub that has gone. That's not the case anymore. So my job, uh, interacting with senior leadership is to help them to bridge that gap. Um, I don't see it as a remedial. I see it as a meeting people where they are. So, um, this is the same message. Um, the geopolitical risk is no longer background issue. China is not the same China that you know, uh, these are the things need a, ah, thoughtful, careful, self, uh, training, self education, uh, so that you can make a sound, uh, judgment and influence uh, your workforce to follow through your leadership.

Speaker B: So we kind of started our conversation talking about AI as a weapon of cyber espionage and things like that. And we've kind of zoomed out and talked about, you know, Geopolitical forces, the bigger picture, all that kind of stuff. So as we wrap this up, kind of bring it back to, you know, the defense industrial base, if you will. We've talked about cmmc, which CMMC is really, you uh, know, a compliance framework that is aimed at and targeted at the defense industrial base. So to kind of close this out. So organizations thinking about AI systems in the defense industrial base, so how should they be thinking about AI systems that increasingly have access to sensitive information and critical workflows?

Speaker C: So let me start this by pointing out um, a few lessons, uh, that the defense contractors and compliance leaders should take. One, uh, AI supply chain risk is now a compliance issue. Uh, if you have an AI system in your stack and you don't know where the training data come from, what the model can be prompted to do, you have a compliance exposure and then 2 shadow of AI is unmapped Insider threat. That is something need to be recognized, uh, on the CMMC, uh, live now level to wave, uh, 11-10-2026. That is unstoppable data flaw with false uh, claims at risk on the named executive. That's also something that need uh, to be um, mindful uh, and leaders uh, should take into consideration. There is also a China counterintelligence story. A model that an uh, adversary is actively probing, uh, in a counterintelligence concern. Not just the data lost. Vendor, um, risk, software risk, national uh, security risk are increasingly the same conversation. So organizations currently have a temporary defensive window. Right now AI can help defensive industry, uh defenders industry vulnerability and reduce technical debt faster than adversaries can exploit them. That advantage will not last forever. The Anthropic project putting their most capable model in the defender's hand. First is a recognition of exactly this. Um, that is remarkable. Without any regulatory compliance requirements in the books. Anthropic was doing that, uh, um, uh, the OpenAI's similar uh action need to be recognized. So the history suggests advanced capabilities eventually diffuse the three priorities, um, reduce technical debt aggressively. Now use AI to find new vulnerability before your adversaries does and build resilience as an organizational discipline rather than a checkbox. That is a common thing in the compliance world, that people do things for the sake of checking the box. That is not the right approach. So the best time to fix a vulnerability is before your adversary can find it in a second. This is particularly important in a defense industry.

Speaker B: Just to pull the thread real quick, the insider threat thing you mentioned is something I have not even thought of and we work a lot with organizations on insider Threat and helping to interpret what is an insider threat. And some conversations I've had recently have illuminated that. I think there is. I don't know if lack of understanding is the right term, but that's what's coming to my mind around insider threat. And what exactly is an insider threat? I think historically people have thought insider threat is, you know, somebody who has a malicious intent inside my organization to do harm to my organization. But the reality is an insider threat can be a standard user who makes a mistake. And I think AI fits right in with that. Right. Like you can use AI in what you think is the proper form and inadvertently potentially cause harm to your organization. And that is an insider threat that constitutes an insider threat. So we do need to think of it that way. I think that's a particular interesting and relevant thing as we're talking about, you know, how do leaders think about some of these things? I think it does require us taking kind of what our preconceived notions are of different things within cybersecurity and expanding those and rethinking them for some of these new things like AI and uh.

Speaker A: So just to close this out, one

Speaker B: final question here Nuri. And again I really appreciate you coming on today and sharing your perspective on AI and really so much more than that, the geopolitical implications and all of that. This has been a really rich conversation but just want to close this out and we've kind of talked about this but I think it's important and I think uh, you know, I'd like for you to just distill it for us as a way of closing out this conversation. So what do you think leaders should be doing to prepare for the next generation of AI enabled threats?

Speaker C: Um, we need to um, uh, you know, in a corporate um, and the uh, and uh, the government, um, uh, I made a five different recommendations in the AI powered, uh, cybersecurity threat. I'm a big believer of recognizing the issue. Uh, you know I think that the, we have diagnosis on the problems that we're facing or uh, problems that we're having. So I think the, the on the governmental level we need to laser focus on the prescription. Um, I think the United States, um, as far as the government, business, uh, community, tech, uh, community and the society as a whole are equipped to come up with a solution uh, to uh, the problems we've been discussing in the context of a uh, US China competition. I think the real question is whether the United States and China will compete. But the question is whether they can compete responsibly so the hyperbolic statements in some instance emotional statement when it comes to national security concerns on chip sales issues are not really uh helping to resolve this unprecedented challenges that we're facing on the uh tech world. What I think that the leadership should do consider uh doing is continue to be transparent, um, continue to share best practices, continue to be honest with the people, public. Uh, you mentioned something that inside threat. I look at people, how they use AI and oftentimes they just rely on what AI generated information as if that are reliable. Going back to uh the article that you mentioned uh at the outset of our conversation. That's the way the relying on the AI, uh, the hallucination, uh and AI platform, uh, the Chinese find vulnerability. So the fluency in the AI field is something fluency uh, of AI learning how to use it effectively, uh, with a mindset that the information that they're getting uh, may not be accurate. The human fact checking should be still the norm. This is for the users. So in summary I encourage people to uh, in generally speaking, um, AI literate and the government, um, policymakers, decision makers to be level headed, to be objective, uh, while recognizing the potential challenges to come up with something that is workable, that is enforceable, that can be implemented to uh, safeguard AI safety for the corporate world. Um, they need to find a balancing act between uh, complying with the national security concerns and laws and also um making money. Uh the corporate CEOs have a responsibility to the shareholders, uh shareholders, uh main focus is return of investment. The corporate world, um, uh technology world, uh, that is capable of inventing uh some of the most sophisticated technology and tools should be able to come up with the ways to uh, strike uh the right balance between maintaining national security, um, protecting us uh national security in particular uh civil liberties, privacy and uh, getting them a return, uh return of investment, uh, or maintaining economic competitiveness in today's complicated geopolitical world.

Speaker B: Thank you for sharing those Nuri. I think those are all great things that leaders can be doing. And not just leaders but all of us really and more broadly. I really appreciate you coming on today and sharing your perspective across this very wide ranging and broad topic. Uh, and I know our listeners will really enjoy listening to this episode. I learned a lot from it. So I really appreciate you, you taking the time.

Speaker C: Thank you very much Cole. I really appreciate our conversation.

Speaker A: Thank you for joining us on the Cyber Compliance and Beyond podcast. We want to hear from you. What unanswered questions would you like us to tackle? Is there a topic you'd like us

Speaker B: to discuss or you just have some

Speaker A: feedback for us, Let us know on LinkedIn and Twitter Kratos Defense or by email@ccbeyondratosdefense. Uh.com we hope you'll join us again for our next episode, and until then, keep building security into the fabric of what you do.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Eric Ries on Why Good Companies Go BadPodcast Archives · on Anthropic92 / 100
  • The 18x Midas Lister Betting $3B on AI (and calling most of it fake) | Navin Chaddha, MayfieldThe Peel with Turner Novak · on Anthropic91 / 100
  • 183: Why Trusted Data is the New AI Moat (w/ Rick Kranz @ AI Marketing Automation Lab)Move The Needle · on Anthropic91 / 100
  • Fighting Fire with Fire: How CyberProof Is Automating Cyber Defense with Edy AlmerCyber Sentries: AI Insight to Cloud Security · on Anthropic80 / 100
  • Iran Hacks the US Water Supply - The 443 Podcast - Episode 382The 443 · on Anthropic77 / 100
  • SailPoint presents: How healthcare can secure AI tools and non-human identitiesHIMSSCast · on shadow AI77 / 100

More from Cyber Compliance & Beyond

All episodes →
  • 30 - Teaching AI to Protect CUI58 / 100
  • 31 - When AI Attacks - Part 1
  • 29 - Modernizing the Shop Floor: Security, Efficiency and Survival
  • 28 - Keeping OT Safe, Secure and Online
  • 27 - CUI Discovery for CMMC Compliance
Explore the best B2B Ops podcasts →
All Cyber Compliance & Beyond episodes →