
Cyber Leaders · 2026-06-12 · 30 min
Key moments - from our scoring
Substance score
60 / 100
Five dimensions, 20 points each
Chris Cochran, Field CISO at SANS and author of the Scotty Threat Hunter graphic novel, explores the dual nature of AI in cybersecurity - both as an existential threat and a necessary defensive tool. He argues that while models like Mytheos show promise for vulnerability detection and static analysis, the real danger lies in the inevitable proliferation of autonomous agents for attacks within months to years. Rather than debating AI's risks, Cochran advocates that defenders must "fight fire with fire" by leveraging AI themselves. His framework centers on three priorities: first, closing foundational gaps (workforce identity, non-human identity, agentic identity, and incident response programs that most organizations have deferred); second, adopting AI for defense rather than remaining skeptical; and third, building resilience through community and storytelling. He addresses the crushing workload facing CISOs caught between board pressure, team resistance, and competing priorities, recommending peer communities like Security Tinkerers and structured communication strategies as burnout mitigation. For security leaders, the message is clear: preparedness requires both technical hardening and psychological sustainability through collective action.
Leaders should focus on closing foundational security gaps in workforce identity, non-human identity, and agentic identity management, and ensure robust incident response programs are in place before autonomous attacks scale.
AI is both - it enables faster vulnerability discovery and threat detection, but also powers autonomous attacks; defenders must use AI defensively rather than reject it, or they cannot keep pace with adversaries.
Join peer communities like Security Tinkerers, communicate through storytelling to boards and teams to convey both risk and solutions, and use frequent structured dialogue with peers to break out of isolation and mental echo chambers.
Cochran estimates tens of thousands to hundreds of thousands of autonomous agents targeting vulnerabilities could emerge within three months to two years, not a distant future scenario.
Mytheos is a controlled-release AI model focused on finding vulnerabilities through static code analysis quickly, but its broader implication is that public AI models will eventually match these capabilities, raising questions about how to control access to powerful models long-term.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers meaningful territory on AI-augmented cyber threats and defensive strategies, with Chris offering practical frameworks (three buckets of AI use, intentionality in implementation, AI governance councils). However, significant portions are devoted to Chris's background, community-building philosophy, and personal anecdotes (graphic novel, standup comedy, podcast origin story) that, while humanizing, consume airtime without advancing technical or strategic insight. The core AI/defense discussion lands solidly but is diluted by filler.
The stuff that Anthropic talked about at the end of last year with the autonomous attacks... I saw the tip of the iceberg. I feel like it is not a stretch of the imagination that within three months, six months, nine months, a year, maybe two years, we're gonna have tens of thousands, if not hundreds of thousands, of autonomous agents looking for targets of opportunity for the adversary.
At SAMS, we kind of look at AI in three different buckets. One bucket we think about how do we utilize AI... the other is protect position for artificial intelligence. What are some of the failure modes in which you need to understand... And then ultimately, I think the most important aspect of it is like governance.
Chris articulates the tension between open AI development and national security credibly (the Mythos paradox), and the three-bucket framework for AI governance is sensible. However, the core prescriptions - "get your house in order," identity management, incident response maturity, storytelling for buy-in - are well-worn in CISO circles. The autonomous agent threat timeline is speculative rather than data-grounded, and the community/burnout discussion, while sincere, repeats familiar themes without novel framings.
So, what is to say that a year from now, the regular models that everyone has access to today turn into exactly what we're afraid mythos can do in the hands of an adversary?
The more we can band together as leaders and work with each other, that'll help prevent burnout. That's step one. Step two is really get good at communication.
Chris Cochran's resume is genuinely strong - USMC intelligence, NSA, Cyber Command, Netflix, SANS Field CISO - and his involvement in UN AI red lines and the American Society for AI's governance initiative demonstrates serious policy access. He is a credible practitioner-turned-leader rather than a pure theorist. However, the transcript reveals limited specific examples of direct operational decisions at Netflix or elsewhere; much of his authority rests on titles and network rather than detailed case evidence.
I happened to be lucky enough to get a job in intelligence, focused on technical intelligence... went to Mandiant doing incident response security operations, and then long story short, ended up at Netflix.
I'm actually a signatory on the UN red lines for uh AI development... I'm a part of another organization called the American Society for AI... the part that I'm leading is the non-proliferation part of it.
The episode largely trades in generality and forward-looking speculation. Chris mentions Anthropic and Mythos but offers no concrete metrics, timelines, or named case studies of actual AI-driven attacks he's personally investigated. The three-bucket framework and governance council concept are abstract templates rather than instantiated examples. The only concrete personal details are anecdotal (the Friday CISO call, the graphic novel, college thesis) rather than evidentiary of threats or solutions.
I would say about 50% of them are AI skeptics. Right. They don't want to touch it, they don't want to use it.
every Friday for maybe a year, I let a call of maybe 30 to 40 CISOs, and we would talk about everything from life to work to hey, what's going on with this particular threat
The hosts (James and Kieran) demonstrate strong rapport and chemistry; they ask open-ended questions and attempt to draw out practical advice. They push Chris on the tension between community support and real workload constraints, and Kieran directly challenges him to distill 30 minutes into 30 seconds. However, the hosts rarely press back on vague claims (e.g., 'hundreds of autonomous agents in 1-2 years' goes unchallenged), and follow-ups often take tangential turns (graphic novel, standup comedy) rather than deepening technical or strategic points.
So if we had to summarize your thoughts for the community and its leaders into one short sound bit, or sound bite even... what would it be?
Can I just at the risk of slightly putting you on the spot? But it's such a big question, and you've got a long and very distinguished career in government. What do you think should happen in terms of the way the state, the US Republic, the other countries, what should we be doing?
Computed from the transcript - who did the talking, and the words that came up most.
In this episode, Ciaran and James speak with Chris Cochran, Field CISO and Vice President of AI Security at SANS Institute, to discuss AI and cyber defense. Chris shares his perspective on the rise of AI-driven attacks, why community matters for security leaders under pressure, and what it will take to keep AI safe. Contact: Have questions or comments? Email us at cyberleadersnetwork@sans.org
Transcribed and scored by The B2B Podcast Index.
Welcome to Cyberleaders. I'm James Lyon. And I'm Kieran Martin. Welcome or welcome back to our show where the geek, that's me, and the generalist, that's me, get together to discuss a whole range of wacky, weird, wired, wireless, and wonderful topics for the cybersecurity leadership community.
The geek and the generalist, do you reckon we should call it that anyway? Thanks to Sans, where we both toil, we can bring you the perspectives from across the spectrum of tech security from someone who's been breaking the law. Sorry, that's a typo lawfully breaking qualification. We can hear from someone who's been lawfully breaking into all sorts of different internet weaknesses in order to help organizations defend themselves and give the baddies more bad days.
That's James, the Uber Geek. To the sort of issues around policy, operations, and posture that organizations need to defend themselves from the perspective of someone who used to run cyberdefence for the UK. That's Kieran, a geek in his own very special way. Yes, I have a community all of my own.
Well, there's a few of us. But anyway, we want to bring to you the perspective of expert guests from all over the world on different aspects of cybersecurity. Indeed we do. And loyal listeners.
We know there are some, and we love you. And we love our new listeners too. We do, but loyal listeners may have noticed that we've been trying out a few things of late. We've had special episodes on the Iran War and Mythos, but today it's back to brilliant basics.
Though still, I I think with the good helping of Mythos and wider AI, I mean it's unavoidable at the moment, isn't it, Kieran? Yeah, back to basics. You know me. Don't like change.
I'm still taken with that history teacher who told me that everything after the fall of Constantinople in 1453 is current affairs. But anyway, to take it all back to the way it was before, I just want to chat at extraordinary length to a great cybersecurity leader. Well, I can do one of those things for you, Kieran, because we do indeed have a great cybersecurity leader for you, someone who I think bridges the old and the new of this podcast. This is a brilliant community builder in cybersecurity.
Well, as you know, community really does matter. And a proper expert on operational defense in the age of AI. So today's guest is no less than a former United States Marine. He's also worked at a national security agency, Cyber Command, Mandian, and Netflix as well, which I'm sure is fascinating of its own.
Probably an impending movie. Well, I reckon there's a large Venn diagram of people who've served in the Marines, NSA, Cyber Command, and a sizable one, but smaller if you had in that grip company now owned by Google, Mandiant. But I reckon it might drop to one if you throw in Netflix. Well, let's ask him, because he's now Field CISO here at Sands.
Now, James, we both live in the English countryside. Field CISO, is that something to do with what's going on outside your window? Agriculture, you know, does he look after the security of food production? You are being very naughty now, Kieran.
That is silly even by your standards. Okay, I'm sorry. Boss. You know, you know you know very well that as field CISO and VP Hieritans, this means he works with all sorts of different companies helping their defenses.
He's also founded his own consultancy and hacker media platform. Great watch, I should say. And he's one of the most passionate and successful community builders I have ever known. Not just a thing I say to be kind in introduction.
It really is remarkable how well connected he is across those who are trying to make cyber criminals miserable. So joining us all the way from Dallas, it is the great Chris Cochran. Hello, Chris. Welcome to the show.
How's it going? James, Kieran, uh, so happy to be here. It's an honor to be amongst you great uh podcasting cybersecurity leaders. Well, thank you so much.
Our day is going much better now that you've joined us. So thank you. Now, James has already mentioned your absolutely stellar career, but he omitted one thing. And I know I said I'm not comfortable with the change, but I'm quite happy to announce the first.
I think you are the first published novelist we've ever had on the show. Am I right? The first published cyber novelist? Yeah, it has to be.
I don't know. I I've watched a few episodes. I'm not quite sure if I know the entire Rolodex of the folks that have been on here. But yeah, I uh wrote a graphic novel.
I have three daughters. They're 17, 11, and six. My 11-year-old, she's into anime and cartoons and all these things. And I thought, wow, wouldn't it be cool to take her likeness and create a graphic novel hero around her?
So I did, it's called Scotty Threat Hunter, and it's uh volume one of three. I'll eventually get to volume two one of these days, but she's a real girl that goes into this cyber world and is a threat hunter, tracking down all the baddies uh around the globe, taking down ransomware, taking down AI-generated bots, all kinds of different things. That's amazing. And it's probably the first time we're gonna put a link to a graphic novel in the show notes.
And the plot seems to be about turning innocent users into zombie bots, so maybe that's a segue into mythos, but maybe we'll come back to that later. Yeah, I mean, sounds about right, but yeah, it seems like it was ahead of its time, and all of a sudden it seems to be coming more and more reality every day. We've been struggling with the answer of how we should advise security leaders in the next five years. I think we've got the answer here, and we just need to get Chris to sit down and write a future prediction, the uh Nostradamus of cybersecurity in graphic novel form, right?
Well, we need volumes two and three. Don't do what my namesake's George R.R. does and leave us hanging for the last two books.
My daughter asked me every other month. She's like, is it almost done? I'm like, I haven't started it, maybe. Well, look, Chris, now we've got that extraordinary first out of the way.
Let's start by talking about your novel career. And no, I don't mean your novel writing one. I mean your unique story. See what it is there.
Quite happy with that. Lovely. Very good. Uh, we always ask people about their path into the industry.
And yours is, you know, really fascinating and compelling story. So tell us about it. How did you end up in cybersecurity? Yeah, I'd always been interested in technology ever since I was a kid, sort of the classic, hey, I want to break this thing apart and see how it works.
But I really wouldn't get my start until I joined the United States Marine Corps. I happened to be lucky enough to get a job in intelligence, focused on technical intelligence. So I was able to utilize that desire and that passion I had for technology for the work that I was doing. And, you know, obviously being focused on intelligence, it felt like I need to be able to do more, right?
I don't want to necessarily stay in the government forever, even though there are people that do that. And I might even go back to the government one day. But uh I wanted to get out there in the world and industry. So in order to do that, I actually created my own company standing up threat intelligence capabilities for organizations.
And so I did that for a little while, went to Mandiant doing incident response security operations, and then long story short, ended up at Netflix. That's where uh I really started to lead in the threat intelligence space and going into more incident command education for other folks. Around that time, that's when I started a podcast with a good friend, uh Ron Eddings. And then we ended up building out to Hacker Valley Media, which I no longer lead.
I uh passed the reins over to Ron, so it's in really good hands and he's done some incredible things since then. And yeah, I would say on the AI side, you know, my first entry into AI was uh my senior year in college. My thesis was on digitizing the human brain. And yeah, I, you know, I read that paper maybe six months ago, and uh I actually got quite a few things right about how language is gonna play a part in uh artificial intelligence.
And we won't talk about all the stuff I got wrong because that's not important. The important part is I got some things right. And so ever since I would say even right before GPT-3 came out, I was dealing with some generative stuff in the smaller cyber communities, just playing around and trying to figure out how do we leverage this. And then all of a sudden, GPT-3 kind of opened up the floodgates for just about everybody.
And so that's when I just went head first. I was like, hey, how do we wrap our brains around this AI thing? And that's what I've just been doing ever since. So I have two observations and a question.
The first is very on brand for the cybersecurity community to talk about the areas we were right in our predictions and ignore the others. Love that. Secondly, Kieran, I'm starting to suspect, given his early work there on the digital brain, we might be talking to a clone of Chris. But he's doing a good job on the podcast, so I suggest we continue and see if we can find the real Chris later.
Yeah, you're the techie, you have to detect it. He's convinced me. We'll work on it in the background whilst he's answering my next question. Chris, I want to ask you about your work on community building.
It's a real passion for you, I know, and it's one I share. You've heard me say bet on people and talk about how the cyber criminals have their community, so we must have ours. You've spoken so much about it and you've done so much to build it. So tell us about what the cybersecurity community is, its strengths and weaknesses, and what it means to you.
I would say the cybersecurity community has a life unto its own. I would say very early on, I felt like there were pockets of folks kind of gathered together. And being from the government, also, you know, working with classified material, it wasn't like I could contribute in any measurable way. And so largely I was on the outskirts.
I felt like, wow, I want to be a part of this community, but it doesn't seem like there's a way for me to really connect. And then I really didn't get that opportunity to connect with the community until I started speaking. I started speaking, then I started doing the podcast. You got on the circuit, didn't you, Chris?
Oh, yeah. Yeah, I did. I went pretty uh pretty hardcore into the speaking circuit to the point where I was always trying to look for opportunities to improve my ability to speak, to include going to LA to a comedy club and doing five minutes of standup, which if you ever do that, anything else is going to be super easy from a public speaking standpoint. Kieran, we've got to find that.
We've got to. We have, and we will, we must. But yeah, I would say the best thing that I realized once I started sort of building my own uh little community is that there are a lot of folks out there looking for a community. And so I've always been of the mind, hey, the more, the merrier.
We need as many people from as many aspects of life as possible. Because if you think about it, cybersecurity is all about problem solving. That's all we do. And so to have different ways of thinking and being able to share that trade craft, being able to share those best practices is honestly how we're going to get through any obstacle, how we're going to get through any storm to include this artificial intelligence, autonomous attack storm that I think is brewing.
So I would say that I've done everything from created communities for people getting into cybersecurity. I've created and been a part of some really great CISO communities. But I would say that having a community is one of the most important things that we can do as human beings, but especially cybersecurity practitioners. Well, let me pick up on something really important you said there, Chris.
So you talked very passionately about this community that you're such an inspiring part of, but you then mentioned communities facing challenges and you highlighted the big one, the one we're all talking about. We can't really come back to the community without touching on the pressures of the new AI models setting the cybersecurity world ablaze. Mythos preview, the open AI delay of their own model, the anticipated vulnerability storm, as you called it. So let's get into that.
James, what do you think? Yes, indeed, Chris. First, you know the big question, right? Cut through all the debate and hype for us, would you?
We got a whole range of views from this is the apocalypse and rise of the Terminators to frankly nothing has changed, and this is asinine marketing. All the way from the end of the world to great opportunity. So, what, so far as you are concerned as an expert, can these models do that we actually need to take stock of? So I think that mythos is a step in the right direction from a couple of angles.
Its ability to do static analysis on applications and find vulnerabilities very quickly, I think is fantastic, right? There are folks that are already out there using it. They're trying to find the flaws and the vulnerabilities before the bad folks do. The other thing I think this really starts to highlight is the power of models and the controlled release and the control of access to that particular model.
But here's the problem that I'm seeing. The problem I'm seeing is that are we going to, in perpetuity, prevent the development of models and the release of models publicly in order to support national defense or cybersecurity? Because here's what I mean. Sure, mythos was focused on cybersecurity, finding vulnerabilities, but the problem is as these models continue to improve, they're going to improve across the board.
So, what is to say that a year from now, the regular models that everyone has access to today turn into exactly what we're afraid mythos can do in the hands of an adversary? So I'd be really curious to see how this starts to unfold from a control perspective and an access perspective. Can I just at the risk of slightly putting you on the spot? But it's such a big question, and you've got a long and very distinguished career in government.
What do you think should happen in terms of the way the state, the US Republic, the other countries, what should we be doing, thinking about in terms of that almost potentially existential question? Yeah, so there's quite a few things that we should be doing. I'm actually a signatory on the UN red lines for uh AI development, which is there are certain things that AI shouldn't do just in general, right? But then also I'm a part of another organization called the American Society for AI.
And right now, what we're doing, we're calling it an AI constitution, but at some point I think the name is going to probably change. But this is all about how do governments around the world coordinate and orchestrate together to make sure that we have control over the AI that we're developing. So the part that I'm leading is the non-proliferation part of it. And so that's about, hey, how do you ensure that we aren't bringing something to the world that isn't going to be catastrophic for a number of reasons, whether it's for nuclear or biological, whether it's the Skynet, whether, you know, this thing just changes the world from a psychological operation standpoint.
I would say that uh we need to really start to think about how do we measure capability? How do we ensure that the people that need to know this capability exists? And then also how do you control that capability? I think is going to be ever more increasing as we continue to go down this AI race with all these great Frontier labs.
Well, and Chris, I guess building on that, what do you think this means for defenders in kind of practical terms now and over the next few years? What should they have their sights on, do you think? So this is something I've been talking ad nauseam about all around the world, basically. I see this, right?
The stuff that Anthropic talked about at the end of last year with the autonomous attacks, it was meant very similar to the Glasswing mythos stuff, very mixed bag. Some people felt like this was the end of the world. Some folks felt like this was just automation, just a little bit faster. But this is what I saw.
I saw the tip of the iceberg. I feel like it is not a stretch of the imagination that within three months, six months, nine months, a year, maybe two years, we're gonna have tens of thousands, if not hundreds of thousands, of autonomous agents looking for targets of opportunity for the adversary. And so, from my perspective, I think that we need to do a couple things in order to prepare ourselves for that inevitability. I don't think there are a lot of folks that are really looking at it right now.
And for good cause, everyone is doing their work. Cybersecurity practitioners are already fighting fire to fire, right? They don't necessarily have the time to always pop their head up and look around and see what's going on. I just will happen to be in a position where I'm talking to a lot of these folks.
I'm reading the tea leaves. And so this is what I'm seeing. So, from my perspective, we have to do a couple of things. Number one, we have to get our houses in order from a cybersecurity perspective.
There are way too many foundational things that we've never really gotten to, or a lot of folks haven't gotten to. Things like workforce identity. We never really quite nailed that. Chris, I call it the pile of shame, the things we know we should do.
It is. I mean, it is. We tend to sweep it under the rug and hope that it never comes to pass where we have to deal with it. But I think we're having to get to a point where we do have to deal with it, right?
Because then we brought non-human identity to the picture, and that got more complicated. And then we were like, hey, this isn't complicated enough. Let's bring agents into our organization. And now we have to figure out agentic identity.
A lot of folks don't really have a good incident response program, right? We need to get some of these things completely shored up because the bigger the holes are in our system and our programs, the harder it's going to be for us to keep up with these autonomous attacks when they start to happen. But then also, how do we start to leverage AI ourselves for the protection of our organizations or the people that we love? And so believe it or not, I speak to people, I've probably spoken to hundreds of people over the last several months.
And I would say about 50% of them are AI skeptics. Right. They don't want to touch it, they don't want to use it. They say, you know, it's a fad or it's wrong or it's bad for the planet.
And this is what I say each and every time. I say, you can no longer afford to be an AI skeptic. Worst case, you can be cautiously optimistic. But because the adversaries are leveraging AI, you have to then fight fire with fire.
And so we can't just stand idly by and think that with our manual hands, we'll be able to keep up with machines. So I'd say that this is a lot of the things that I see for the cybersecurity practitioner in the coming months, years. So, Chris, that's really interesting. And I think whether you're one of the remaining AI skeptics, or even if you're not, even if you're convinced, when I was listening to your masterclass and conveying advice to people about putting our house in order, and then you started to talk about the workload and you started to talk about the pressure on skeptics and pretty much everyone, I started to think about bringing the two themes together.
And I think this is something that James and I really, really want to ask you. So this is a truckload of work, whether you're enthusiastic about it or skeptical about it. Uh, you can see where this is going. How is the community that we and particularly you care about so much supposed to cope with all of this stuff?
You know, give us something to think about in terms of workload, overload, burnout, the challenge of talking to C-suite board leaders about all these problems. This is a paradigm shift, but how do they cope with all of this alongside all the other things that they already have to worry about? That's a huge problem. And that's a problem that I'm constantly trying to think about how do I help the community as much as I possibly can?
Where can I pitch in and be of service? And uh I've given a talk several times about burnout and how burnout happens for several different reasons, right? But I would say one of the big things, especially when you know you're talking about cyber leaders, they are kind of getting it from all ends, right? They have top-down pressure to say, hey, what are we doing about AI?
How are we going to secure it? And then having to figure out what AI is in general, right? We didn't just come out of the gate and everybody knew about AI and all the aspects for it. But then you also have to learn the security aspects of it.
Then you're trying to talk your teams into using AI and they are giving you pushback because they say, hey, we don't do that, we do it the old school way. And then you're dealing with your fellow C-suite folks, and you're dealing with incidents, and then you got cyber insurance that you're dealing with. So it's really a tumultuous reality for a CISO today. And I would say multiple things.
Number one, community. That is the most important thing that you could do for yourself as a leader is find the folks that are in your area in your industry that you can speak to, that you can speak freely, because being a CISO is a lonely job. So, shout out to uh one of the best CISO communities out there, the security tinkerers. Became a security tinker, I think, in 2019.
And then when 2020 happened, everything shut down. And I actually started this thing uh every Friday, I was doing a call. It was called NextGen. These were directors, VPs that were looking to get to CISO eventually.
And it became so popular, the CISOs from the security tinkerer community started to join as well. So every Friday for maybe a year, I let a call of maybe 30 to 40 CISOs, and we would talk about everything from life to work to hey, what's going on with this particular threat to hey, I'm having a hard time at home, yada yada yada. And people found that so valuable because if you're just sort of stuck in your own mental echo chamber, it can feel like you're alone. You feel like everything you do is wrong, you feel like everything is just kind of coming at you.
And sometimes all you need to do is talk it out. Sometimes you just have to say it out loud to someone else, to another human being. Uh, but I would say that the more we can band together as leaders and work with each other, that'll help prevent burnout. That's step one.
Step two is really get good at communication. I think that from a communication standpoint, that's something we felt like we learned in grade school. And then all of a sudden we really kind of just left it and we don't really increase our ability to communicate. But whenever you communicate with someone and you're able to convey information, but also tied to emotion, whatever emotion that is.
And I'm not saying to manipulate people, but if you want a desired outcome, if you want to really send a point home, you have to understand the power of being able to tell a story. Storytelling is one of the most important things in the world because if you can tell a story to a board or a CEO or to your team and it puts in their mind exactly what you're dealing with, and then you can let them know how they can help and how actually this would also help them in return. That's where things start to have this inflection point of posity.
But when you feel like you're in it by yourself, you're gonna constantly feel burned out. You know, Chris, I love that communication point. I think it's so important. And I would highlight to folks as well that is an opportunity area for AI to specifically assist that isn't about, you know, the technical application of models to vulnerability discovery or or otherwise.
It is Rather good at this, but it also takes some time and practice. It's very easy to generate generic M-propagated text that frustrates the listener with feeling like you didn't really put any original thought into the communication. So using the tools the right way and doing what Chris said on storytelling, I think is immensely powerful. But Chris, if I could narrow this question down a little more for some of our audience again, you have lots of wonderful advice.
So I've said many times on this podcast security teams run at a hundred percent capacity or more. They're always busy, there's always something going on, and this just adding to the workload, let alone trying to dissect the latest press release on why a model might be the end of the world or quite helpful. So security leaders are going to have to make time for their folks to work on this. Assuming they do that and they find a way to open up some space.
Where should folks first spend their time? And I know, Chris, it's hard to answer this universally. I mean, looking at some of our folks developing our new AI classes, such as how to use AI for vulnerability discovery, it does require a lot of the security knowledge of the original problem domain as well as AI orchestration and management skills. So I know you can't truly silver bullet this, but if folks get time from security leaders, how might they deploy it to make themselves feel a bit more connected to the future of AI-augmented cybersecurity?
I would say, you know, at SAMS, we kind of look at AI in three different buckets. One bucket we think about how do we utilize AI. So from that perspective, even if you have to just think about what is one thing that I can start to leverage from AI that could save me the most time or to make this product that much better, like really just start to find those little use cases where you can really start to lean on artificial intelligence from a protect position for artificial intelligence.
What are some of the failure modes in which you need to understand, especially for your organization, right? How do I think about what is the worst case scenario for my business? I used to say when I was uh doing a lot of threat intel work, I used to say, I want you to think about what is that headline that would be in the newspaper that would absolutely gut you. And then how do you prevent that from happening?
So you have to start to think about threat modeling and failure modes. And then ultimately, I think the most important aspect of it is like governance. And then again, governance, you can't do that in a bubble, right? Artificial intelligence isn't just an IT thing, it isn't just a security thing.
AI is becoming an integral part of every aspect of business. And so now you have to start to think about who are the different stakeholders we really need to bring together to start to figure out how do we govern artificial intelligence together. So creating something like an AI governance council from around the organization, I'd say those are the really the high leverage. If you get a little bit of time to start to wrap your mind around some of this stuff, that's where I would put a lot of my dollars.
Wow. So this is turning into one of my favorite ever episodes for all sorts of reasons. The community, the technical expertise, the bringing the two of them together. But most of all, I think this is a masterclass on how to convey an awful lot of really useful information.
In a very short period of time, I'm talking to you from a well-known university, and the students often talk about communication skills. And if James releases the copyright, I think I'm going to get them to listen to this. But therein lies a challenge for you, Chris. That's something we can do, Kieran.
Fair enough. Thank you. But for the short version of the class, but also for James' benefit. Chris, I'm sorry.
Ah But go on, I I'll see where you're going. I suspect you're about to be cheeky. For James's benefit, you have to condense all of this into less than half a minute. Yeah, see, I knew you were gonna be cheeky.
That's not exactly how I'd put it, Kieran. Of course you wouldn't. That's classic CEO behavior. You'll deliver a sucker punch in velvety language.
That's what you people do. Oh harsh. Maybe fair. Who knows?
Anyway, what Kieran actually means, Chris, is that this is a podcast for hard-pressed security leaders. And look, we've covered so much about the state of the industry, the AI challenges, and what they themselves need to be doing. That is a lot. Now we don't want to overwhelm people.
This podcast is supposed to be a break from CISO Burnout, after all, not a contributor to it. The end is nigh, panic. So if we had to summarize your thoughts for the community and its leaders into one short sound bit, or sound bite even. Ha ha.
Double word. Oh, see what you did there again. This is excellent stuff. Well, I love a data size joke, you know, absolutely.
Just a nibble. Anyway, a bit of advice on the road ahead. What would it be? I believe that's called the 30-second takeaway, Chris.
So take it away. All right, 30-second takeaway. I would say be intentional. And that might sound like it would add to burnout, but I'll say this: be intentional around how you implement artificial intelligence.
Sit and think about it. Just pause for a moment. Even with your teams, be intentional. Be intentional about how you operate with them.
Every moment should have a reason. It should have a why. Really focus on what are the important things I need to do today in order to save my team time, save my team, my organization heartburn. Be intentional about all these things.
Even if you have to just sit and think for a moment about hey, what would be the next step from my perspective? Be intentional and center everything around people and community. I would say that's all I'd have to say. Absolutely wonderful.
Brilliant takeaway. And I'm afraid all I have to add to it is the end is nigh. But don't worry, only the end of the episode. I do love that advice though, Kieran.
I do think much of the burnout issue, the fatigue, comes from over-reliance or over-avoidance. Completely. So kind of rotating tasks deliberately, using AI for some things and not others to keep our brains working. I really rather like that takeaway.
He's quite good at this communication thing, isn't he? Oh, sorry, Chris. You're still here. Are we still here?
Thank you so much for joining us today, Chris. I think you've shared a lot of incredibly useful advice for our community and hoping you'll join us again at some point. Oh, absolutely. And you guys are fantastic.
This was so enjoyable. We'll definitely have to do it again. Well, you can definitely come back having said that. But that is all we have time for today.
So do leave us a rating, a really good one, because this was a great episode. Thanks to Chris. Do leave us a rating wherever you got this podcast. According to people who understand modern communications technology, they tell us it helps if you do that, especially if you leave a nice, good, strong rating.
And if you have any suggestions or follow-ups on our show, you can email us at cyberleaderspodcast at sands.org. And with that, thank you very much for listening. Thank you for listening.
Keep cybering from me, Kieran Martin, and me, James Lyme. It's goodbye. And remember, an AI task a day keeps the bad guys away.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.