
Cyber Leaders · 2026-05-22 · 43 min
Key moments - from our scoring
Substance score
68 / 100
Five dimensions, 20 points each
Kevin Jones brings two decades of experience to this conversation, having shaped his thinking through early hands-on technical work, deep academic research into human trust and multi-agent systems, and leadership roles at complex organizations like Airbus and Bayer. The discussion covers the specific challenges of securing global operations with mixed environments - from legacy OT systems to cutting-edge agentic AI platforms - and how a platform-based delivery model enables both stability and continuous adaptation. Jones emphasizes that the real security challenge isn't technology scale but organizational clarity: translating the overwhelming complexity of 15+ simultaneous initiatives into three coherent business outcomes. He advocates reframing security from compliance language ("ISO 27001 tick") to outcome language (enabling market access, customer trust, company resilience). His research background in human-centric cybersecurity - including pioneering the employment of psychologists in security teams - and current work with the Cyber Innovation Hub Wales on commercializing academic security breakthroughs add depth to his perspective on how organizations should think about both immediate threats and long-term capability building.
Compress all initiatives under three business outcomes: license to operate (enabling market access), customer trust (mission delivery with stakeholders), and company resilience. This shifts framing from compliance language to outcome language that resonates with business leadership.
Managing scale, complexity, and global regulations - organizations must operate stable, standards-based security platforms across mixed environments (legacy OT, cloud-native, AI systems) while adapting to regional compliance requirements and emerging threats simultaneously.
Human trust in multi-agent systems was foundational to his PhD work in the mid-2000s; he found psychologists could improve system design, threat analysis, and decision-making in security operations by applying behavioral science principles like those in aviation's Black Box Thinking.
A platform-based delivery model - rather than project-based or ad-hoc operations - provides stable foundations while allowing continuous improvement and rapid adaptation to new threats without rebuilding security from scratch each time.
Outcome framing (e.g., enabling NHS delivery) ties security directly to business value and market opportunity, making the business case clearer and helping security teams align with organizational strategy rather than appearing as a separate compliance function.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains solid, pragmatic guidance on AI security strategy (four pillars: AI-against-AI, governance, defense of AI models, using AI defensively) and organizational framing (license to operate, customer trust, resilience). However, much content is conversational scaffolding, banter, and biographical setup that doesn't advance security thinking. The core AI insights, while sensible, lack depth and novelty - treating deep fakes, vulnerability management, and governance as known problems without concrete countermeasures or data.
attackers have AI today and are using it quite effectively
the first one I would say in there is deep fake technology is being used widely by attackers
The episode rehashes familiar frameworks (risk-based approach, threat modeling, governance councils, DevSecOps) and relies on standard industry terminology without fresh reframing. While Jones mentions ideas like 'security fabric' and 'human intelligence' over AI-first thinking, these are presented as extensions of existing thinking rather than contrarian or novel arguments. The discussion of AI's limitations is sensible but not particularly surprising to security practitioners.
everything we do should underpin on three things: license to operate, customer trust, and company resilience
they're definitely artificial. That's a quote. So they're exceptionally good at mimicking humans and finding data
Dr. Kevin Jones is a genuinely credible operator: currently Group CISO of Bayer (90k employees, 80 countries), 10+ years at Airbus in senior security roles, published 50+ peer-reviewed articles, PhD in multi-agent trust systems, and honorary professor at Cardiff with real institutional leverage (Cyber Innovation Hub). He brings concrete experience architecting security at massive scale across sensitive sectors (pharma, aerospace, agriculture), not theoretical commentary.
he is the one and only Dr. Kevin Jones
group CISO of an organization of around 90,000 people...who operated across 80 different countries
The episode is light on hard data and named examples. Jones mentions deep fakes used in fraud, AI-accelerated vulnerability exploitation, and open-source supply-chain backdoors, but provides no metrics, timelines, or case studies. References to incidents are oblique ('faraway lands' for the 2012 ICS incident) rather than concrete. The Bayer operating model is described in terms of principles (platform-based delivery, risk-driven prioritization) but without KPIs, adoption rates, or measurable outcomes.
I mean, you're producing things and elements...depending on the maturity
we've moved to a platform-based model for delivery of our security...It's not projects, it's not different operations every time
The hosts (Kieran Martin and James Lyne) ask sensible follow-ups and show genuine curiosity, but rarely press Jones on specifics or challenge his claims. The conversation drifts frequently into banter and tangential topics (Bayer pronunciation, existential questions, random references to Hitchhiker's Guide). A few sharp questions emerge ('how on earth do you prioritize between data protection and operational safety?'), but these are not consistently pursued with rigor. James explicitly softball the 'solve world peace' framing rather than demanding concrete priorities.
if everyone has AI...the edge once again is human
how on earth do you prioritize?
Computed from the transcript - who did the talking, and the words that came up most.
In this episode, Ciaran and James sit down with Dr. Kevin Jones, Group CISO of Bayer and honorary professor at Cardiff University, to discuss cybersecurity across critical industries. Kevin shares his expertise on human behaviour in security, the growing impact of AI on both attacks and defences, and the challenges of protecting complex, real-world systems. Contact: Have questions or comments? Email us at cyberleadersnetwork@sans.org
Transcribed and scored by The B2B Podcast Index.
A very warm welcome to Cyberleaders with me, Kieran Martin. And me, James Lyme. Now, we're both from the Sands Institute who are kindly backing this podcast. I myself am a geek, a massive geek, I might say, that spent my life chasing cybercriminals around the internet.
And what am I? Well, whatever I am, I'm not that. But I dealt with cybersecurity policy and government and cyber operations, and I set up the UK's National Cybersecurity Centre. Now, together, these days, James and I are trying to unpack the weird, wacky, wired, and wireless world of tech security and all the complicated things that it involves.
I love that over each season you're adding an additional W, and by the end of this, it's going to be a mega paragraph. Wolverine will make an appearance. I'm holding you to that. Okay.
But look, folks, this podcast is a voice for security leaders and Wolverine, apparently. We want CISO's security directors and beyond to build up their knowledge of what works, what doesn't, and ultimately secure your organizations more comprehensively and quickly. Now, Kieran, starting off today, I've got some questions for you. You have so many questions.
I'm here for you, my friend. Times are tough. We must stick together. Tell me what's bothering you, and I will help you find true peace.
Well, that's not exactly where I was going. This is actually less existential and more cybersecurity questions. Well, that's very embarrassing. I'm sorry, I thought you were gonna ask me what the purpose of it all is, and um, I was ready for some existential questions about the meaning of it all.
But anyway, you carry on. Yeah, uh how are we gonna recover? Um, well, here we go. So I have some existential cybersecurity questions for you.
How about that? Well, I'm just as bad as those. I'm at meaning of life questions, but but let's give it a go. We're back on track, Kieran.
In as much as we ever are. We're never on track in this podcast. There is no such thing as on track, only variations of off-track. Graduations of off-track.
I like those things. Graduations of hacked, maybe one might say. Yes. Anyway, look, two questions.
Nope, 42. That's the answer to number one. Probably number two as well. No, look, no Hitchhiker's guide to the galaxy for you.
These are important questions. Oh, okay. So behave if you can. I'll try.
So first, when you were at the National Cybersecurity Centre, what sorts of sectors did you worry about the most? Well, there were all sorts. At the time, 12, 15 years ago, the banks, the telcos and the energy sector, they were always banging at your door. But then you had all the really serious ones like pharmaceuticals, healthcare, food production, transport, defence.
And we started to worry about them big time, but they weren't on the radar so much right at the very start. But I think now with all the resurgence of criminal attacks, we've talked about those in previous seasons, all those attacks disrupting networks, the whole geopolitical situation getting worse. We had a whole episode on Vault Typhoon type stuff. Those sectors like health, pharma, agriculture, absolutely crucial.
Yeah, look, Kieran, I I was half expecting you to say there were 42 companies you were concerned about. Way more than that. But that was actually half sensible. Thank you.
And by the way, folks, if you didn't listen to it, going back and listening to the story on Vault Typhoon, absolutely worthwhile, just fascinating and incredible guests. But let me continue to question two here, Kieran, whilst I've got you in sensible mode. Yes. When you think about that now and these massive, crucial economic sectors, what do you think those sectors need to be thinking about in the age of AI?
Has anything changed? That's a really good question. Can I ask ChatGPT? And there I thought you were making some sense for a minute.
Well, no. Well, I I I think you technically could, but as for the podcast today, no. We will not ask ChatGPT or other LMs that are available for that matter of fact. We will ask our guest.
Now he may decide to use ChatGPT, of course, Kieran, but that's up to him. Well, that sounds much better. So who is this guest? Well, the great reveal will happen momentarily, presumably whilst he's asking ChatGPT.
But put it this way: it's someone who is breaking new ground in AI security strategy at a massive scale across a whole range of critically important sectors. So what you're saying, James, is that you want to know more about how to do AI security strategy in some really complicated and important sectors, and you've got three options. In third place, it's chat GPT. In second place, it's me.
But in first place, you have a great guest. Yeah. Well, let's leave the second versus third place discussion for now. No.
That's probably some version of right. But you've got one thing right here that's crucial. We've got a great guest who's better placed than anyone to bring to life the implications of revolutionary new technologies to really complex and important environments. Okay, so it is time for your great reveal.
Who is our guest? We have today the group CISO of an organization of around 90,000 people, enough to fill Wembley Stadium, who operated across 80 different countries. That in of itself makes it an incredibly challenging job, I am sure. That company is Bayer, a world-famous conglomerate operating across pharmaceuticals, healthcare, and agriculture.
But that's not all. Oh no, that wasn't enough to have someone on a podcast telling us about the challenges of cybersecurity. Before that, he spent well over a decade at very senior security roles at Airbus, applicable again, building on an already very wide and deep experience in cybersecurity. And there's more, he's an honorary professor of cybersecurity at the University of Cardiff, who's very familiar with rain, of course, in his native Wales.
And he's published over 50 articles on everything from the use of threat intelligence to the cybersecurity of industrial robotics. And rumor has it, he didn't use ChatGPT to write any of them. It is the one and only Dr. Kevin Jones.
Hello, Kevin. Welcome. Thank you both. Uh ChatGPT reliably informs me that I am, in fact, a recovering techie.
So I sit perfectly between the two of you. I used to be techie, now I'm more on the policy and strategy side. But really good to be with you and to see you all again and have the chance to spend some time with you both. Well, thank you.
And let's feed ChatGPT with some more lines of varying degrees of truthfulness. So, James, why don't you get started with our normal question for cyberleaders about Kevin and his path into this industry of ours? Absolutely. Well, look, Kevin, as Kieran said, thank you so much for coming on the show.
It is a privilege to have you. Now that we ask this question, as Kieran says, to pretty much everyone to show the diversity of ways in which people get into cybersecurity leadership positions and how their background shapes their thinking and produces the different types of leaders that we run into out there. So for you, tell us your path. Were you a cyber geek growing up?
But you've already mentioned your recovery, a late bloomer. Did you always want to mix private sector work with academia? How did you get into it? I actually, believe it or not, joined the industry at the age of 14 or 15, working in cyber cafes, if you can remember what they were.
Back in the days before uh anyone had the internet at a home. It was all ISDN and scratching the back of my brain there, Kevin. Oh, ISDN. Oh and ripping out token ring networks, replacing them with early Ethernet.
That's how I really started and started learning. But actually, unlike today, where there were so many career paths and directions you could go in. I mean, there was nothing like online hackathons or even formal training courses in the UK in schools. It didn't really exist.
It was kind of desktop publishing type thing. So for me, it was all self-learned and another blast from the past, if you remember things like ICQ and the chat messaging. And that's how we all self-taught each other and drove from there and continually learned. Thankfully, I was very fortunate to go to university and do computer science.
So that's where the academia piece really started to come in. And equally was able to combine both my passions because I was able to play sports at a decent level as well at university whilst studying and rather enjoyed that. So to did a master's and then eventually went on to do my PhD, but always kept a hand in industry as well as academia. So consulting, doing various things.
And I'm very privileged to have worked really on the offensive security side, ethically, of course, testing security of companies and environments, and actually over the years in some very specialized areas. I mean, uh built out one of the UK's leading commercial industrial control system labs and built out a red team that was specialist in aircraft or satellites and industrial control systems. Worked very much on the defensive side too as an architect, and then gradually shifted away from hand-on keyboard and into the more strategic and business uh side of life.
And I think that's a natural direction to go as you're managing business risks for the CISO. So really always learning, always wanting to do different things. I get bored easily. I think that's probably my downfall.
So come through the industry in that direction. And it's really multidisciplinary. And then that's one of the things I love about this industry. It doesn't matter really how you get into it.
I know some great people who come from degrees in all kinds of different subjects, humanities subjects, and really huge amounts of value they can bring to our industry. It's not just about tech. And I still today, even as the CSO of a company, you never stop learning. But I love conversations, deep technical conversations, one minute, conversations with governments the next about what's going on, and then risk teams and then business teams.
And I think you really need that flexibility. And somebody used the word fungibility. There's one you can look up on Chat GPT later on about how you adapt and evolve. So this is absolutely fascinating.
Thank you. Really varied. In James's introduction, we could have gone even further and talked about not just the range of experience you had, but sort of the depth of it across different subjects. This academic stuff.
Now, I also work in a university, so find it quite interesting. So, first of all, straightforward question, because I think the answers are always fascinating. Tell us about your PhD. What was that in?
After all your cyber cafes and then studying computer science, and then you sit down and you've got something of your choice. What did you do that in? My PhD was actually in mapping human trust in multi-agent systems. So this is long before zero trust was a thing.
It's long before we're in the AI world. And I keep saying this is over 15 years ago, I mean, nearly 20 years ago, probably I was working on some of these research topics. So I keep joking and saying now is my time that we were doing formal mathematical modeling in temporal logic of human cognitive trust in multi-agent systems and identity of agent systems. So I'm looking forward to seeing where the industry goes.
Sounds familiar, right? That does sound a little applicable to the zeitgeist of the moment. It does, doesn't it? And when did you do this PhD?
Sorry, I know this is asking you to give away your age in part, but you know. Oh, so I think the the early research was sort of mid-2000s, uh, right the way through to about 2010, I think we were we were there. Well, if you're interpreting our questioning as hostile, then we're asking you to give away your AIDS. If you're interpreting it as friendly, we're asking you to measure uh how far ahead of your time you were.
So look one last question for me on this academic side. So you've published, I think, several dozen articles on all sorts of different subjects, other than your PhD. Is there one area where you thought, wow, this is really cool, and I've made a difference here? I'm really proud of things like the human-centric research that we've done in the past with Cardiff University and other universities as well, De Montford University and Leicester.
And I think I was, if not the first, I was certainly one of the early adopters for employing psychologists in cybersecurity teams. And even today, some of that research is paying dividends in terms of being able to protect ourselves, design systems. And actually, there's a great book called Black Box Thinking by Matthew C. Ed, which is all about the aviation sector.
That is a good book. And how you design systems, think about decisions you're making, think about the psychology, and security can learn a lot from that. So I'm really proud about that. I'm also quite proud about some of the industrial control system stuff we were doing.
Um, should I say that there was an incident, small one that everyone seemed to realize in about 2012 in the industrial control system space, which I won't name. Kind of faraway lands. Yeah, yeah, faraway land, those kind of things. We were doing research long before that and in that domain and definitely shortly after that.
So I'm really proud of that. And one thing right now, actually, I've switched it up a little bit. So I'm really proud of some of the work we're doing right now with Cardiff University around the Cyber Innovation Hub and Cyber Innovation Hub Wales. Yeah.
In the UK, for me, we have fantastic ideas and fantastic academic approaches to these types of things. We don't seem to be able to commercialize them very well. So the idea of the Cyber Innovation Hub in Cardiff is that we put academics with entrepreneurs and we actually train and educate entrepreneurial mindsets into people and even seed some new businesses and some new startups with a little bit of funding to get them off the ground. And there's some really cool businesses coming through.
And the idea being that we're going to design for scale and growth and not just cottage industry security for the UK, but really designed from the outset for investment into and go for seed rounds and A and B rounds. And I think that's quite innovative. I'm not really seeing anybody else doing that, taking the academia, the government, the industry, and entrepreneurs and putting them all in a melting pot and seeing what comes out. So I'm really proud of it, the team there and what's going on.
Well, this is growing great so far in that absolutely fascinating stuff. But I think if I've been taughting it up, we're on about 27 different topics we could explore because we've, you know, we've referenced offensive security now, skills, innovation, the human-centric aspect of it, robotics, whatever, industrial control systems. And so that's five. I'm not going to try and list all 27.
So we're going to have to try and narrow this down a bit and focus in on some points, particularly on some of that big system security and AI. So I'm going to get James to start leading on that. But just to segue into it, we always debate terminology in our industry, you know, and even pronunciation. So SISOS, SISUS, CISUS, etc.
So I need you to give us the official pronunciation of your employer company because I've heard so many different versions of Bayer, Bayer, Bayer, et cetera. And my accent doesn't help. So how do the Germans pronounce this world-famous and strategically crucial company? I would disappoint you because the Germans and the Americans pronounce it slightly differently.
And we're a global organization. Oh, this is good. No, this is good. So I think you can say either Bayer or Bayer or Bayer.
Bayern. So um you can have as you wish. Feel free. Excellent.
Right. Well, with that clarity, over to you, James. So many options. I feel like we should maybe take voice prints of each and then run a mathematical average and ask AI to form a perfect pronunciation that everyone could agree on.
But as we're not doing that today, and you've asked me to focus, Kieran. Kevin, one thing that's really obvious as you read about you and talk to is you don't do cybersecurity small. I mean, just all the descriptions you've given us in the opening, big problems, big ideas, many of them considered kind of many years before they hit their mainstay. But also organizations.
I mean, Airbus and now Bayer, I mean, huge organizations, really complicated supply chains, tons of operational technology, fascinating and challenging customer base, massive risk profile. I mean, it's probably easier to list the threat actors that might not be interested in you rather than the ones that might be out to get you, unlike many people on the planet. So a lot of our listeners will be from smaller organizations and kind of wondering what's different about operating at the scale that you do.
As a leader in terms of the security problems, I mean interested from every perspective. There must be some real advantages, but there's got to be some drawbacks as well. Yeah, I mean, I told you I didn't like to be bored. So these big organizations are definitely keeping life interesting.
I think the first thing to say though is every company is a target, either because of what the company is, what the company does, who a company is a supply chain to, or just because cyber criminals are randomly targeting things on the internet to see where they land and spray attacks. So it would be a myth, I think, and a misconception to say it's only the big companies that are targeted. But you're absolutely right. I mean, companies like ours are usually targeted for different reasons.
I mean, obviously things like intellectual property theft, big well hunting, we'd be a big target in terms of cyber criminal gangs, those type of things. And some of the headline news is that you're seeing in other companies that are being targeted, especially in the UK. The reality is that they were done because of who the company was more than anything else. I think in terms of specific challenges, you've said it already.
The challenge is scale and complexity of the environments that we operate in. And how do you get a handle and an understanding of the level of digital footprint that companies like Bayer actually have? The second part to that actually is global operations also mean global regulations. So we have to do regulations at scale as well.
And we're seeing a very increasing number of national or regional cybersecurity regulations. So I think for us, that's definitely a factor we can talk about in terms of how we're delivering that global regulation in the right way. And I think also for companies like ours, some of your listeners may be coming from, say, digitally native organizations or cloud native organizations. Others might well come from more traditional organizations.
And I think companies like ours that have a very long history in the digital space are operating mixed environments too, right? We have super modern agentic AI platforms that we're building out, more traditional applications, OT environments. And how you manage the security operations across all of those that deliver at scale, I think is good. And to be honest, the way we handle that is through strong standards in the way we operate.
We have to build clear accountabilities and well-defined workflows for our security operations. And buyer over the last two years, we've actually moved to a platform-based model for delivery of our security. So it's not projects, it's not different operations every time. We're fundamentally delivering full stack platforms.
And I think that really helps us build those workflows and engage them out in a risk-based approach. Generally, I find that works exceptionally well with the stakeholders. The clear advantage for companies like ours is to be honest, we're reasonably well resourced. I mean, we have fantastic and talented people that we can bring into the companies to help us deliver forward-thinking security platforms and security programs and manage that and make the changes we want.
And it's fantastic to be able to walk in and just randomly jump into a meeting somewhere and a workshop that's going on. And you're talking about how to protect AI, for example, or moving a technology platform from one to another. And the people we have really make organizations like this. And it's a privilege to work with people day in, day out.
And the final piece, I think that's an advantage for us, evolution and change is constant. And the platform-based model allows us to have the stability, but still deliver constant change and constant improvement in those platforms to adapt to whatever's going on in the business. And we weren't talking about businesses rolling out agentic AI two years ago. We were still talking a lot about cloud and full DevOps and DevSecOps.
And now we're suddenly pivoting. So the scale that we have is the challenge, but actually the advantage we have is our ability to move to adapt to those challenges and those scales. Yeah. Yeah, it makes a lot of sense that the pros and cons.
And I just love that point you have on being able to walk into rich discussions on kind of fascinating security and technology challenges, the joy of a team who are well trained, you've got great ideas, you know, at your disposal. And one of the things that's always impressed me in our discussions is your ability to take large numbers of initiatives and kind of compress them in a way that a board and business leaders can understand the kind of focus at the level of two or three things, as opposed to 20 technology projects and a kind of vast roadmap quarter by quarter, which at some point someone might want to see, of course.
Any quick pro tips for folks listening who maybe aren't as gifted at that, that you'd suggest in trying to communicate the myriad of stuff that's always going on in security teams. Even a small cybersecurity team usually has 15 things, not two. How do you simplify it? I mean, for us, this is something we've worked very, very hard on.
And there's two challenges here. Number one is the number of changes and technical changes that you've spoken about. The second challenge to this is cybersecurity and generally IT can be seen a long way from the business in air quotes. And I keep saying, if we're not the business, who is?
We're here to enable the business digital operations. So they're part of us. So when you start to overcome them, you can really break down and say, what is the value proposition of security? Why are we all here doing our jobs day in, day out?
And and yes, it's to defend the business, but actually we broke it down and we said everything we do should underpin on three things. Number one, license to operate. And recently we we're not just talking about are we compliant to this or that regulation? Where are we?
It's like you can flip this into outcome thinking. So our license to operate is all about enabling market access. And I know it's a subtle change in the language we're using, but concretely, if it was a UK example, we don't just say cyber essentials or ISO 27,000 certification tick, we're compliant. We say we can deliver our business services to the National Health Service, or we can deliver our business services into other areas.
That's an enabler that security gives us. So it's number one, license to operate. Number two is customer trust. And in organizations like ours and anywhere else, we have to add to the company's mission to deliver with trust to our customers and our stakeholders and our engagement.
So all of our teams can pin what we do in security somehow to that outcome of that mission. And then the third one is company resilience. Sometimes, if you listen to Gartner, it's called anti-frigidity because they like a term that's very Gartner-esque. We basically refer to it as resilience and cyber resilience.
And part of that is how do we reduce blast radiuses? How are we resilient to cyber incidents, but not only from a technical point of view and a business one? And I think if you really break it down to those three things license to operate, customer trust, and company resilience, at the end of the year, I can look back and say we did a good job. Well, let me pick up on that and maybe even arguably a tension that you get in some organizations between the second and the third, between trust and resilience.
Sometimes they're complementary, but in a company like yours and an Airbus beforehand, you've got these hugely complicated, really sensitive systems. And if they go down, not if they get a data breach, you've talked very passionately about protecting customer data, but if they go down, you could have serious real-world consequences in food production, healthcare, pharma, and so forth. And I'm just wondering in that whole, you've worked, and thank you very much for doing this, you've worked with the NCSC community of interest on industrial control systems, and you'll be familiar with all the industry totems like my threat model is not your threat model, and if you're protecting everything, you're protecting nothing, and so forth.
So let me ask you one specific, sort of provocative thing, and I'm madly obsessed at at the minute. You know, if you look at your risk profile and all the things you have to worry about, and you think, well, I've got all these data protection laws, but actually, some of the systems you have to protect, the implications of those going down are way more important. So how on earth do you prioritize? Yeah, I think the reality is we take a risk based approach to everything that we're doing here.
And for us, that consideration that not all systems are equal from the outset, and that allows you to really prioritize what You're doing and even to things like vulnerability patching. The second part of that is around threat modeling and threat intelligence. Uh, large organizations are able to leverage those types of skills and capability. I'll say it's also very dependent on the maturity of the organization as to how valuable threat modeling and threat intelligence is.
Threat intelligence has to be timely and actionable and uh have situational awareness and context and maybe even a confidence value to it. So for us, that's really good and helps us to prioritize and understand the offensive attacker landscape coming back at us as well. The third part to it really would be about data-driven decisions wherever possible. And this is something we're actively working on to give us tooling to drive visibility of our environments and our digital landscapes.
It's always worrying as a CISO, uh, I don't know what I don't know, and I can't protect what I can't see. So for us, those aspects about leveraging automation and potentially in future also leveraging AI to help us drive those data approaches and where we want to go. And one may be slightly controversial, but I always like to think about in our platforms, we talk about capabilities that we deliver. I have to admit, as an industry, we're not very good at consolidating the capabilities or interconnecting the capabilities.
All of the vendors like to have their own dashboards. All of the vendors like to sort of say, hey, I specialize in this area and that area. And we're seeing an industry trend around consolidation of tools, for example. I'm working to this concept, and I've stolen the idea with pride from data scientists who talk about data fabrics.
I think we should be working towards a security fabric. Every element of the capabilities is interwoven into each other. And that's a design principle. It means if you're sitting in identity platform or you're sitting in the SOC or even connectivity security, you should be thinking in the mindset of how does somebody else in security use my logs, my data?
Can I have an API, or if we're talking about AI managentec, can I develop an MCP or an A2A that allows these security systems to work together automatically? Because that's the only way that we're going to have an ability to defend and do things appropriately in this environment. The other one I would say is culture is key. So the strategy around organizational culture is also really, really important.
Kevin, it's just fascinating. And we've had quite a few guests on this podcast talking about the differences in industrial control and OT space. And one of the quotes I love from earlier in the season was this we think that many of those environments and their reliance on segregation have ended up kind of 15 to 20 years behind the mainstream computing environment. You know, to the principles you're describing, it's just fascinating to think about how one drags some of those kicking and screaming up to the standards that we hold the rest of our IT environment, particularly in an organization like yours, where there's just such motive for attackers in your threat model that would have seemed kind of ludicrous to think about, kind of 20 years ago.
But I'm I'm going to stop us from detouring further into that. You'll have to come back and talk about it more because that will turn into a whole podcast episode. And I want to get to the main item for today AI security strategy. So opening thoughts, Kevin.
Where do you think AI has got to in terms of your industry, or I suppose industries given the scale of the organization? Where's it going? And what does all of that mean for security, do you think? Yeah, I mean, the obvious thing to say here is this is rapidly evolving.
What I knew last week about AI and what was being implemented and the tools that were available is going to be not true by next week. And I think that rapid pace of change is definitely driving forward a lot of great innovation and a lot of business direction. The other thing is I think every business in the world is really looking for this as a transformative technology to adopt in the business sense. One thing I do want to pull out though is for me and for us in Bayer, the consideration is that this has to be a business-led and IT or digitally enabled initiative, not driven by IT and technology first.
You need the use cases that make sense. You need to really rapidly think about where our AI adds the most value. And in that sense, whatever you do as a company, data is clearly the new gold or the new oil. It's going to underpin all of the systems that are going to leverage AI.
It's data and security, really, are some of the enablers for that. So we're trying to think about how to really design and build the right ecosystem around AI. And a term I keep using is is this use case AI ready? And I think most people would do very well not to think about AI can do this.
Think about your environment, your ecosystem, systems thinking. And then you'll find some really good use cases for that. AI is also not fire and forget, right? I don't just deploy a tool and it's AI, and then I don't have to think about security.
Those things have to be there. What I will say is certainly ALMs have been quite transformative. And again, we're talking about different types of AI. I mean, AI has been around for a very long time, actually, in a lot of industries, including ours, for data analytics, neural networks, k-means.
We've been using those to analyze data for a long period of time. That's not new. What is fundamentally changing here is this move towards LLMs and actually the next step into a gentic AI that allows this interaction and interface with AI technologies and systems. So that's where I think it's going to be truly transformative for businesses if we get it right.
The drive and evolution and the investments that are going into this, especially in the hyperscalers and other companies, I think will A, transform business, but will also transform the consumer space of technology. And I think the final consideration that probably the focus on is an awful lot about, I don't like the term, but human capital. How do you make people more efficient by using AI? Whether that's a bots or whether even some industries are looking at sort of the AI worker assistant type of thing that goes with that as well.
For me, the conversation is actually more about human intelligence. Kieran said I'm not controversial and I'm not going to be here, but actually the intelligence part for me of AI is the bit that still needs work. They're definitely artificial. That's a quote.
So they're exceptionally good at mimicking humans and finding data. And if the prompt part of it, I think, is underutilized. And to get the best out of AI at the moment, certainly LLMs, it's all about how good you are at crafting prompts. And the data sets that it's trawling over.
So I think there's a discussion here for companies, not only about how to make people more efficient, but how do we leverage human intelligence in this AI world? For me, those are the things that are in the back of my mind that are driving the security strategy that goes with it. It's just fascinating. I admit confirmation bias to much of that view as well.
I've you know tended to find myself over the past 12 months saying things like, if everyone has AI, and you could take that as everyone across every industry, or you could take that as attackers and defenders, or it can work to multiple levels. If everyone has AI, the edge once again is human. And to your point on the kind of very artificial and some of these technologies, I think the biggest leap for me is not particularly in the math or the kind of impressive scale of parameter-based auto-complete.
It is how friendly and accessible much of this seems and how therefore tempting it is to use to get to a first order answer. And what is really interesting is you see some people engaging with it and going, oh, it's done the work for me. And then when you inspect it closer, in many cases, it hasn't particularly done it well or better. There are some use cases where Franklin is just trampling the need for humans and automation is eradicating use.
There's this some of that. The better examples are where you get to this rich prompting and you get to second or third order kind of solution and thinking. So this human creativity and pushing and using it, I think is really important. But the ease of use and temptation of AI, the, oh, you're so brilliant for asking that question, I think is pushing a lot of people into the kind of lazy lesser use case versus better.
So it's really fascinating having an AI industry that's trying to drive this feeling of I can do everything for you, combined with a reality, Kevin, that you and I are articulating, that used aggressively with a lot of thinking, it makes humans better. But we're almost at odds with a lot of what the AI companies are trying to do in that statement, aren't we? I mean, this is where it's going to be fascinating around the business case for companies. And what is the business case is very difficult to make when you're talking about enhancing human intelligence with props.
And I think that's something we need to be better at as an industry, is looking at that and saying, okay, how do we get the right skills that we need to enable these aspects of AI? Where does it add efficiency? And even, as you said, next order of operations for people in that role, but still gives breadth for this enhanced human intelligence that'll go with it. I will caveat all of that and say that is entirely based on AI and LLMs as it is today.
And I revert back to my opening statement that everything I know this week may not be true next week. So somebody may develop something that is truly intelligent, context-aware. And again, the ecosystem around it. Today it's all about data, data analytics, and predicting from the data, they're really good predictive engines.
If I had a context-aware system, which again is not new as a concept, it was around 25 years ago, then suddenly you're starting to talk about something completely different in this world of AI. We're just not there today. So can I tempt you on this caveat to maybe go a bit further and revoke the whole there are no stupid questions attitude in cybersecurity ever telling me, Kieran, that was a really stupid question. But Oh, this is gonna be good.
Watch out, Kevin. You've made sure on the LLM side, and that's where all the use cases are and so on. But you've worked, you currently work for and previously worked for, you know, hugely complicated physical production companies making all sorts of stuff. So could you say a little bit, just even if it's very early days, in terms of the thinking about how AI and AI security is actually applying to the physical world, rather than just the sort of things that we've been talking about in terms of code, in terms of you know, generation of advice, services, and all of that, because I just haven't heard that much about it yet and thought maybe if anyone I know is likely to have thought about it, it might well have been you.
So I think it it's still early days. It's kind of embryonic in that world. I mean, you're producing things and elements. And again, it depends on the maturity.
Some production lines are still very annual, actually, and others are fully automated, and depending on the level of production that you have in the industry you're working in, and even the type of aspects that you have. And that there's a couple of constraints I'll put on this, because the first one is some production industries obviously are safety critical. Even the products that you make are safety critical. So you need to have absolute certainty in decision making, tolerances, quality.
And if you're going to bring AI into those environments, you can do it. That said, I don't think there is this split anymore between OT and IT. The worlds have been colliding for a decade already. That's really interesting.
And some of the companies out there are already having digital twins of the production environment or digital twins of the product. Yeah. And if you think about it, these systems are data driven. And if you have enabled MES environments that are running, helping you to make decisions, the bit of development in AI is actually this link to human interaction, right?
And that's what we're seeing. And I I've seen in expos and shows digital and OT environments with wearable glasses and wearable tech and smart authentication devices, even that lets you say, This is who I am, and then you get a customized screen on the production line. These are not fantasy things, they're coming. And again, it it helps drive better production, better production costs, better safety and security standards if you have a good safety and security culture to go with it.
So a TBD would be the answer. Yeah. But the walls are colliding quickly, quicker than I think people realize. Well, it's better than tell me it was a really stupid question.
So thank you. Well, I'm going to follow on with maybe my own stupid question, but I feel I've got to ask it because we've just talked about how elastic all of this is and all the ifs and buts. And well, this might happen. So I'm just going to ask you to solve world peace and the complete future of AI for all organizations out there.
But Kevin, I just being pragmatic at the moment. Organizations are obviously struggling with this. They are obviously concerned about the impact that it's going to have from a security perspective. People are worried about their jobs.
But, you know, most folks are kind of getting on and deploying and then kind of thinking about security a little bit later in most instances. Not a new pattern in our industry for most organizations, shall we say? So, how should our listeners be thinking about AI security and strategy and policy for the here and now? You know, what advice would you quickly give them to focus on for the next 12 months with the caveat of AGI suddenly turning up being out of scope here?
In bio, we we're looking at this from really four pillars. So the first one is really AI against AI. It's attackers already have AI today. And in fact, they're using it quite effectively against different organizations.
And we're seeing a big evolution in that domain that means we're having to already adapt our security defenses in certain areas. The first one I would say in there is deep fake technology is being used widely by attackers, replicating voice, using phone calls to people, especially more in fraud than in security cases. And this is where some of the psychology that we were talking about earlier really helps. Because traditionally you teach the technology of a cyber attack, not the psychology of a cyber attack.
And we've moved our systems to say, does the CEO or the CFO or the CISO, do they normally call you under time pressure, ask you to break process? So really by teaching the psychology of an attack, it almost limits the need for us to keep retraining constantly every time there's a technology change in these attacks. And quite frankly, if you're still teaching about spelling mistakes or dodgy URLs, these things are all automatically generated with AI. Attackers have learned to spell in many different languages in parallel within like minutes.
So that for me is one of the things we're defending against right now. And the second one we're looking at actually is around vulnerability management. One of the things AI is very good at is reverse engineering, writing code, not necessarily good code, but it's effective to do what the attackers need. So, what does the future of vulnerability management look like if you don't have a day, 24 hours?
The attackers can take a vulnerability, exploit it, scale it, deploy it within hours. And we're already seeing that. And by the way, I had this debate about open source software, and historically everyone was like, hey, open source software is more secure because it's got the many, many eyes looking at the code and fixing it and patching it and the bugs would have been found. I said, yes, that's true.
But can they keep up with AI either finding those really tricky vulnerabilities in open source code and libraries that nobody found? Or even worse, are you dealing with a bot that's updating open source libraries and embedding super complex, obfuscated backdoors in there that you're never going to find? So that's AI against us. The second pillar for us is really Bayer plus AI.
So all companies are leveraging AI third parties. There's a lot of AI tools and technologies around there. So this is really about us making sure we're doing the right awareness, promoting safe use, encouraging people to understand the limitations and the risks of AI. Governance is super important in here.
I would encourage all organizations to have at least a governance council for the use of AI within your business. Not only security, but ethics, compliance, all of those types of aspects that go with it. Well, do you mind if I just button there quickly? Because you've said everybody should have a governance council.
What do you think, if anything, organizations like yours should be compelled to do? And given that you work in 80 countries, I'm going to use the plural. Where are governments in all of this? And where do you want them to get out of the way and where do you want them to play usefully?
Because I think on the government side, there's a lot of regulation already out there, and there's a lot of standards already out there as well. Governments should leverage the existing standards, ISO 27,000, NIST, the technical standards, and then kind of harmonize what is best practice for the industry. There's a lot of competing governance in those aspects. So certainly we are asked to show what we're doing in AI around having a council, how are decisions taken, where are things implemented, and that's part of our strategy.
And then also we're asked to, and this is kind of the third pillar, we're asked by governments actually to show how we're defending and protecting our own AI models, whether that's the agent orchestration layer and identity, we're going to see big changes in identity lifecycle management. We're going to see MCP and A2A type of security controls, DevSecOps for AI, all of that's in there. And then how do we use AI to defend ourselves is is also the fourth pillar. But governments will not and cannot keep pace with those evolutionary changes that we're seeing.
So the best thing they can do is around how do companies standardize and harmonize on the control plane? How do we continue to have best practice? Because otherwise we'd be getting new regulations every other week around AI. Got it.
Okay. Well, look, I think to try to summarize, I was wondering, would I be scared or reassured? And I think probably both, but in the correct order. You know, there's a lot going on.
But I think you've brought it to a really pragmatic, practical, scare assured, strategic. You get the strategy right, get the capabilities right, that framework for government. We can manage us. The one thing I certainly wasn't was bored.
And certainly you've got a huge challenge in the years ahead. So thank you for sharing it with us. And we need you to succeed because if you go down, then I think we're in quite a lot of trouble. So we're wishing you well.
But we would let you go, except we can't, because we've got James's favorite bit of the podcast to do. Ah, my favorite bit, Kieran. The 30-second takeaway. I love a 30-second takeaway.
Kevin, look, ultimately, this podcast is about lessons for cybersecurity leaders. You've shared a lot of ideas with them already on where they can apply their focus, how they could think about these models, how they can communicate to their kind of fellow business partners. But if you had just 30 seconds with a cybersecurity leader to help them think about the next couple of years, the decisions they're going to make, something to pay attention to, something to ignore, whatever you like, how would you spend that 30 seconds?
What would you advise them on? For me, the attitude that a security leader needs, and in fact, all of our organizations. Number one, perpetual learner. The industry's moving so fast, technology is moving so fast, we're all learning.
And it doesn't matter whether your early career is in this or you're the CISO of a global tens of billions company, you must be a perpetual learner to be able to survive in this industry. The second one is very much linked to that. Get comfortable with change. Change is the only thing that's constant.
For me, that's definitely true. And my third one, which is kind of my personal advice to people, in a world where our job is constantly a world that's on fire, sometimes it's good just to take a step back and give things some perspective because you can very easily end up in the weeds. And there's always something happening and something going on. And trust the people you've got.
It's a fantastic industry, talented people in the business, but also there's great networks out there, like Sands. And I'll give you the last plug there as well. Join communities like this. Well, that is very kind, and thank you.
And a great set of takeaways, including actually taking time to think. Absolutely love it. So thank you so much, Kevin. We've really enjoyed having you on.
We'll have to get you back on the other 26 issues that we identified in the first few minutes. But I guess, apart from other things James likes to talk about, I think that's probably it. What else do we have to do, James? Well, you know, feedback.
Oh yes. Yes, go on, Kieran. Do your thing. Yes, I'll read it out at that advertising speed.
You can email us at cyberleaderspodcast at sans.org or leave feedback at the podcast site. Tell us what you'd like to hear more of, less of, anything you like. Well, within reason.
It should be slightly related, I suppose. But hey, look, jokes aside, and and my moderate flippancy in Kieran's ability to deliver the advertorial section on feedback, we do read it all, and we're always focused on what we can do with security leaders to help you, as security leaders, make life harder for cybercriminals. So if you do have an idea, we'd actually really love to hear about it. Suggested guest topic, thing that's keeping you up at night.
But anyway, with that, thank you for listening. Thank you for listening and keep cybering. So from me, Karen Martin, and me, James Lyne, it's goodbye. And may the AI overlords be kind to us.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.