
Cyber Risk Management Podcast · 2026-06-30 · 48 min
Key moments - from our scoring
Substance score
50 / 100
Five dimensions, 20 points each
The Cloud Security Alliance, founded 17 years ago to establish cloud security standards before mass adoption, is now applying its proven model to artificial intelligence governance. Jim Reavis explains how CSA's grassroots, vendor-neutral approach - which brought together cybersecurity and cloud experts to create pre-adoption guidance - uniquely positions the organization to address AI trust and safety. Unlike cloud's measured pace, AI is advancing exponentially faster, with step-level improvements in model capabilities and viral agent adoption creating unprecedented opportunities and risks. For attackers, AI democratizes nation-state capabilities: automated vulnerability discovery, chaining exploits, and broadened attack surfaces now operate at machine speed. For defenders, AI offers transformative advantages through SOC automation, vulnerability prioritization using contextual intelligence, and what Reavis predicts will eventually shift advantage to the good guys due to computational resource disparities. The conversation covers MCP (Model Context Protocol) adoption accelerating from 5% to projected 80% of SaaS companies by 2027, the shift from web-based to agent-to-agent communication, and the critical need for deterministic harnesses, context development lifecycles, and shared responsibility models that mirror CSA's successful cloud framework. Reavis and hosts debate whether standards-development can keep pace with AI's velocity and how AI itself might help generate contextual best practices in real-time.
CSA is using the same vendor-neutral, grassroots approach that made it successful with cloud standards - bringing together cybersecurity experts and AI practitioners to develop best practices and controls frameworks before AI adoption reaches critical mass, rather than waiting for traditional standards bodies that take 5-15 years.
AI enables attackers to automate vulnerability discovery, chain multiple exploits together, and scale attacks that previously required nation-state resources. This dramatically broadens who attackers can target and how quickly they can act, as the economics of attacks become much more favorable.
AI helps defenders solve their asymmetric data problem by using SOC agents to correlate disparate signals - for example, matching vulnerability scans with business intelligence (like Zoom calls discussing new system deployments) to prioritize what's actually critical, multiplying defensive capacity.
MCP (Model Context Protocol) enables loosely coupled, service-oriented integrations between AI agents and systems without hard-coding interfaces, making it dramatically faster and cheaper for SaaS companies to integrate AI capabilities at scale.
As AI capabilities improve, a growing proportion of incidents will stem from model misalignment, hallucinations, or unintended consequences (like coding agents deleting source trees) rather than from adversaries - similar to how Gartner estimated 99% of cloud failures were user error, not provider failure.
Our reviewer’s read on each dimension, with quotes from the episode.
A handful of genuinely interesting ideas surface - the 'two exponentials' framing, the defender-advantage-through-compute argument, and the shift from SDLC to 'context development lifecycle' - but they are buried under extended tangents about Claude Opus versions dropping mid-recording, doctor's appointments, and TikTok videos, plus the usual 'AI is transforming everything' platitudes. Novel-insight-per-minute rate is low.
we're, we're really seeing those step level changes in model capabilities right now. And then the second exponential is viral adoption of agents
proportionately the number of incidents...is going to decrease in the number that come from malicious actors...and it's a lot more is going to be the AI just like uh, because of alignment issues or whatever else
The cloud-vs-AI distinction ('cloud is about putting compute wherever, AI is about putting creation wherever') and the compute/energy defender-advantage thesis are moderately fresh angles, but most of the content recycles standard 2024-era AI-and-cybersecurity talking points without a genuinely contrarian or first-principles challenge to conventional wisdom.
the cloud was about like putting compute wherever you wanted to put it, but AI is about putting creation wherever you want to do it. And that's like a, a, a bigger word in, in a lot of religions
instead of our Software development lifecycle. We have a context development lifecycle
Jim Reavis is a legitimate practitioner who founded CSA, bootstrapped it with real early-company money, and has spent 17 years operationalizing cloud security standards; he speaks from genuine organizational experience rather than thought-leadership positioning. His caliber is real but his domain is standards-making rather than operating a large enterprise security function at scale.
Jay Chaudhry at Zscaler and Philippe Corto, Rest in Peace, uh, Qualis and then Phil Dunkelberger at PGP. They each gave me $5,000 to like go build a website and do a couple different things
I personally I've got about six agents that I've coded up that I use like every day
There are useful concrete anchors - 247 controls in the AI controls matrix, 17 CCM domains, $5,000 founding checks from named individuals, Gartner's 5%-to-80% MCP server stat, one-third token savings for markdown vs. PDF - but hard outcome data (adoption numbers, breach rate changes, cost savings from STAR certifications) is entirely absent, and many claims remain at the level of plausible assertion.
we looked at the 17 domains of the cloud controls matrix and then we added a model domain...it's got I think about 247 controls
Jay Chaudhry at Zscaler and Philippe Corto, Rest in Peace, uh, Qualis and then Phil Dunkelberger at PGP. They each gave me $5,000
The hosts occasionally ask structurally sound questions (the neutral-nonprofit rationale question from Jake is the strongest example) and drive through a reasonable agenda, but they never push back on a claim, allow long filler tangents about AI model releases, and Kip uses airtime to promote his own book and AirMap framework rather than deepening the guest's thinking.
what was the goal of being a neutral nonprofit group? You know, what do you think we would be missing if the standards only came from either vendors or only from regulators
I'm like what is all this? AI speak is just uh, mind spinning sometimes. And I get, I get mad at my uh, Opus 4.7
Computed from the transcript - who did the talking, and the words that came up most.
Would you know if the AI tools your team is buying are actually trustworthy to use? Who gets to decide what trustworthy AI even means? Let's find out with our guest Jim Reavis, CEO of the Cloud Security Alliance, the group that helped the world learn to trust the cloud and is now building the standards for trusting AI. Jim explains how AI is changing what attackers, defenders, and governments can do, and walks through the tools his team built so you can adopt AI without guessing. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates. Cloud Security Alliance:
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to the Cyber Risk Management Podcast. Our, um, mission is to help executives thrive as cyber risk managers. Your hosts are Kip Boyle, virtual Chief Information Security Officer at ah, Cyber Risk Opportunities, and Jake Bernstein, partner, uh, at uh, the law firm, um, of K and l gates. Visit them m@crmap.com and klgates.com
Speaker B: so, Kip, what are we going to talk about Today in episode 213 of the Cyber Risk Management Podcast?
Speaker C: You know, there's this one group helping the whole cybersecurity field get ready for generative AI. And you know, we have to take a look at what that group's doing because they're actually making a lot of investments to help us turn the corner, uh, to figure out how to deal with this. Right. And so today what I want to do is I want to talk about how that group is helping us change the game for attackers and defenders and governments, um, and how can we make AI trustworthy. Right. Um, our guest today is Jim Reavis. He's the CEO of the Cloud Security alliance and he spent years helping the industry agree on shared security standards for cloud computing. And Jim's got this really rare and valuable view about how A.I. is reshaping, uh, our very work and how the, uh, CISOs of the world are coming together and, uh, trying to help us navigate through this. So Jim, welcome to the podcast.
Speaker B: Yeah, and, uh, I mean, the CSA has been around for a while, so. Yeah, why don't you tell us, give us your story.
Speaker D: Yeah, so, uh, started it 17 years ago. Um, I got, was right out of kindergarten and so was looking for something to do. Uh, so it was actually about 18, 19 years ago when I first was seeing cloud emerge. And I had a background of like, building security communities and participating in things like Issa and other groups. And you could just see that, uh, this idea of compute becoming a utility made a lot of sense. There was like, the Electrical Electrification of America was like one very famous article in the Harvard Business Review and said, yeah, I'm in. And so if, if I'm thinking about what are the future problems I could start working on to solve it was that cloud computing needed to pass muster with security teams and audit groups and things like that. So, so let's think about like, building the best practices before people are really adopting it at scale. And so it's there when they, they need it and when they see the business rationale for doing it. But it was something that just made so much business sense, but yet there wasn't a lot of understanding about like how to secure it. And so that was the idea. Let's just go do it. And, and it just sort uh, of was a grassroots effort and it just caught on. It was like the right time.
Speaker C: And that was the beginning of a huge transformative technological change. It was really still playing out.
Speaker B: It is.
Speaker D: I'm curious too.
Speaker B: Like, I know I'm immediately going off script, but does it, does it feel, does it feel like we're back there again with AI?
Speaker D: I think that it definitely has a lot of the characteristics of like a new major paradigm shift. And so you have a lot of the examples of, oh, we're not going to use it. Oh yes, we are going to use it. Oh, it's getting adopted virally inside of organizations, you know, shadow, it becomes shadow AI and you have like every pig feeding at the trough for every sort of different business opportunity, including like what we do. And so there are those echoes at the same time. This is moving much faster and the, the predictive nature of the technology is, is very different. And the, the cloud was about like putting compute wherever you wanted to put it, but AI is about putting creation wherever you want to do it. And that's like a, a, a bigger word in, in a lot of religions, like the Creator is God. And so that's, it's, it's, it's much more profound, it's much more transformational and it's happening very quickly. And so we're, we're trying to use that. And there are some like, really good sorts of things we can think about in terms of, uh, supply chains and, and third party risk and, and shared responsibility. Uh, but there's also a lot of like, new things in a predictive technology doesn't behave the way that you would expect. Like, like traditional deterministic technologies. So, so yeah, it's, it's definitely different.
Speaker C: What a segue for me to mention that I'm writing a new book. Exactly. About that.
Speaker B: Kip, I was just going to say a wise man once said that gears don't guess.
Speaker C: Uh, okay, well, you said the title. Thank you.
Speaker B: Yes, you're welcome.
Speaker C: Okay, so, uh, Jim, before we start talking about artificial intelligence and what makes it trustworthy, just, I want to just explore a little bit more about this, the history of csa, because I think it's going to help the audience understand, you know, why the CSA is well positioned to do this. Right. I think some people who may not know about the organization might say, well, Cloud Security alliance, what do you guys know about AI? But, um, but I think if you could just, just tell us, like, um, like the Earl. Like, start with the early days, like, who, who showed up and like, what did you build? And then how did that create a platform for CSA to go a little bit wider on the standards work?
Speaker D: Yeah, so we had observed that when this new technology was coming that you're going to have like, incumbents that are going to fight it. Um, you could see it was going to move pretty quickly. And the standards bodies, traditional standards development organizations, hey, it's five years, 10 years, 15 years between an update on a different standards. He could see that wasn't really going to work. And, uh, because it was new, it was like, well, there's really no barriers. You just get a good group of experts, which ended up just being a mix of cybersecurity people who are curious about cloud and cloud people who were curious about security. It was really that sort of simple that you had that just sort of intersection and, you know, social. Social media was just starting to like, really take hold and called crowdsourcing back then. It's like, hey, instead of like doing something super formal, let's get grassroots, like activities. Let's have people crowdsource, like different ideas on how to do this. And several just different, like, smart people just said, yeah, this is. We're starting to see the same thing, so we'd love to help sort of like develop these sorts of things. And, and it was, it was just great because no one had an agenda really, other than wanting to like, do the right thing. And came from just all different walks of life. And I tried to make it very like, international in terms of the participation and just all different sorts of roles and responsibilities, big companies, small companies. Because, like, even, even back then we kind of knew, hey, there's that one person that like, has a, a point of view, like a hacker, like, go back to Captain Crunch and, you know, you go back to those guys that like. And an individual that can make a big change. So I knew, hey, let's just be, let's be inclusive. This is not about big companies or anyone else like, doing this.
Speaker C: Um, and, uh, and then I remember distinctly you talk about making it more international. I remember like years and years ago I was chatting with you and you're like, well, I gotta go. I'm on my way to Crete for a meeting. I'm just like, yep, that's about as international, as distributed as I can imagine.
Speaker D: Well, that's, that's where, uh, ANISA was based. I think they still have a few people there, but. And I don't asked me to explain how they set up different agencies in, in Europe, but it's a beautiful place to be. But yeah, that was one of our early, early partners and still is like a pretty strong partner. But yeah, we just like we, we launched it at, in 2009 at uh, the RSA conference. But what we did differently because there was a lot of people thinking about this is let's not just do a press release and say, hey, let's come together. It's like, no, we kind of worked in stealth and we created like the full guidance. And so then that kind of just was the fade accompli. And everybody said, oh, we don't need to compete against that. They announced it and they, they got the guidance and like it just was pretty viral and it's a dog.
Speaker C: So you bought, you borrowed a little Silicon Valley playbook there, didn't you?
Speaker D: Yeah, yeah, this was, you know, absolutely. So, so, uh, um, and it was actually like some startups like Zscaler was, uh, they, they weren't even called Zscaler when they started that. They were when they were a puppy.
Speaker C: They were.
Speaker D: Yeah. And, and so Zscaler it was, it was Jay Chaudhry at Zscaler and Philippe Corto, Rest in Peace, uh, Qualis and then Phil Dunkelberger at PGP. They each gave me $5,000 to like go build a website and do a couple different things. And there we go.
Speaker B: So just real quick question. I think we don't want to spend too much time on it, but just from the legal governance view, what was the goal of being a neutral nonprofit group? You know, what do you think we would be missing if the standards only came from either vendors or only from regulators? M. If you had a thought on that.
Speaker D: Yeah. So, well, vendors, probably the easy one, like they're, they participate uh, a lot in standards bodies to like make sure that there's a favorable outcome for their products and technology. And, and you. So you got it. There's a lot of extra work you got to do on governance and then like regulators and I'll, I'll throw out a name. I think that uh, um, you probably both know about Jeffrey Ritter. He'd written about like systems law and that ah, regulators increasingly in technology were going to be pointing to industry best practices versus codifying things. And so that was like, yeah, we'll create stuff that they'll just use and point to. M. Interesting.
Speaker C: Perfect. Got it. Okay, so um, let's pivot now and talk about AI because um, as you Kind of said at the top of the show that this is not just another tool. I mean this is, this is a real change to what attackers can do, how fast they can do it. Same for defenders, right? Everything that AI could potentially do for an attacker. Defenders are able to use all of those things. Of course the governments are going to do what they feel that they need to do. But I want to look at each one of these in turn. So let's start with that, with the attackers. Right, so what are you seeing about how AI is changing their playbook?
Speaker D: Yeah, so it's important to sort of understand like where we are at with AI that we're living in this world of two exponentials which sort of impacts each of them. So, so we're, we're really seeing those step level changes in model capabilities right now. And it's happening like very, very quickly. And so they are just getting so much smarter. And then the second exponential is viral adoption of agents where this is now you're giving AI tools and access to do a lot of different things. And so from an attacker's perspective they uh, have nation state capabilities. Now I think that's kind of the conclusion out of um, Mythos. And so they can automate attacks, they can automate the discovery of vulnerabilities, they can chain vulnerabilities together. So um, now there's a lot of vulnerabilities that never get exploited and all those like, sorts of things. But the, the economics of this from um, an attacker's perspective is like quite stunning. And they can just accomplish a lot more, a lot more quickly. And so it, it like broadens their, their attack base and, and who they can go after. So I expect that to be like something we're just going to have to contend with certainly for quite a while.
Speaker C: And it's sort of like. Go ahead Jake.
Speaker B: I was horny where uh, it was a vendor telling us about their MCP server and how um, in 2025 roughly 5% of SaaS companies had MCP servers. Gartner is now estimating that by next year 2027, 80% of SaaS companies will have an MCP server enabled for their systems. Now the competitive pressures are immense and
Speaker D: all of that, but
Speaker B: really kind of combines cloud security with AI. Right. Because what an MCP is really doing is creating a massive interconnected web, um, data pipes and connections and it's, it's kind of, I, uh, mean when have we ever seen adoption go from 5% to 80% in two years? It's, it's Crazy.
Speaker D: Yeah. Ah, you can do things so quickly and you know, with, with agentic coding you can just, you can create MCP interfaces or any other interface that uh, when we go open claws, the fastest like growing open source project ever. So it is like super fast and it does have like a lot of those aspects of service oriented architecture loosely coupled where it's just, it's not hard. There's not a, like a big lift when we used to sort of hard code interfaces to different systems. So yeah, we're rapidly interconnecting things and there's a lot of things that we need to do to like, you know, harden these types of systems based on, you know.
Speaker B: It reminds me a little bit about, just like the stories about how, you know, how many emails get sent, you know, every second, you know, compared to how many emails were, you know, were sent in the, in the 70s and 80s when the technology was just being done. And it really took decades for those numbers to get to impressive levels. Right.
Speaker D: I mean,
Speaker B: and I think what we're seeing, the pace of change with AI is truly unlike anything technology is seeing. Even cloud moved at the stately pace of a couple decades.
Speaker C: Yeah, they look like hockey sticks, but this looks just like, I don't know, a line going straight up.
Speaker B: I don't. Yeah, I mean if you, I guess what I'm saying is if people thought cloud moved fast, it may have been a glacier compared to what AI is doing.
Speaker D: Oh yeah, absolutely. It's stunning how coding has changed in 12 months. And really the capabilities and the unlock in coding agents really was only like the GPT4 plus Opus 4.6 mat maybe. And so it's really recent, but it's just all different now.
Speaker B: Yeah. Do you know?
Speaker C: Yeah.
Speaker B: Opus Point was released to me.
Speaker D: I don't even have a chance to
Speaker C: notice it before I, I was just using it before we started recording. Actually I saw that it dropped and uh, I immediately started trying to figure out how uh, I could take advantage of it in my, in my current AI workflows. So uh, but then I had to make this a, uh, podcast episode.
Speaker B: No, I was, I was at lunch and the, the person I was having lunch with told me about it and I was like, I go to a doctor's appointment and I miss a major model release. Like, seriously, like, come on.
Speaker C: Yeah, right.
Speaker D: Um, that's the good thing. There'll be another one very soon.
Speaker C: Yeah.
Speaker D: You know, um, he told me, he,
Speaker B: he told me that there's this, there's this like comedy video TikTok going around right now that's like, you know, bro, you're still on uh, opus 4.6. That's like, that was like, you know, esto like three minutes ago. I was like, that's what it feels like.
Speaker C: It does feel like that. Um, and then I think another, another change that I'm anticipating. And Jim, I'm just interested to uh, to know if you've heard of this or considered it. I would think you had. But um, you know, with all these um, these agentic uh, solutions and particularly on endpoints, I mean we're not really going to use websites anymore, right? My, my agent's just going to query uh, you know, a place that sells stuff but I'm never really going to actually browse anything. I'm going to tell my agent what I want and then it's going to, you know, go and fetch the data and I'm just going to look at it in you know, my uh, however I've got my screen set up. I'll, I'll never see anybody else's Chrome again. Does that sound right?
Speaker D: Um, you. I'm not as absolute about that. But yeah, basically like it's going to be agent to agent in a lot of the communications, but also like person to agent. There'll be, you'll, you'll want to watch some streaming, you might want to do certain things. But yeah, it's it. That's kind of how we're thinking about it. Like, you know, we're, we're uh, famous for delivering research in PDFs and that doesn't seem like that makes sense much longer because people take research and they want to understand the context so they'll put it inside of Claude or ChatGPT. And a markdown file is much more efficient. It's like a third year token usage. And also like we want um. And we're like already sort of thinking about agents as being like customers of CSA and we want them to read the markdowns like directly. And so yeah, you're going to see ah, a lot of this and it's like that interest and what's that nexus between an agent being technology and a human like worker and how we think about them and operate with them. But yeah, it's absolutely going to be like very, very different. And you know there's. I personally I've got about six agents that I've coded up that I use like every day and like they've like relieved me from doing a lot of different sorts of things that I would manually
Speaker B: wants to go back
Speaker C: well, then you live in a bubble, my friend.
Speaker B: Well, sorry, I don't know anybody and there's a lot who would like. I don't know anybody who's actually made use of AI, who, who would willingly go back to pre AI, assuming that we still have to do the work that we're doing.
Speaker C: Well, it's interesting, right, because there's a lot of commencement speakers that are getting booed because they show up.
Speaker B: Uh, those kids don't know what they're booing.
Speaker C: It's, I don't know, they cheat. Like hell with those things. Don't tell me they don't know what it is. Well, anyway, I don't want to try, I'm not trying to open up that conversation. What I want to do is segue to the defenders, right? So where does I actually help people who, the blue teamers. Right, the people who get no respect and you know, nothing we do is sexy because all the pen testers get all the glory. But what do we get out of this, Jim? What are you seeing?
Speaker D: Well, the thing about this is that we have as defenders a, ah, huge data management problem. And it's the whole Dan Gear quote that attackers, uh, only find one way in. But defenders need to defend every vulnerability weakness that was ever. And AI is just like built to do that. So seeing agents start to do a lot of the SOC operations to be able to find the heat maps inside a very large vulnerability scan reports, uh, being able to pull together a lot of different things. Like just as an example, maybe there's a zoom call where people talk about a new system being deployed. And you correlate that and say, oh, this system that appears to have no customer data, it has some vulnerabilities, but it's not a priority. But that zoom call gives you the context to say, oh, next week it will have all that information and so that becomes a priority. So it gives us a lot of ability because, hey, what would you do if you had like, and let's not talk about token costs yet, but you had like 10 million junior engineers that you could put to work on things and.
Speaker C: Right.
Speaker D: So, and, and, and this is a little bit on the, the long term side. It appears as though like the model capability is most closely correlated with the amount of compute. And that compute has got a basis in energy and everything else. And it just seems as though the, that's where the hackers and the, the malicious actors are going to like, they'll run out of resources before the good guys. Because the reality is there's more good guys than bad guys in the world. And the fact that you can use more energy and use more tokens means that I think we're going to, I don't know how quickly uh, but we are going to see that shift to defender advantage on this, which is good for all of us. Now the AI itself is predictive and one of the things that I'm expecting is proportionately the number of incidents that, that the cybersecurity industry needs to deal with are it's going to decrease in the number that come from malicious actors that proportionately I'm talking about, uh, and it's a lot more is going to be the AI just like uh, because of alignment issues or whatever else, it's going to like not follow the right processes. And we've seen a lot of that. Like yeah, the coding agents like deleting source trees and things like that. So.
Speaker C: Right. I remember Gartner made a prediction and I don't know if they still stand by it, that like 99% of all cloud failures are going to do be due to user error or something like that. I mean that was their prediction for years and years. And it sort of sounds like a, ah, similar thing here where it's not really the model, it's how you harness it that really determines, you know, what kind of results you get and how reliable they are and consistent and so forth. So I think that's what you're saying, right?
Speaker D: Yeah, it's another sort of echo with cloud. When, when we started csa, a lot of companies just said well securing the cloud is, it's Amazon's problem, it's AWS's problem and all of us just ride for free on that. And when we started this it was like huge focus on, on OpenAI, anthropic DeepMind, uh, like what they were doing to make this more safe and secure. And what we're finding now is this sort of general intelligence that you're building with large language models. It just can be used for good and bad and like prompt injection or hallucinations which they've like gotten much better at. But how they operate, that's really kind of how it's designed a statistical model there. And so it's really going to be uh, we're getting that better understanding now that we need this. These harnesses like the runtime execution for agents that say, okay, we're going to have a deterministic way of blocking that and we're going to understand the context and context becomes like, you know, like instead of our Software development lifecycle. We have a context development lifecycle to understand what's in the markdown files that feed these things. So yeah, so that's kind of how like see it evolving and, and that's healthy that I think we're understanding that this, that's how the shared responsibility comes back in what we're doing.
Speaker B: Interesting. That's challenging about AI is, is precisely that it moves so fast that it almost doesn't feel like there's time to create security standards, best practices, anything like that before the whole, before the whole game changes again. I mean, you know what I mean? Like I'm ah, just like, you know you're saying like I totally understand what you're saying but at the same time I'm like we have time for that because it doesn't feel like it.
Speaker D: Yeah, we gotta operate at machine speed with like clear articulated goals for the AI systems. And this was actually something that uh, I was at an event recently and you know, I believe there's going to be trillions of agents and very diverse and like how do you have like very specific best practices for that? And then to me the obvious answer is AI develops those best practices and, and it makes decisions with humans in the loop to whatever degree of autonomy we sort of decide. You don't want to put give more autonomy than is warranted based on the situation. But uh, even you know, we pretty early on we saw people take like our AI controls matrix, other things and put that into a chat screen and have AI sort of create okay, what's the overarching framework we should use or what's a maturity approach to implementing these sorts of things. So I think you're going to find, just like you're seeing AI improving, AI now is kind of where they're at. You're going to see AI again with the right like alignment human in the loop. It's going to be creating a lot of the detailed implementation of practices, a lot of the decisions. It's going to have to be that way because it's got to be machines.
Speaker C: Uh, well I think speed is the new firewall. I think you've just you know, described one very important aspect of that. But I want to pivot now and I want to talk about the practicality of what CSA is doing here. Right, so you all are building tools, you're helping organization, uh, organizations use AI with their eyes wide open. I think our listeners would love to know what's CSA's plan for helping people to adopt AI. I know we could talk about that. For hours. But maybe you could just give us a thumbnail sketch.
Speaker D: Sure. So like how we are thinking like we need to reinvent ourselves is that it's certainly like one part is like continuing to do best practices sorts of research. Uh, another part is like helping the industry build tools and building open source tools and helping on the operational telemetry around the different risks, the different vulnerabilities. Like what's, what's happening out there. And like I was sort of mentioning, we're thinking about, thinking about agents sort of having human like capabilities. So like do, do agents need to have a security certification of their own? Not, not like an organizational certification but you know, think like a CISSP or things like that even.
Speaker B: Oh.
Speaker D: So we're, we're building uh, a lot of like here's more of the near term. Here's the playbooks that you need to be thinking about as you are becoming like you're a greater AI adopter, you're being attacked by AI. Here's, here's the playbooks that you need to have and here's the um, education that you need. But also here are some different tools that you can maybe avail yourselves of. Here's maybe some open source agents that you can go build. We call our mission out of our AI foundation, securing the agentic control plane now for the next 12 months. So that comes down to a lot of the harnesses we're talking about and the risk observatories and creating we want. And I see the biggest job title we're going to see, new job title showing up in cybersecurity is AI Builder. You're going to build stuff like you're going to, it's your toolbox and you're going to, you're going to build things to under better understand your environment and to better make decisions and to like better like create that like machine speed capability. So it is a lot of research, education and certification that we've always done but just a lot more operational tooling as well I think.
Speaker B: Yeah, um, agentic control plane is a phrase I've heard recently.
Speaker C: And I'm like what is all this? AI speak is just uh, mind spinning sometimes. And I get, I get mad at my uh, Opus 4.7. I'm sure 4.8 isn't going to be any better when it's just trying to constantly slip in all this AI jargon into our conversation and I'm just like, just stop. I'm tired of talking about surfaces. Can we just talk about, can we just use ordinary like real People, language. Come on man. Um, dm, tell us about STAR for AI. What's that? What problem is that solving?
Speaker D: Yeah, so our, our STAR program which has been around for like 14 years or so say, and a sort of a multi level certification program for uh, basically for the same reason that like we created CSA is you have ISO certifications, you have SOC twos, those tend to, don't tend to get changed very often. And so what we created with STAR was let's create an ability to like scope a certification towards cloud specifically and its shared responsibility. And so essentially we have taken that same approach to AI and even our cloud controls matrix, we extended that, we built on it with the AI controls matrix because a lot of, lot of most AI you could say, even if it's on the edge, it's either it's, it's delivered in a way that looks like cloud and how it spun up and data ops and everything else, or it actually is from the cloud like you're seeing with uh, the large frontier models. And so we felt like we could just extend it. And so STAR for AI is you can do a level one self assessment. You can do, you can get a level two where you get audited. And then the one thing we added that's new and different is we created an AI auditor called Validated. And so this your level one self assessment and it'll actually do a really good job of scoring it and analyzing your answers and really like making recommendation how you can improve it. And so we're actually seeing that sort of taking off. And uh, organizations that get certified, they'll look at that as it's, it's cheaper and it's a good preparation for doing the human like third party audit.
Speaker C: Yeah, that's really cool. I like how you said this at the beginning, but now here's a proof point right where you're actually saying what does CSA have to be now in order to move with the times? And you've actually built an agent, right, that's actually implementing new capabilities. Uh, and yeah, I want to acknowledge that that's great.
Speaker D: Yeah, I appreciate that. I mean I think grc, it's like pretty ripe for, for this like something we noticed around Opus 4.6 I think because we do a lot of mappings, crosswalks between different standards and best practices is it does not a perfect job, but it does really a pretty good job of like, like doing that sort of thing. And I tell a lot of enterprises like that's, that's really something you can, you can do to like save, save time, save money. And you want oversight on that. So yeah, it's definitely helping us.
Speaker B: What's Maestro? So Maestro Capital M, Capital A. It looks like an acronym.
Speaker D: Yeah, I think it is an acronym. But basically don't quiz me on that. Uh, it's threat modeling. And so threat, uh, modeling for agentic. It was like. And it's, it's pre open claw that are, uh, Ken Huang is the contributor who, it was his brainchild and I think it holds up pretty well. We'll have to look if we need to make some adjustments to it. But it does threat modeling where there's a lot of like there's been a lot of standards like Stride and others for doing threat modeling. This really accounts for that, that autonomy and that predictive nature of this technology and how like tool use happens, how you just, you're not going to get, you got to build, you got to build into your strategy that you are not going to get the same results every time when you go like test, do a security testing of AI types of technology. And so it tries to account for uh, a lot of that and it's real like useful way to go do that. And again what we're learning is with, from threat modeling now when we look at the capabilities of the models, everybody's got nation state capabilities. So that might be one area we need to kind of look at and think about in the tool itself.
Speaker C: Okay, now time being what it is, I want to, I could talk about that for a long time, but I want to, I want to talk about a couple of others before you know, we get to the end here. Cloud controls matrix. So probably a lot of people who are listening right now go, oh yeah, I know what that is. Well now there's AI controls matrix, so tell us what that covers. And like you know, how is that the same or different from cloud control matrix?
Speaker D: Yeah, so uh, we felt like, as I said that like it's, it's really very cloud, like how AI gets deployed and implemented. And ChatGPT went crazy because it was essentially a cloud service. And so we took the 17 domains of the cloud controls matrix and then we added a model domain. And then we looked at the controls which are control objectives. They're fairly high level and we made sure that they were worded appropriately for the AI environment. And so we looked at the targets of the models, the model providers, the sort of orchestration LangChain kind of level the cloud providers. And then even more specifically like the implementation guidance has been tuned for AI. So Essentially it's a superset. How you think of it, it's got I think about 247 controls, some more controls and it's um, it's something that like it's gotten a lot of a uh, lot of downloads, a lot of usage. It's really about operational control framework and it's very complementary to things like the EU AI act or the NIST risk management framework or even ISO 42001 that are higher level, more abstract. So this is intended to be a real operational framework.
Speaker C: Good luck pronouncing that acronym, Jake.
Speaker B: Yeah, Too much, Too much.
Speaker C: Um, yeah. How do you say that? A I, V, S S avis.
Speaker B: I would pronounce it AVIS if it were me. But it doesn't quite work because it's more like avis. Do my best.
Speaker D: Ah, ah.
Speaker C: So um, aivss, that's another thing that you all are working on, right?
Speaker D: Yeah, so that's through olas, but I actually was involved on that um, group. So it's really, you're familiar with you know, cvss. It's you know, the severity scoring for like more conventional vulnerabilities or DSS is kind of like provides more uh, contextual sort of overlay for the, the AI deployment. So kind of similar to how I was describing Maestro, but like when this vulnerability is inside an AI system with that, with the type of autonomy and multi agent, like you guys have maybe heard of like the confused deputy where you've got multiple agents and one agent doesn't have the rights and so it just asks another agent and it gets escalated privilege. So um, so it's to help us really understand vulnerabilities in AI, um, how we can score them and understand severity. Now I have to say we gotta take another look at this with Mythos, because what we've seen it can do is it can chain multiple low scoring vulnerabilities and create um, a high risk, a uh, vulnerability and an exploit that's going to, you know, have high impact. So we're going to have to take more um, looks at these but you know, it's good work.
Speaker C: Okay. And just to be clear, it's not CSA's work product.
Speaker D: No, this is M out of OASP, but yeah.
Speaker C: Okay. Out of OAS. Okay.
Speaker D: I was commenting on it, I was invited to go comment on it and so I know something about it. Yeah, we'll have to look at it.
Speaker C: Thank you for saying something about it because I was a little, I was uh, I was doing the research, I was a little Confused about you know, how much CSA was involved in that. So I appreciate you clarifying.
Speaker D: I would have chosen, I would have chosen a better acronym like our, our AI Education. Uh, Trusted AI Safety Expert. That's pronounced TASE because it's shockingly good. So you know, you better do better acronyms.
Speaker C: I mean that's kind of your, that's one of your like core superpowers. Right Is naming things.
Speaker D: That's my opinion of it. It's not universally but yes, I would agree with that.
Speaker B: So uh, let's wrap it up by having you give some practical advice. So if I am a security leader at a mid sized company and I know that AI is coming at me really fast, what should we do in the next 90 days?
Speaker D: Yeah so like small and medium SMB like you probably there's I'm going to assume ones that actually are sort of managing their security program. Uh if you're on the smaller side and you're probably needing to use an MSP and then like this might be more for your MSP to like go figure um a lot of this out. But we, we have to like let the business leadership know that because of all these changes one we, we're sort of reassessing what our risk profiles really look like and we, we need to all sort of do that. And so that kind of goes across from the very largest to smaller organizations is like we, we need to think about that. So like, but practical things are like use, use the LLMs to like sort of understand like security issues, explain security problems, do vulnerability discovery and, and can help with remediation. Use, use uh coding agents to if you are, if you do have like developer teams use it to go improve uh the security quality of them. Use it to build some agentic answers. Like the, the thing I talked about validated for our auditing. This is not like a huge lift for an SMB to go build some agent like tools um do, do tabletop exercises to prepare for like this what we're expecting this sort of vulnerability storm. But like the big thing is like focus on the basics. So the interesting thing is that AI I think is going to cause us because of all the technology changes it's going to cause us to go back to first principles. So make your environment sort of like hard to attack. And so that means like the segmentation needs to be like really good, the defense in depth like zero trust is like great like create all of these like proper boundaries that like going to raise the attackers cost. But, but, but no there is a security Poverty line. And like you, you also have to understand if you're an SMB, how much of this can I do on my own, um, versus like when do I need to bring in like the service providers? And then we got to really make sure they know what they're doing because we understand that's a very uneven industry. Because bottom line is you can't outwork these machine speed threats. So you've got to, you got to lean into this. And like I said, I think like AI Builder, that's going to be like the big security title in the next couple of years.
Speaker C: Yeah. Um, so we work with a lot of mid sized companies and they're not building AI, right, they're buying AI. And so, um, so one of the things that we've done is created a framework we call AirMap and it helps them do a couple of things. One is culturally get themselves ready for using AI because a lot of organizations just still don't even understand some of the fundamental aspects of it. Uh, and so as an organization they need to have a certain amount of readiness if they're going to govern it and bring it in. Um, and then we've got another dimension where if you've got a use case, a very specific thing that you're trying to get done, we can actually go into that use case and we can actually evaluate it using like 20 questions to find out, you know, well, what exactly is the risk here? And oh, by the way, uh, one of the risk items is you just spent a lot of money, you know, trying to figure out how to adopt this uh, AI, uh, you know, uh, technology. But are you even set up for success? What's the likelihood that this money's all going to be wasted because you just didn't even understand what, you know, what kind of inputs you needed and you know, and all the plumbing around the model so that it doesn't go off in squirrely directions. Right. So um, yeah, so I think CSA just kind of strikes me as, as an organization that's more oriented towards builders rather than buyers. But is that a fair assessment?
Speaker D: Um, I'd say that we are, I would say yes, because I think we, we, we look at large enterprises that have like the toughest problems because we want to solve those. And then we do spend a lot of time like tied into the organizations that are like trying to create the new solutions. But like I'll, I'll leave you with like I have a 39 year old computer science degree and like just the, the, the advancements in the Last few months have been a real unlock for me personally, and I think that this is. You're ultimately going to find this is very democratizing for, like, SMBs, and they'll. They'll be builders soon, I feel.
Speaker C: Um. Okay. Yeah. Okay. Well, I don't think most of them are right now, but that's a really good point. That doesn't mean they won't be at some point in the future. Okay, so as we wrap up, I just want to say, um, Jim, this is your opportunity. If listeners remember just one thing from this whole conversation we've had, what would you want them to remember?
Speaker D: So I think that cybersecurity professionals should aspire to be the most knowledgeable people about AI in their organization. Like, that's how we become strategic, and that's how we really help our organizations prosper. And, uh, I think, like, we. We've. We've gone way past, I think, being the department in the know and, and trying to reject things and being super conservative. But this is scary times. And I think that's how we can, like, help is be very curious, explore this stuff, go consume. There's a lot of great education that's out there, and I think if you do that, they're gonna. You're. You're going to make yourself more valuable for your career and you're going to just help your organization.
Speaker C: Yeah, I like that. Thank you. So that wraps up this episode of the Cyber Risk Management podcast. What did we do? Well, today we looked at how the Cloud Security alliance is helping the cybersecurity community get ready for generative AI. We heard how AI is changing things for attackers and defenders and governments. And we walked through some of the tools that CSA has built. Star for AI Maestro, the, uh, AI controls matrix. And we learned a little bit about AI vss, which is interesting, but not csa. There you go. We did all that with our guest, Jim Reavis, the CEO of, uh, Cloud Security Alliance. We'll see you all next time.
Speaker A: Thanks M for joining us today on the Cyber Risk Management podcast. If you need to overcome a cybersecurity hurdle that's keeping you from growing your business profitably, then please Visit us@cr-map.com. thanks for tuning in. See you next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.