The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Cyber Security Business
Cyber Security Business artwork

AI Compute as a Business Risk

Cyber Security Business · 2026-05-13 · 35 min

0:00--:--

Key moments - from our scoring

Substance score

50 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality10 / 20
Guest Caliber13 / 20
Specificity & Evidence9 / 20
Conversational Craft7 / 20

Cassandra Mack brings rare expertise running security for Tensorwave, a company operating the world's largest AMD GPU cluster. The conversation reveals why AI compute infrastructure is an overlooked attack surface and vendor risk challenge. Unlike traditional cloud hyperscalers, AI compute providers often operate from rehabilitated data centers with unique challenges around power reliability, cooling, and the inability to simply migrate workloads. Mack highlights that most companies adopting AI lack in-house CISOs - many are Series A or B startups relying on DevOps engineers for security decisions. She stresses that AI infrastructure requires evaluating hardware bill of materials, firmware integrity, encryption practices, and supplier chain verification in ways that AWS, Azure, and GCP haven't historically emphasized. Beyond infrastructure, Mack argues CISOs must move from a blocking posture to enabling AI agents and automation while building guardrails through education, human-in-the-loop practices, and risk management documentation. She notes emerging AI-native tools designed to coach employees on data handling and regulatory compliance (covering state AI privacy rules), and emphasizes that cyber attacks now have kinetic effects on physical infrastructure through OT and ICS systems.

Key takeaways

  • →AI compute infrastructure is fundamentally different from traditional data centers and hyperscalers, requiring expertise in power management, cooling, hardware provenance, and SLA guarantees that most companies lack.
  • →CISOs must shift from a defensive "Dr. No" posture to enabling AI safely by building guardrails, enforcing human-in-the-loop decision-making, and establishing vendor vetting criteria for AI compute providers.
  • →Vendor risk for AI infrastructure extends to hardware bill of materials verification, firmware integrity checks, and supply chain validation - areas most companies previously delegated implicitly to hyperscalers.
  • →Series A and B AI companies typically lack security leadership, forcing DevOps engineers to make security decisions; onboarding education from infrastructure providers is critical to establish baseline security stacks.
  • →CISOs must implement continuous threat modeling at the architecture stage, maintain threat intelligence feeds, and recognize that cyber attacks now have kinetic effects on physical infrastructure through OT/ICS systems.

In this episode

  1. 1Introduction to AI Compute Infrastructure Risk
  2. 2New CISO Responsibilities in AI Adoption
  3. 3Cost, Availability, and Sustainability Challenges
  4. 4Securing AI Compute as an Emerging Attack Surface
  5. 5Vendor Risk and Hardware Supply Chain Management
  6. 6Risk Ownership Across CISOs, CIOs, and Physical Security

Mentioned

tensorwaveCassandra MackKevin PushagAMDSlackJiraOpenAIAWSAzureNvidiaGCPNeo clouds

Guests

Cassandra Mack

Topics in this episode

Software Bill of Materials (SBOM)TensorwaveAMD GPU clustersHardware bill of materials (HBOM)Firmware integrity verificationSupply chain security for AI infrastructureGPU provider vettingHyperscaler dependency (AWS, Azure, GCP)Power and cooling infrastructure riskAI compute SLAs and uptime

Questions this episode answers

What makes AI compute infrastructure different from traditional data centers?

AI compute infrastructure cannot be easily relocated like traditional workloads - it requires careful tuning and testing across all layers; it also has far fewer redundancy options and introduces new dependencies around power availability and cost, cooling reliability, and hardware compatibility that traditional data centers didn't emphasize.

Why should CISOs care about hardware bill of materials and firmware in GPU clusters?

Enterprise customers now demand proof that hardware hasn't been tampered with and comes from legitimate supply chains; every batch of hardware and optics differs even from the same manufacturer, and CISOs must verify firmware integrity rather than trust hyperscaler or vendor assurances.

What are the main risks of using brokered or middleman GPU providers?

Many brokered GPU clusters operate from undisclosed locations (sometimes repurposed crypto mining facilities), lack sound data center practices, compliance oversight, reliable power infrastructure, or mobile generator backup capability - creating SLA and uptime risks that are unacceptable for production workloads.

How should CISOs approach enabling AI agents and automation safely?

Rather than blocking AI adoption, CISOs should implement guardrails through coaching platforms that enforce human-in-the-loop decision-making, establish clear pre-launch security and compliance review processes, and educate employees on data handling to prevent shadow AI risks.

Who should own AI risk management in mid-to-enterprise organizations?

AI risk ownership is a joint effort across CISO, CIO, infrastructure/architecture review boards, and physical security teams; the CISO must work cross-functionally to address how cyber attacks now affect physical infrastructure and OT/ICS systems.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode contains a handful of genuinely non-obvious points - AI compute infrastructure as a distinct availability risk under the CIA triad, hardware/firmware integrity concerns, and the framing of AI agents as personas to be managed. However, roughly half the runtime is consumed by general advice ('educate yourself,' 'break down silos,' 'yes not no') and personal anecdotes that add no operational value.

you need to make every AI tool and agent its own Persona. It needs to be managed like a person, like a stupid person
availability is coming back into concern for a ciso. It's no longer somebody else's problem or no longer a shared problem

Originality

10 / 20

The 'AI agent as a stupid person persona' framing and the cyber-physical convergence argument for GPU cluster availability are genuinely fresh angles. But the episode is significantly weighted toward well-worn CISO talking points - shadow AI, Dr. No, embracing AI or being left behind - that circulate constantly in security podcasts.

you wouldn't tell your dumbest friend critical things about your business because you don't know what they're going to do with it
you can impact the, um, OT systems or the ICS systems in a data center and you can bring down entire GPU clusters for days

Guest Caliber

13 / 20

Cassandra Mack is a working CISO at an AI infrastructure company with operational skin in the game - not a career speaker - and her commentary on bare-metal GPU security, supply chain integrity, and data center build-outs reflects real practitioner experience. The score is tempered because portions of the episode drift into generic CISO career advice well outside her differentiated domain.

we built the world's largest AMD cluster last year
In some cases, we're building a data center in two to three months from scratch. Uh, like we're doing one right now that is, you know, it's an old manufacturing plant

Specificity & Evidence

9 / 20

There are isolated concrete anchors - the AMD cluster claim, FAIR framework, Uber CISO reference, and a Pew Research 2030 automation statistic - but the majority of claims are unquantified ('a lot of companies,' 'several states,' 'various cases of CISO strife') and the guest repeatedly stops short of naming clients, breach costs, or actual SLA numbers.

by 2030, it's something like over 50% of cybersecurity processes will be automated with AI
even OpenAI was just saying maybe we can't meet our trillion something trillion dollars compute bill

Conversational Craft

7 / 20

The host asks topically relevant questions but operates almost entirely in enabling mode - never challenging a claim, not following up on the AMD cluster assertion or the data center build timeline, and labelling the conversation a 'masterclass' mid-episode. The final third is a standard rapid-fire personal segment that generates zero substantive insight.

I feel like this has been a masterclass on AI security, which I really appreciate
Wow.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A86%
  • Speaker B14%

Most-used words

security23ciso23risk22data21tools15sure15trying14help14power13compute11somebody11space10didn10place10customers10everybody10

Episode notes

As AI moves from experimentation to business-critical, security leaders are being forced to think about risk in new ways. In this episode, Kevin Pouche is joined by Cassandra Mack, CISO at TensorWave , to break down why AI infrastructure and compute are becoming central to the modern security conversation. Cassandra explains how these environments introduce new challenges around reliability, cost, and visibility and why traditional approaches don’t always apply. They also discuss how the role of the CISO is evolving, from enabling innovation to guiding long-term strategy, and what it takes to keep pace as AI continues to scale across the business.

Full transcript

35 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Welcome to Cybersecurity Business. I'm your host, Kevin Pushag. AI is creating new opportunities for the business, but it also introduces new dependencies and risks that security leaders can't afford to ignore. Joining us today is Cassandra Mack, CISO at tensorwave, where she focuses on securing large scale AI infrastructure in helping organizations think through risk as AI continues to scale across the business. Cassandra, great to have you here.

Speaker A: Thank you for having me. Good morning.

Speaker B: Good morning. So, before we dive into it, let's give our audience an idea of your role. You are a CISO for an AI company. I can't think of a more relevant, important CISO role in today's world. I mean, don't get me wrong, we know CISOs have to deal with AI on a daily basis, but your role seems to be centered on AI, Right? You founded the AI Security Council. So how did this all come to be and did you seek out an AI centric role for your latest endeavor?

Speaker A: Yes. So I have been working pretty much across all industries in the last probably 20 years and had a lot of visibility into, you know, a lot of modernization of virtualization of data centers. Just seeing a lot of crazy stuff happening. And then when the AI boom came and everyone started really paying attention to what was already happening in the AI space, I was really surprised by the differences in AI compute infrastructure versus the traditional legacy data centers, because I just assumed, probably like everyone else, that it was just another flavor of the same thing, but it's very different. Uh, like when you move from CPUs to GPUs and the infrastructure, we're talking about light speeds of difference in the technology and the complexity of what people are doing in that space. And a lot of people don't realize that we specialize in amd, and we built the world's largest AMD cluster last year. And what we realized is a lot of what we needed to do didn't exist. And we had to refactor existing components, make them do things that they never did before. And our engineers were very much challenged in that space. And even my security team was kind, uh, of walking around aimlessly trying to figure out what are we doing here? Because the existing practices and tools that we had just didn't exactly meet what was needed. The only thing we've ever had to think about is we just buy the stuff they offer us, stack it up, call it a day, and we know that we'll fail over because we have redundancy in the AI space. You don't have a lot of redundancy because this stuff can't just be picked up and moved to another place. It's very complex. It's very rooted in very careful testing to make sure that all the layers are working properly and the workload has to be fine tuned so you can't just pick it up and move it. So there's a whole lot of challenges in terms of like reliability in the compute, reliability in the cooling, reliability and power. Power is uh, a huge issue and it's not just the availability of power, the cost of power, it's making sure that all that stuff works the way that you're expecting and that your uptime is maintained. So a lot of new considerations there that are, they're pretty fun, you know, pretty fun. And we never have a dull day here. So yeah, getting all uh, that into one little thing is, is we're, we're very excited about it and we're excited to help educate other people so they can make good decisions.

Speaker B: Well, that's pretty cool. And I want to get in to more detail on AI compute, but before I jump too far ahead, I just want to take a step back and in general, sort of get your thoughts about a lot of these new responsibilities that are starting to fall under, let's say the average ciso. What are these new responsibilities as it relates to AI becoming more embedded in the business that are falling on the plate of the average ciso? What are they dealing with on a daily basis?

Speaker A: Yeah, so I think there are a couple things that they know about and there's a couple things that they're getting surprised by or they get pretty wide eyed when I start talking about them at, uh, CISO conferences. The first one is we all know that we have to uh, secure the AI that everyone's using on a daily basis and the tools that they have. Right. It's the integration of the AI chatbot, the AI functionality that's being rolled out automatically and sometimes turned on automatically without you knowing about it, such as in like Slack or Jira or other applications that you are, uh, already using and already are uh, very well ingrained within the stack in the organization. But there's also a influx of people learning how to do no code and uh, you know, regular coded AI agents. And there's really a need to be able to automate as much as possible and everyone's embracing that because the costs are becoming so high that you need to optimize not only the CPU part of your process, but also the GPU part and how they interact together. So there's a lot of components there. And there's also really the availability piece, which a lot of times does not fall on the ciso but technically does fit within the CIA triad. It's confidentiality, integrity and availability. And a lot of what people are realizing now is that availability is coming back into concern for a ciso. It's no longer somebody else's problem or no longer a shared problem. We have to start thinking about what is our compute strategy for SLAs that we maintain for our customers. Because now we don't have all our eggs in one basket with a hyperscaler because cost and availability are starting to become an issue there. Right? There's a lot of buying and a lot of the enterprise customers swoop in and scoop up all the availability because they're the ones that have the capability to proactively decide what's my 1, 3, 5, 10 year plan. And they know that they need to spend millions, billions. And you know, even OpenAI was just saying maybe we can't meet our trillion something trillion dollars compute bill. Uh, so you know, small to mid sized companies really have to start wrapping their head around. I need a compute strategy because I can't just get it from one place. I'm not going to be number one in line and I need to be able to rely on moving my AI compute projects from proof of concept to being able to show the board return on investment. And in order to do that you have to have reliable everything. So you know, that's the biggest aha moment I think that people are having on top of. What the heck do I do with these AI agents that everyone is unleashing in my environment and most E cells are erring on the side of just saying no, we're not going to do that. But I highly maintain that the people that are doing that are going to be very much left behind in this race because you've got to embrace it and figure out how to build the guardrails and make it functional or you're essentially handicapping your business. And that's not our job. Our job is yes and not Dr. No. That's very much an old way of thinking and we have to all get away from it. We have to figure out how to empower each other to be able to do that.

Speaker B: You mentioned cost, uh, you mentioned availability. Do these things. They must have a big effect when the business all of a sudden starts expecting an ROI on their AI strategy, right?

Speaker A: Very much. You're seeing costs skyrocket in terms of the power availability and is being passed on to customers. But one thing that people have not been thinking about very much at all is public companies, enterprise level companies have to meet sustainability targets that they set for themselves. And even small to midsize companies now are getting pass through costs from these enterprise customers because we also have to have sustainability goals. And they're not telling you exactly what you have to have, but you have to set something and you have to meet it or you have to justify why you didn't meet it. Because it's just being expected now that we're not going to be as wasteful as we've been. And we can't just justify it as, oh, everybody needs this. Well, yes, everybody needs it and that's why we need to manage it more effectively. And I think we've been able to say, oh, that's not us, that's not something that anybody's had to think about. But pass through costs on sustainability, environmental costs just in the business and trying to make sure you're doing the right thing and even optimizing what you're using right water is a big thing. Um, just the cost of maintaining these systems is very expensive and eventually is passed through to the customer. But even more so on the infrastructure side, we cannot estimate what the load is going to be or what the need is going to be if people don't come to us ahead of time and say, hey, here's our letter of intent for this much power or this much clusters, or you know, here's what we're going to need in terms of training and inference. There's just not a lot of visibility right now into even being able to do that effectively. Unless you have somebody on staff who has experience in the AI space or who's coming from large scale data center build outs who can advise you properly. And there are some companies out there that are starting to advise well, but it's really still wild wild west for a lot of companies to be able to even speak intelligently on. Here's what we think you need. Because we've largely got companies who are running, you know, 10 to 20 POCs in their AI space trying to figure out what is going to stick, what's going to work. And a lot of them unfortunately are slapping AI labels on existing products that weren't working well and weren't adopted well and trying to, you know, resell. And there's the added complexity of a, uh, CISO or B level person trying to figure out, you know, is this snake oil or is this real? Can I even buy this thing and is it going to work for me or is it going to get me fired? Because I, I didn't even know what I was looking at.

Speaker B: You mentioned CISOs can't be. Dr. No. Which I completely agree with. Somebody once said a CISO needs to protect to enable, right? That being said, companies that make an announcement that we're going full force into all aspects of AI faster than a speed and bulletin. Mr. And Mrs. Ciso, you need to find a way to help us do it safely. Uh, CISO role has always been a pressure cooker in some ways. Is this putting an insurmountable pressure on some CISOs?

Speaker A: I do think increasingly in the public sector, especially where now you could potentially go to jail for doing something wrong if you're not able to prove that you had effective risk management practices in place. And like for instance, I go to many CISO events so that I can cross pollinate with people that know better or have experienced things, you know, and learn from their experience. But one of the things I took away from like the uber CISO came back and said emphatically, if I would have had more risk management in place, I would have been in a better place. And that was his number one recommendation, is do better at risk management and have an effective plan and be able to show that you took mitigation steps that everybody agreed to. And then, you know, there's various other cases where people went through considerable strife and personal struggles, including physical challenges because of things that happened to them as a CISO and a public company. And I think there are a lot of learnings there for all of us at whatever level you're at to really think about what you're doing, get as much information as possible and iteratively change your process. Right? Don't be stuck with one thing, don't be stuck in a fear mode or uncertainty or doubt about your program. Do as much as you can, do as much due diligence, document, get sign off, right? Don't make decisions in a vacuum and don't make decisions with very limited information that stick for a long period of time because it's moving so fast and we all have to band together. The days of working in a silo as a CISO and being defensive about your posture and not wanting to talk about things I think are coming to an end if we don't work together on this. This is one of those things that really could break companies either adopting too fast and without guardrails or buying a bunch of tools and trying to rely on this Integrated spaghetti system of things working together. Because there are a lot of companies out there that are designing tools. But I firmly believe that going into design partnerships with some of these newer AI first companies is a really good strategy and one that we would have shied away from before because it just wasn't, it wasn't reliable and baked in and you didn't have a surety that it wasn't going to get you fired. But I think layering tools together and figuring out, is this a tool or is this a process that we need to fix, or do we need to put guardrails in place? And one of the newer tool sets that are out there is, it's not really a guardrail. It's a coaching and education platform that essentially pops up when customer or employees are trying to use AI with your platform or whatever tools you have. And it says, hey, it looks like you're trying to do this thing, or an AI agent is trying to work on your behalf. Are you sure you want to do this? Or it looks like this kind of data is about to go here by this, you know, do you want to check it? So enforcing human in the loop practices, which is super key, and building into your educational system within the company, hey, you need to do due diligence with your security and compliance department before you bring out a tool. Here's how you build in, uh, processes to make sure you have human in the loop decision making. And you're advising customers, prospects, candidates on the use of AI within your platform. Because now there are several states that have AI data privacy rules. And if you're not abiding by these, there are many companies out there that are just squatting and looking for opportunities to sue you. So we have to make sure on all fronts that we're educated and we know exactly what needs to be done. And we're helping our employees do that because shadow it is going to become a huge thing in shadow AI, right? We're, we're adding additional layers of complexity here. And I truly believe education is the number one foundation for making sure that everybody has the tools they need to help you make good decisions and also to call to your attention, like, hey, I see this thing happening and it looks weird. Can you take a look at it? Because in the past we would rely on tools to tell us that this stuff is happening. And I think it fails in a lot of ways because if you don't have it tuned, you don't have the right tool, you don't have the right people looking at it. You're not going to find out until after the fact and a person's going to notice that a lot faster. So we need to make them empowered and feel empowered to come to you and say, hey, I have a thing.

Speaker B: Right. So this notion of AI compute, Cassandra, at a high level, it's, I'm, um, on calls every day with companies and AI compute, this notion doesn't come up I feel like as often as it should. Right. Most AI, uh, conversations are focused on models and use cases, let's say, not necessarily infrastructure. Like, do you consider this sort of a newer attack surface? Like why, why isn't this getting the attention it deserves?

Speaker A: It is largely because people cannot afford to build their own data centers or maintain them and don't want to. You know, that's not a focus because it's, it's very labor intensive. It relies on a very specific skill set which is hard to find. We have some of the best recruiters out there in external agencies scouring the planet looking for people that are capable of doing this. And it takes a, uh, quite a bit of effort to be able to vet these candidates because you're, you can't use run of the mill recruiters who don't understand the space or they don't even know what to ask. So most companies just can't do it. So they're having to now rely on other companies who are emerging in the space, like Neo clouds like ourselves. And some are even going to middlemen who are brokering what turns out to be, you know, crypto mining facilities that have extra capacity and some grandma's basement somewhere. And it's, it's becoming much more dangerous because if you are not used to going out and vetting these kind of companies and you relied implicitly on your hyperscaler or other very large company that has dedicated resources to do this. It is a new frontier for you to even know what to ask or know what to look out for. And I'm newly acquainted with, you know, are, uh, we largely go into abandoned data centers or abandoned buildings that have a lot of power and we rehabilitate them at lightning speeds, which is almost unheard of. Right. Like we're, we're positioned uniquely because our leadership had uh, foresight into going to where the power is and securing that and then looking for places to build a data center. So what we're finding is we have to do some education in terms of like, here's what you need to look for when you're looking at a provider. They need to have sound data center practices, they need to have compliance practices. They don't just rely on a third party vendor once a year to come and look at 10% of the data center and make sure it's functioning as it should. Because if you don't have reliable power, you don't have backup power, you don't have ability to pull up mobile generators in a pinch and you don't have ability to integrate the newer GPU clusters quickly and timely. You're dealing with obsolete hardware by the time it's even brought up. And the old hardware makes a huge difference in your ability to compute. If you don't have the right storage solutions that are fast enough, you can't run your workloads uh, at uh, optimization. Right. So it's a competitive market in terms of these. Each individual lever that has to be in the right place for your workload and tuned and also the risk factor, right. You need to determine is this a low risk activity that could go on a middleman's brokered GPU cluster in a small thing that, you know, if it goes down, it's not a big deal because their SLAs are not there or their uptime is not there, or do I need to be in a reliable data center that is top tier, that has redundant data center capability and they can, you know, they have contracts in place to be able to pull up a mobile generator if we need more power in a pinch or we've got a blackout of some sort. So there's a lot of things there that we're learning that we need to educate the customer on. Another one is really now we're in a shared responsibility model where we do bare metal. We don't code our own security tools, but we will recommend to our customers who largely don't have a ciso. Most of these places are AI first, there are series A or series B and most places do not hire a CISO until like Series C or they don't even have a first security hire sometimes until series B. So you're talking to them about really expensive programs, really complex workloads and they don't have anybody on staff that understands security. And it largely falls to an AI engineer or a DevOps engineer. And they're relying on whatever one or two classes they got in their degree program, whatever uh, they can get out of, you know, googling the Internet to figure out what do I do here. So we're finding we have to do more education for our customers at onboarding to help them understand. Here's what a proper Security stack looks like. Here's what you absolutely have to have and here's what we recommend. And if you're going to do bare minimum, we also need to help you with, you know, abc.

Speaker B: Well, I mean, you're really talking about vendor risk, which in some ways was already a challenge in the weakest aspect of a security program. How about the big players like Nvidia from a hardware perspective, or AWS and Azure from a cloud perspective? Those bigger players, should we just be implicitly trusting them?

Speaker A: No, I think the onus falls on every single layer of the stack should be owning their own destiny and really being as, um, proactive as possible. Because like, for instance, Nvidia and AMD and every other provider of GPUs or CPUs, they do their best to source components which are very sparse. And we have a consistent challenge with trying to line up components to meet the need of these huge clusters and these really fast build outs. In some cases, we're building a data center in two to three months from scratch. Uh, like we're doing one right now that is, you know, it's an old manufacturing plant that was abandoned and we are going in and, you know, gangbusters getting this thing ready because we have customers lined up already. So we're relying largely on our supply chain to be what we expect it to be. But we also have to look at hardware bill of materials and software bill of materials. We need to be able to prove to our enterprise customers that this stuff hasn't been tampered with and that it hasn't come, uh, from a substandard facility. Because every batch of hardware is different, every batch of optic is different. And even though they're coming from the same manufacturer, they're coming from different sites. And I think people don't think a lot about that because we've always just been like, of course, you know, Azure, of course, uh, GCP is getting the best of the best. We trust them. And, you know, There are some CISOs out there that would say, I never trusted them. And they are, they're the ones with the right mindset for this new frontier. Because we all have to be thinking about this stuff. And before it was very optional to look at your hardware bill of materials. And now enterprise customers are saying, no, no, we need proof that you're doing this. We need proof that you're checking it. We need proof that you're nuking the firmware when it comes in and not trusting that it's good. We need to know that you're doing Your certificates, right. And your encryption and your access keys. Everything has to be checked and maintained and make sure that we're iterating as the threats evolve. And, uh, largely the threat landscape and threat modeling is changing. Right. It used to be an optional thing that you would go to an outsourced provider and say, help me with threat modeling or help me with this threat intel. But now we have to have constant feeds and we have to have people internally that are, uh, trained to do threat modeling at the architecture stage. You know, how do we build this thing with the threats in mind instead of after the fact? We've got a vulnerability now that was caught on a scanner or a pen test and now we got to do something about it that's no longer acceptable. And it has to be a continuous process.

Speaker B: You mentioned helping organizations outright that don't quite have a CISO to own this. Let's talk about maybe a mid size or enterprise organization that do have layers and do have a CISO who should hone AI risk. Is it the ciso? Is it the cio, the data team, the business, who should own it?

Speaker A: I think it's a joint effort, um, joint effort. Most mid to enterprise companies will have an infrastructure review board and an architecture board and things like that. So they're a little bit more mature in that respect. But there also is a heavy tendency, I see now to say, oh, the CISO doesn't own physical security. I have a physical security team or a facilities team that owns that. And I'm trying to educate more the CISOs and the physical security people to help them understand. We're now living in a new era where cyber attacks affect physical infrastructure much more. So because it's a kinetic effect, you know, you can impact the, um, OT systems or the ICS systems in a data center and you can bring down entire GPU clusters for days. And that used to not be the case because you had redundant power clearly available and if something went down, you can move everything over. So now you really have to be a lot more in tune with my cooling system working properly and proper water coming through these liquid tooling systems and you know, do I have biosludge? Just, uh, a lot of components have to be thought about and the CISO needs to be involved in that because availability falls under as much responsibility there as it does for a CIO or a cto. It's impactful for the entire business and it can no longer be like, that's not me. Uh, you know, it's over the fence over there. I think the success will come from everybody coming together, being as educated as they can be, and being open to, you know, maybe we gotta do something a little weird here to make sure this works. We can't rely on exactly what we did before, although there are a lot of learnings that we've had from, you know, dot com and other technology advancements. Like you probably remember, everyone was like, oh, what's this? Google? I don't know what this is. This is never gonna work. Or, you know, oh, what's this? E commerce? Everybody was very skeptical. Just like, everybody's a little bit up at arms about AI. You know, we've solved these challenges before in a different flavor. We just need to learn from it and, you know, tweak it essentially, and figure out, uh, okay, what flavor of solution or what mix of solution and how many, um, smart people can we get in a room to make sure we're making good decisions that are not going to negatively affect somebody up or down the line.

Speaker B: So to me, when I think of AI Compute and the business risk success is risk reduction, right? It's doing a lot of the things that you've been mentioning, um, other metrics that we should be using to measure AI risk reduction. This is a relatively new risk in the grand scheme, right?

Speaker A: I think there's a couple things that need to happen in the risk space. Just from, you know, doing risk management for many, I would say almost three decades now, we went from, you know, swag, you know, lick your finger and put it up in the air and judge the win. We went from that, right? Like, what's, what's. What do we think as a Monte Carlo model internally in this organization or across my peers, that is the likelihood and impact of this thing happening. And if they were doing risk management as a whole, it's very rare. It's very much like a. Most people will do it once to do it and have it done in a year, and then they, they don't look at it very much. And then when something bad happens, they're like, didn't we have a mitigation plan for this? You know, who should we blame for this? Um, or we'll just throw money at the problem or people at the problem and try to solve it. And that rarely works. There has to be a lot more thought process and a continuous learning exercise in that respect. But we also have a lot more quantitative tools available to us. And there are a lot of data out there on breaches and events and data leaks. And if we're not getting those tools and integrating them, um, into our risk practice internally. We're not doing ourselves justice because there are things out there. Like when quantitative analysis with FAIR came out, a lot of people are like, that'll never work because security never has any data. We don't have enough data to do this. But it's not just internal data capture. It's using those external sources that are vetted that insurance companies are using. Because largely a lot of our mitigation strategy is we're relying on our insurance policies. But new information is coming that says, you know, a lot of insurance companies will decline to cover things because somebody either told alternate realities on their insurance application or they just didn't have the right person filling it out who actually knew. And when we go into forensic analysis with the insurance company, they realize you did not have the right things in place or you were willfully non compliant with something. And that can really set you back because you don't have any remedy and you're spending money that you didn't plan on or the insurance only partially covers and you're stuck with reputational impact and other things that could have been prevented. So, you know, it's not a perfect science, but there is a lot of data out there now and I encourage there's even tools out there now that are very cost effective for small businesses, but they don't usually have somebody who knows risk management. So I like to tell people like, hey, go find yourself somebody who's experienced in compliance and audit and security. Go get yourself somebody who's multi talented. As your first hire, don't just hire a security engineer because that's not going to cover everything you need. Because most of these smaller to midsize companies, they have a multitasker that starts right. Like I know all the areas and I'm now looking for people who are specialists in areas that I'm not a specialist in. But if you wait too long, you have a ton of security debt and a ton of risk that's inside that you can't manage because you don't even realize how embedded it is or how bad it is or how that it's already affecting you. If you don't have the right detection and prevention tools in place, you don't even know that bad stuff is happening until it's already fully ingrained. And you can't tell the difference between your baseline security and your baseline behavior. And what is a bad event or what is an ongoing person living in your network, Person or entity. Right? And I think one thing I keep forgetting to Mention is one critical mistake that companies are making in a risk management perspective is not making every AI tool and agent its own Persona. It needs to be managed like a person, like a stupid person. Right. You wouldn't tell your dumbest friend critical things about your business because you don't know what they're going to do with it. You would not tell an AI agent or an AI tool things that are stupid. And a lot of people are just implicitly trusting this and they're not factoring it into their risk programs. You know what happens if somebody gives too much information to this AI agent that's given too much permission, and there's no human in the loop? This kind of stuff needs to be in your risk program, and you need to be actively managing against it.

Speaker B: Wow.

Speaker A: Okay.

Speaker B: I feel like this has been a masterclass on AI security, which I really appreciate. And because of that, I have one more question for you on, um, the topic Cassandra. In this. This is sort of, ah, a hard one in, in many ways, but I think you're equipped to answer it. And what. I'd love to know what you think AI security will look like. Well, I want to say three years, but three years in AI security seems like 30 years, so maybe 18 months

Speaker A: is a better question.

Speaker B: What do you think?

Speaker A: Right. Um, I'll just quote something that I found from Pew Research recently when I was doing another podcast and I needed to make sure I was not telling lies.

Speaker B: Okay.

Speaker A: Um, I found that by 2030, it's something like over 50% of cybersecurity processes will be automated with AI, and that's on the cybersecurity space. Other spaces, like big, uh, pharma, banking, um, they're way ahead of us. They're going to be much more automated. And I know it freaks people out thinking they're going to lose jobs, but the jobs are not shifting away from this. We're shifting more towards each one of us that is smart enough to get on the bandwagon. Now we are going to become essentially shepherds or wranglers of the robots, and we need to get on that because we need to be educated and be ahead of the technology, because the technology is moving all the time. And, you know, in five years, it. We're not even going to be able to wrap our heads around where it is. Right? Because we're. We're not even able to wrap our heads around where it is right now and where it's going. And I think people need to get on board with. Go take some classes, go educate yourself. Like, there's a lot of free stuff out there, there's a lot of paid stuff. Everybody's getting out there and putting training out there, and some of it's ridiculously priced. But I say go out and take some free YouTube classes. Go educate yourself, because in five years, if you're not prepared now, you're not advancing fast enough to keep up with it. But those that do, we're going to be part of the people who are profiting and doing well and thriving in the AI era. And especially by 2030, a lot of the things we're doing won't even exist anymore. And, and I know it's very ethereal and it's hard to wrap your head around, but there is a lot of research out there that people are doing to help educate people. You just have to go out and look for it. And, um, I think it's going to be more important to break down the silos and make sure that we're all not working in our own area and just expecting somebody else to do something.

Speaker B: Listen, I have two kids in high school and one in middle school and that putting yourself out there and getting educated, I mean, this is what they need to do.

Speaker A: Yeah, they're largely ahead of us, you know.

Speaker B: Yeah, they are totally.

Speaker A: Well, my kids are 9 and 5 and they just blow my mind already. Like, my son will just ask, he'll. Somebody will show him something they're impressed with and he's like, but isn't that AI? I'm like, dude, what the heck? How do you even think like this? You know, because we just think, oh, it's of course it's true. Right. Like we don't even assume that it's an AI.

Speaker B: Right. Well, so this was great. And that concludes that AI part of our discussion. I do have a few more questions that have nothing to do with technology per se. That is just a few rapid fire questions. I know our audience likes to get to know the person that is on the podcast. So I'm going to ask you a few quick questions. You ready?

Speaker A: Okay. Yeah.

Speaker B: If your CEO gave you unlimited budget for one thing, what would you spend it on? M.

Speaker A: I think smart engineers, they will make or break you in terms of automation. Uh, the ones that understand automation and understand the importance especially in compliance because it really is a tedious time sucking and soul sucking event that happens every year. And there's internal and external audits that really will bog your compliance team down and they really should be working on things and using their best brain power and that's where an engineer really can be a game changer.

Speaker B: Love that you said people. Next question. What's the last book you've read?

Speaker A: Uh, let's see.

Speaker B: Or listen to. That's fine, too.

Speaker A: I'm a big nonfiction fan. Like, I will learn as much as I possibly can all the time. And so it's a lot of, uh, hey, Gemini, find me sources of this so that I can read intelligently. So I would say just in general, I've been doing a ton of AI research and a ton of how do I build effective guardrails? Which I know is kind of boring, but I like to make sure I'm not telling lies when I tell people I know what I'm talking about. And I like to quote actual research. So I spend a lot of time doing that.

Speaker B: Well, I have to say, after this conversation, it's not a shocker to hear that, um, if you could instantly master any new skill, personal, professionally, doesn't matter. What would that skill be?

Speaker A: I. Right now, I'm learning no code agents, because I want to be able to at least explain to people, here's what I'm trying to do. And I've kind of let my tech skills go because, you know, I used to be a mainframe programmer many moons ago, and I tried to keep up with it, but I got super busy with everything else, and I. I was kind of fantasizing about, like, what if I went back to learning the coding so I could actually do the code and be able to communicate, uh, more effectively with the engineering people? Because being able to speak their language really goes a long way towards trying to explain security concepts to them. Because if you're talking in a different language, they're kind of like, do you know what you're talking about? Do you understand the implications to what you're telling me to do? That's going to cost me time and money and people. So being able to kind of cut through your not understanding exactly how to explain it to them, I think would go a long way. So I'm really, you know, kicking that around and trying to figure out how do I carve out time to be more effective in my communication.

Speaker B: Uh, good for you. That's great. Um, if you weren't working in cybersecurity, what would you be doing?

Speaker A: Oh, that's a good one. I have come to realize recently that there are a ton of people who are highly effective out there who are not fulfilled in their personal life, whether it be, you know, their relations with their partner, relationships with their family, things like that and I've become newly attuned to the difference between a therapist and a coach. Therapists look backward and try to help you solve things that are, you know, skeletons in your closet and beehives or the stuff that you keep avoiding and compartmentalizing. And a coach helps you go forward. And I've really thought about my next chapter of life and just preparing for that in the background and really wanting to be like a relationship and kind of intimacy coach for people because I've newly found that in my own life after almost coming to a divorce after 15 years. And I realized I really need to carve out time for this to be important. And uh, I really feel like there's a lot of people out there who just, they don't even have visibility to that being a thing. They think, oh, let me go to therapy and solve this. Well, therapy didn't work and you know, now I just don't know what to do. So I just keep doing what I've done because that's the best I can do. So. And we all go to these self help books that are regurgitated and they don't really help anything. So I really want to focus on that as my next chapter and try to get good at that and practice on the background and be able to help people because I really think intuitively I'm a helper.

Speaker B: Well, I think that's great because there's a real shortage of that. So now you're going to have people reaching out to you on LinkedIn.

Speaker A: Yeah.

Speaker B: Looking for a coach.

Speaker A: Cassandra? Yes. Like, did you also know I do this in my spare time? Right.

Speaker B: So it's my last question for you. What's one piece of advice you wish you had when you first started your career?

Speaker A: Mhm. Yeah, I think there was a real shortage of women in tech at the time and I spent a lot of time having imposter syndrome and worrying about not knowing what I was talking about. And I mean, largely when I started there was no Internet, right. And I didn't have access to a lot of information. So I only learned from people who are willing to share. And I think we have so many tools now. Like I remember I joke with everybody that complains about current infrastructure and coding tools and stuff like that. I'm like, you guys don't even realize. Like we would spend time editing 10,000 lines of code and then we would submit and we would wait all day for it to compile and then we'd fail and we would get out our pillow and our blanket and sleep in our queue because our work wasn't done. And now you can press a button and it instantly compiles and instantly runs and instantly gives you results and it integrates with everything. Right? So we have so much available to us and I think people don't take advantage of it. Seek out the help, seek out the mentorship, seek out the peer groups that can be your advisory board so that you can be the best that you can be because the resources are there. I think people are sometimes afraid to reach out and look stupid or they think if I say this question, I'm going to look like I am not good enough to be in this room. And you, you're clearly above everyone else if you're already here. Right. You just need to reach out and use the resources and don't be afraid.

Speaker B: Wow, thanks. What a phenomenal discussion. Cassandra, thanks so much for taking the time to join us. I know I really enjoyed the conversation and I know our listeners will as well. A lot to think about here, especially as AI UH continues to scale. Security leaves are being pulled into these new areas of risk and decision making that we talked about today to our listeners. If you enjoyed this conversation like I did, be sure to subscribe, share the episode and we'll see everybody next time on Cyber Security Business.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Ep 10. Endor Labs on Code Vulnerabilities, Sketchy Open Source Developers, and Software Supply ChainGenealogy of Cybersecurity - Startup Podcast · on Software Bill of Materials (SBOM)85 / 100
  • Enterprise Buyers Now Demand a Vendor Software Bill of MaterialsB2B SaaS Talks with Fexingo · on Software Bill of Materials (SBOM)81 / 100
  • 210: The One About the Future of Cyber WarfareThe Government Huddle with Brian Chidester · on Software Bill of Materials (SBOM)63 / 100

More from Cyber Security Business

All episodes →
  • The Path to CISO61 / 100
  • Creating an AI Security Culture63 / 100
  • Future-proofing and Storytelling80 / 100
  • Hungry for CISO Trends72 / 100
  • Evolving as a Security Leader65 / 100
All Cyber Security Business episodes →