The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/teissPodcast
teissPodcast artwork

teissTalk: How AI is forcing a redesign of security itself

teissPodcast · 2026-07-02 · 46 min

0:00--:--

Key moments - from our scoring

Substance score

41 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber9 / 20
Specificity & Evidence10 / 20
Conversational Craft6 / 20

AI is compressing attack timescales from years to days while most organizations lag dangerously in readiness - creating a critical redesign moment for security architecture itself. Paul Barbosa (Check Point) and Satyam Rastogi (Bamco) unpack why the 51-point gap between AI adoption strategy and architectural readiness exists, and why traditional security models built around perimeters and human gatekeepers are fundamentally broken for agentic workloads. The core tension: AI agents operate at machine speed via APIs and tokens, executing autonomous workflows across SaaS platforms - yet security governance, accountability (only 14% of enterprises assign someone uniquely responsible), and controls remain human-paced and fragmented. The discussion reveals that visibility into AI usage sits at just 5% across enterprises, shadow AI mirrors the shadow IT problem of cloud migration, and data classification, identity governance for non-human identities, and runtime prevention (not post-incident detection) must be baked into every architectural component. For security leaders and operators, this isn't a tool problem - it requires unified security architecture, identity-centric access controls, API traffic classification, and vendor partnerships that embed checkpoints before deployment. The stakes: attackers exploit the governance gap ruthlessly.

Key takeaways

  • →Only 26% of organizations say their architecture is ready for AI with minor changes, despite 77% making significant AI strategy changes, creating a critical 51-point readiness gap.
  • →The time to exploit vulnerabilities has compressed to just 2 days while time to patch remains at 26 days, creating a dangerous window where traditional security models fail.
  • →Only 5% of organizations have full visibility into AI usage within their environments, and visibility is the critical first step before implementing policy and governance controls.
  • →Non-human identities (agents, APIs, service accounts) calling each other at machine speed makes human-in-the-loop approval systems unsustainable and requires runtime prevention with identity and policy-driven controls.
  • →Only 14% of enterprises have someone uniquely accountable for AI governance, leading to accountability gaps across CISOs, CIOs, and business lines that attackers exploit.

Guests

Satyam RastogiPaul Barbosa

Topics in this episode

DLP (Data Loss Prevention)DevSecOpsWeb Application Firewall (WAF)NCSC AI Shift in Cyber Risk reportCheck Point 2026 Cloud Security ReportShadow AI riskAPI explosion and token managementNon-human identity governanceCASB (Cloud Access Security Broker)IDS/IPS systems

Questions this episode answers

What is the time compression problem AI is creating in cybersecurity?

AI has compressed the time from vulnerability discovery to active exploit from years down to just 2 days, while patch times remain at 26 days - creating a 24-day window where attackers operate freely. This mirrors the cloud migration pattern but at vastly accelerated pace.

Why do so many organizations have AI adoption strategies but unready architectures?

Check Point's 2026 Cloud Security Report found 77% of enterprises have made significant AI strategy changes, but only 26% report their architecture is ready - a 51-point gap driven by lack of governance accountability (only 14% have someone uniquely responsible for AI governance) and vendors deploying solutions before security controls are designed.

What percentage of organizations have visibility into their AI usage?

Only 5% of organizations claim full visibility into AI usage within their environment, and even that visibility is likely limited given the scale of shadow AI deployment across SaaS tools, agents, and APIs.

Why is 'human in the loop' not a sustainable control for AI agents?

Humans cannot operate at machine speed, and vigilance naturally drops after initial safe executions, creating a risky false-confidence pattern. AI agents execute at runtime at scale via APIs - requiring instead runtime prevention, identity governance for non-human identities, and architectural redesign rather than manual gating.

What security architecture shift does AI require?

Organizations must move from perimeter-based defense-in-depth toward unified Security 2.0 architecture: identity-centric controls for AI agents, runtime detection across APIs and workloads, data classification for agent access, and network-level traffic controls as a last-resort layer, with every product and tool retrofitted for runtime prevention rather than post-incident detection.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

A handful of concrete data points (2-day exploit vs 26-day patch gap, 51% readiness gap, 14% with unique AI governance accountability) provide genuine value, but large portions of the conversation are circular repetition of the same 'visibility first, then governance' prescription with no depth added. Many claims are asserted and agreed upon without development.

two days from discovery to exploit and time to patch still remaining at 26 days. So that gap in between is where the battle is on right now for us
only 14% of enterprises had somebody uniquely accountable for AI governance. So in a shared responsibility model it becomes uh, who's on first

Originality

7 / 20

The 'shadow AI is the new shadow IT' and cloud-migration-as-precedent framings are explicitly acknowledged as recycled. The 'language as the new attack surface, not code' argument is moderately interesting but underdeveloped. The episode largely recycles circulating AI security tropes rather than advancing them.

the domain of exploit uh, is not computer science anymore and Python code, right? The domain now is natural language. And so if natural language is the code, um, we know that we have no bounds
shadow AI is the new shadow IT risk

Guest Caliber

9 / 20

Paul Barbosa is a senior VP at a major security vendor but is visibly present to promote Check Point's own Cloud Security Report, limiting independent credibility. Satyam Rastogi is a genuine practitioner but from a low-profile company and contributes mostly agreement and repetition rather than deep practitioner insight.

We released our 2026 Cloud Security Report, very much focused on enterprise adoption of AI. Uh and what we found was super interesting
we were able to bypass a really huge well known EDR by the help of advanced AI level offensive things that we can create

Specificity & Evidence

10 / 20

Several concrete statistics are cited, but nearly all originate from Check Point's own self-published report, which is promotional material rather than independent evidence. Named regulatory frameworks (NIS2, DORA, ISO 42001, OWASP LLM Top 10) add some grounding, but there are no third-party data sources, named customer case studies, or detailed real-world examples.

77% of everyone we polled uh, has made moderate or significant or complete strategy change uh, related to AI, but only 26% said that their architecture is ready and only needs minor changes. So that's a 51% gap
a third of our respondents also indicated that they're already seeing um, attacks they can attribute to AI. Uh and that third that they identified was phishing, advanced phishing using AI, uh and deepfakes

Conversational Craft

6 / 20

The host asks broad, scene-setting questions and never challenges a guest claim or asks a probing follow-up; most energy comes from relaying audience chat questions rather than host-driven inquiry. The conversation devolves repeatedly into mutual agreement loops ('you're right,' 'spot on,' 'right') with no productive friction.

Ade says surely emphasis should be on the vendors to ensure that appropriate checkpoints are embedded in any AI product. Now I think that's a really interesting push to vendors
why are so many businesses struggling with that readiness gap? Why are so many businesses struggling with this? And is it simply down to pace of change or other complexities as well?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B43%
  • Speaker C34%
  • Speaker A23%

Most-used words

governance29security25data25point19controls19towards18organization16place16control15agents15bringing15architecture14identity14human14sure12agent12

Full transcript

46 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello and welcome to another episode of Tice Talk with me, Jonathan Craven. Um, good morning, good afternoon and good evening to you wherever you are joining us from in the world today. Um, hopefully if you're in the uk, you have a very cold drink, you're sitting in a paddling pool or you've got your air conditioning on if you're lucky enough to have it. Um, welcome to everybody who's joining us on Zoom Live Stream. Welcome also to anybody who's joining us in the simulcast on LinkedIn. Uh, if you do want to make a comment or ask the panelists a question today, please do hop on over to the Zoom link. You'll, ah, be able to jump in the chat there and ask our panelists, uh, some questions as the episode goes on. Ah, and if you need an incentive to go over and do that, um, at the end of the episode, uh, we will be picking the best comment or question in the chat and that person will win the much coveted piece of crockery, the Tice Talk mug. Um, so I'm sure you'll all be raring to get into the chat and ask some questions. Um, and of course you're going to want to, because today we've got a fantastic, um, topic of conversation how AI is forcing a redesign of security itself. Now, if that doesn't sound like a riveting conversation for a Thursday afternoon, I don't know what does. Um, and to discuss that with me, I've got two fantastic panelists. Um, so I'd like to welcome them onto the stage. We have Satyam Rastogi, who's the director of information security and DevOps at Bamco, and Paul Barbosa, the VP and general manager for Cloud Security and SASE at Check Point. Gentlemen, welcome.

Speaker B: Thank you very much, Jonathan. It's a pleasure to be here with you both.

Speaker A: Thank you. Um, and also very, very quick, uh, thank you to Checkpoint, uh, as our sponsor for the proceedings today. Um, they're keeping us in ice lolly, so we're all happy. Um, so to kick off the episode today, we have, um, a news item that we're looking at, which was from the ncsc. Um, it's going to be dropped into the chat, uh, now, um, so you can have a look at the article if you like, which is the AI Shift in Cyber Risk, why Leaders Must Act Now. Um, so guys, I don't know what you thought about it. I mean, I think one of the main takeaways I found from the article itself was this whole conversation around AI compressing timescales um, that we've been used to in the security industry for years, if not decades now. And it's compressing these timescales from years to months, from months to weeks, from weeks to days. What do you think about it?

Speaker B: I absolutely identify with this. And the way we're thinking about it is uh, the race is on, uh, quite simply the promise of the productivity gains, uh, that AI is going to deliver to society, to the businesses uh, that are using it, um, are clear. Uh, and so the implementations are happening as we speak. Uh, and the uh, identification of vulnerabilities to exploit, time compression to the traditional time to patch we see now that is like two days from discovery to exploit and time to patch still remaining at 26 days. So that gap in between is where the battle is on right now for us.

Speaker C: All right. And uh, it's like as AI is speeding and uh, just not about like you know, improving the performance, also about uh, the cyber risk. So AI has just not been changing the cyber. It's, it's uh, changing the entire operating model. Either it is uh, into security itself or maybe into DevSecOps. So we need to be thinking of like you know, the AI itself which is more concerning nowadays. It's something which is speed of adoption versus speed of governance and uh, what NCSC is like. You know, every leader is nowadays concerned about the AI governance.

Speaker B: Satyam. We were thinking uh, about this uh, with a lot of rigor and went out and pulled uh, a large group of our customers. Uh and what we discovered was exactly as you described it. We released our 2026 Cloud Security Report, very much focused on enterprise adoption of AI. Uh and what we found was super interesting on you know like 77% of everyone we polled uh, has made moderate or significant or complete strategy change uh, related to AI, but only 26% said that their architecture is ready and only needs minor changes. So that's a 51% gap, right or point gap in between, you know, readiness. And I don't know that we've seen um, a technology shift of this significance create that wide of a gap so quickly.

Speaker C: Right. And uh, as you said like about the SaaS and uh, most of the organization I have seen like you know, they are deploying the cloud before they are you know, making sure that we have a secure plan in place. And similar to AI, we are speeding up and uh, many organizations are repeating the same mistakes. That's towards the AI governance. And uh, speeding up is another thing. And whereas adopting AI, you know, security and governance, uh Itself is something that we need to look at now, uh, and it's the shift we are talking about. So we need to be very much proactive in this case, uh, where we can define and see like which AI agent is like accessing what in our environment.

Speaker B: Yeah, so true. I think this, you know, the good news about this, uh, you know Jonathan, is that uh, we do have a paradigm that we can at least baseline against. Uh, and we have the cloud and the rise of moving workloads into the cloud as at least an operating paradigm. In that era we were very much focused on shadow it, who's deploying unauthorized workloads, et cetera. Uh, and then we took this approach of visibility first, uh, and then policy, governance and control. We see that same paradigm being applied to AI. First the visibility. Now the downside is we believe there's only like 5% of organizations who say they have full visibility into the AI usage within their organization. I would posit that that 5% has probably a pretty limited implementation if they have full visibility. We're seeing quite the opposite. That visibility right now, uh, is the first stage um, of gap control that we're seeing as well. And I think uh, that's something that. Satyam. I don't know if you're seeing that first step to visibility in the same way.

Speaker A: Right.

Speaker C: And of course since uh, it has become one of the security concern and the risk for the organization, every other organization is looking after to bring in the monitoring, uh, controls and uh, the shadow AI is the new shadow IT risk and it's more towards uh, you know, the governance and if we are able to bring in the identities towards all those agents. So every other SaaS or every other tool or maybe any productivity or maybe you can talk about maybe any, any meeting or video conferencing tool. Now they are all coming up with our agents, right? And uh, we, we never know as an organization what, what all the data it has been like pulling and uh, you know, it has been ingesting to their Systems and the SaaS. So we need to be very concerned about giving them the ident, uh, you know, being, being um, in a system where we can monitor them.

Speaker B: Um, and it's, it's, you know, it's not putting pressure, what's very interesting about this technology shift, it's not putting pressure on any one part of the architecture. It's putting pressure on all parts of the architecture equally, all at the same time, all at pace. We see it even in the infrastructure side that the infrastructure problem, uh, now is one of uh, scale traffic. We're seeing an explosion of API traffic obviously as agents are deployed and agentic workloads start calling APIs and start completing closed loops of action. Uh, we see a tremendous amount of east west traffic uh, as well. Even the traditional controls at gateways are also being put under pressure. One, from understanding the workload type, which is a completely new class of workload, and then second, the actual bandwidth and the infrastructure itself to keep pace with the workloads as they, as they grow exponentially. Because we don't, we don't see any sort of growth pause. We just see growth, growth, growth, growth, growth, growth of the, of the, of the traffic in the workloads.

Speaker A: Sorry Satya.

Speaker C: Yeah, I mean you are right. I mean it's, it's like most organizations should uh, you know, start measuring the, you know, AI utilization and what all the uh, agents that we are running within the organization and you're right, like in terms of all the workloads that we have, it is somewhere making the performance and bringing the speed. But then again monitoring them is important for us.

Speaker A: Thank you. I think. Well, the point I was going to make, uh, I think it's going back to something you just said Paul, was I think there's a really interesting dilemma that comes out of the article but also leads us neatly onto the sort of the main topic for discussion today, which is we have a paradigm for this which is um, with cloud and the migration to cloud and the changes that, the technological changes that, that brought about. Um, therefore this isn't necessarily new news. Therefore the dilemma is if it's not new news and it's kind of an issue that we've dealt with before, why are so many businesses struggling with that readiness gap? Why are so many businesses struggling with this? And is it simply down to pace of change or other complexities as well?

Speaker B: I think there's two for sure. Pace of change and putting pressure on all parts of the IT stack all at the same time, 100%. But there's another element that we were really looking at closely and it's the governance side and the accountability. We think this is for sure, um, a juncture, uh, that is trembling right now. And this operating model is one that we think is for sure under pressure because uh, many of the points of accountability are spread across, they're spread across CISOs, they're spread across cross functional committees, uh, for short, even cio, um, responsibility. But what we found in our study was only 14% of uh, enterprises had somebody uniquely accountable for AI governance. So in a shared responsibility model it becomes uh, who's on first, you know, who owns it, right, who's going to govern it and lines of business or central security functions. And I think this probably more than anything past the technology creates those fissures, right. And those gaps uh, that of course attackers are very happy to exploit.

Speaker A: Right.

Speaker C: And uh, as Paul mentioned that it is about the governance side and making uh, sure that every of those controls that we can bring into our AI governance. And uh, very few organizations are actually 100% uh, compliant with uh, the requirement from the industry practices towards the AI, uh governance. And of course uh, since we are moving ahead, uh, bringing in all the possible solutions from AI, it's important to evolve as the risk is uh, going on a higher stage and talking about maybe the agents. How does the good AI agents or AI access control should look like? It should be more towards uh, bringing in kind of identity, uh, centric environment, uh, or maybe governance in place which helps us to understand okay, what's the uh, identity of the agent or what kind of a data this agent is trying to bring in and uh, then talking about what time this uh, requires a human interaction and uh, does this have the identities and the governance monitoring in place. So these are very, very important thing uh, that I believe every organization should be bringing in towards the leaders and accountable persons.

Speaker B: Satyam is such a good point. And the uh, current methods of uh, access and uh, authorization are being far outpaced by the capabilities of agents. Because when we think about non human identities, uh, and the problem that they create is that they're calling each other via API, they're calling each other via service accounts, they're using one token for multiple transactions. We've gone to this place of saying okay, well before we execute, let's put a human in the loop. I posit that is a system that is going to fail quickly. And the reason why is anytime that something executes cleanly or safely, the human's uh, stance lowers. It happens just as natural human behavior, ah, it's a risk reward. I'm super vigilant at the beginning because something bad might happen. Well nothing bad happened. Okay? So I'm not going to watch it as close, I'm not going to watch it as close and then all of a sudden we have something catastrophic happens. So I believe we're going to be moving much more to uh, an operating model that has more rigor versus less rigor because I don't believe that humans in the loop is sustainable at the scale and the pace that we're moving.

Speaker C: You're right. And um, as I mean this, this probably would be a you know, really hottest discussion coming, uh, you know, months because uh, we are talking about autonomous agents and whereas uh, we really bring in the governance and that's something which is important and then that this is how we are you know, talking about human identities and you know, uh, to see like you know, do the traditional monitoring or you know make sure that we have the controls in place and to be like very uh, you know, precise about those uh, autonomous agent. The real challenge is not about you know, one uh, kind of a chat GPD or any of other, the other model. It's more towards what data we are transitioning or maybe you know, triggering the workflows. Because right now every other automation that we have, it's through the APIs. And if those agents have the access towards the API and the token, it's always about the identities. You have the token as identity, what about the agent. So that's the concern part. And uh, talking about the uh, coming surge. So during the recent studies there has been like you know, a really huge surge in the creation of or generating the APIs, you know, in 20, 25 and 26, um, every other organization is now running after you know, having the API integration, bringing in tokens, you know, and that's a single token that works through most of all your SaaS. And that's uh, a concerning point for us.

Speaker B: It feels like we will move to um, a ah, control of first resort identity, non human identity and then a control plane of last resort meaning the network controls and the gateways and controlling the flows of what traffic can move through in the sensor. The control of the classification of data, uh, the movement of data and the encryption of data like along there. Because the APIs are going to fly like lightning bolts, you know, across those control planes.

Speaker C: You're right. And since uh, you know the AI has already taken the picture in that place, uh into the architecture where it is just not you know, answering the questions to people and uh, it is more taking the actions, creating tickets or you know, uh, doing the authentications, using your token to your APIs and getting the direct production access. So it's always bringing in the unified governance as well as unified security architecture towards our AI. And uh, since we are talking about bringing in controls, we need to first have the unified policy that talks about the driven architecture.

Speaker A: I think Paul, to your point as well about the pace of change and how do these control measures actually work? I think there's A really sort of interesting, almost contradiction in the way I articulate it is how does a human in the loop work at machine speed?

Speaker B: This is it. We cannot. Right. We're not tuned to operate at machine speed. And so the point I think Satya makes is very poignant because the architecture itself has to envelop or encompass the new working paradigm, which is very different from what it was built for. Um, perimeters, uh, layers of perimeters, defense in depth and client to server type of applications. Uh, that world has to be retrofit in real time, uh, as we address these new workflows. The point is, where do we get our arms around it? We talked about visibility, but at the end of the day, these workloads are happening as we speak speak. We believe, like right now, it's all about runtime, right? Everything is going to execute at runtime and if you detect something, it's far too late. So we need to be focused on prevention in runtime, against the operating model, against the policy with the governance. Now, naturally people are going to say, good, give me a tool and give me a product, uh, to do that. I don't believe that's possible. I think that every product, every part of the architecture needs to be geared, um, or retrofit to detect things at runtime. Whether that's a copilot acting in an inbox, uh, and reading obfuscated, uh, prompts, uh, that are not visible to a human, whether that's through an Ah, AppSec stack, uh, and calling APIs that are fronted through a web application firewall. Um, all of these points of interaction at runtime is where I believe the focus needs to be, because this is where the point of exfiltration, uh, will surely happen.

Speaker A: Hendrik makes a very good point in the chat. Uh, the problem is that governance comes on the scene too long after many organizations have jumped into AI. Same as in the beginning days of moving to the cloud, but much stronger. So what do you guys think about that,

Speaker B: Satyam? I'll let you jump in and then,

Speaker C: uh, sorry, I mean, my Internet got frozen, so lost for one minute.

Speaker A: No worries.

Speaker C: Okay.

Speaker B: Yeah, yeah. So Hendrik makes a really good point. Um, because the governance is coming onto the scene longer, uh, or after the implementations are happening. We see it in the data. 70% of organizations are already launching AI applications and or strategies. Um, and so the governance has to catch up, there's no question about it. Uh, which means that, uh, we are absolutely in a new operating paradigm between the operators, the integrators, the vendors, uh, have to come together in a way that we never have before. Uh, we're seeing this much more with our customers. From a design partnership standpoint, there's no longer show up and pitch, we select and go. This is in the room on the whiteboard, full architectural discussion about what our workloads happening now and what can the existing tool set be modified quickly. And this is where I went to the runtime sort of paradigm. Um, and where is your future going and how are you using AI, uh to help govern and fight AI uh is critically important. So Hendrik, I think his point is right on. And it will require a pace of partnership, uh, that we're experienced. Cybersecurity has always been about the community. It's always been about the relationship between operators, integrators, uh, and vendors. Uh, that's going to be heightened, uh, even more so I think this is an opportunity for the industry to, to step up and shine. Uh, we've done it before. It's, it's, it's now time for us to, to do it again, but at uh, a much quicker pace.

Speaker C: Right. I mean. Right. And I, I totally agree on the architecture side. It's, it's towards you know, having the security controls, you know, in place and making sure all the visibilities are there and making uh, the policies are created. We are able to vet our vendors and all the other APIs and then design the security architecture. So every other organization would like to get out of uh, the 5% what we have as in the AI governance and they also would like to bring in the controls. So in order to do that they would need to talk about the Security 2.0 architecture and that would be, you know, bringing in all the solution that we, you know, used to say like back 20 years ago, like you know, talking about ids, then there was ips, you know, got introduced then similarly the AI is something which is new it risk and uh, we need to have the entire monitoring and the detections in place. And this is something where the Security 2.0 Unified Security architecture comes in and uh, every other organization should be bringing in the DLPs, should be talking about you know, the, the CASBs towards uh, the SaaS or um, you can say bringing in identities for the agents that are actually talking in our production environment.

Speaker A: I think as an interesting and potentially quite provocative comment, uh, from the chat, ADE says surely emphasis should be on the vendors to ensure that appropriate checkpoints are embedded in any AI product. Now I think that's a really interesting push to vendors and I Think perhaps springboards off your point Paul. About Actually this needs to be a uh, sort of an ecosystem solution rather than an um, individual entity solution.

Speaker B: Spot on observation by Addie. And of course you know we are doing exactly that. Um, but there's an interesting twist to this new operating model. You know the AI is the LLMs themselves are not deterministic which creates a really unique problem because you can put guardrails in, you can guard the system prompts, you can um, put runtime protections in. But there may be uh, a point where an LLM decides I'm going to return uh, something against the policies. Now of course every day the fidelity of the runtime controls are getting better. But um, the domain of exploit uh, is not computer science anymore and Python code, right? The domain now is natural language. And so if natural language is the code, um, we know that we have no bounds, right? Because it's only bound by the limits of human creativity which we know has no limits. Uh, and so absolutely Adi, this is a point that everybody that in the industry that I know, friends that are at checkpoint and outside of checkpoint are absolutely focused on making sure that everything we put in place uses AI, uh, uses machine learning algorithms, uses pattern recognition for this new workload and identity federation 100%. Uh, but we should acknowledge that this operating model has shifted from code to language. Uh and it's in the language then that presents one all the possibilities and the breakthroughs of productivity that we couldn't have imagined but presents a very very complex uh security problem for us.

Speaker C: You are right, yeah, I mean certainly it's towards uh the data and uh, since uh, we always talk about data classification and uh, when we say uh, maybe HR data is something which is classified as confidential, we should always be talking about uh, whether the data that uh, AI agent or maybe my API or any copilot is going to be accessing that should also be having the list within our data confidentiality or classification policy. As we take ah, every log and uh, take the tokens and the identities of the human who tries to access the data. Similarly there should be the identities that we should be bringing in. And once we have the identities and the, and the visibility towards all those agents or API then certainly a SIM can actually give us a broader view towards uh, bringing any of the event investigations.

Speaker A: So it's, I mean I think what we're, we're talking that then is about moving beyond sort of this idea of just having sort of policy and a whole set of tooling and things like that is there needs to be a very holistic response. And I think this, this harks back to a point you made earlier in the conversation Paul is that and uh, indeed was pointed out in the NCSC article is that this is now AI implementation is now becoming an issue for every business function. Not just and forgive the air quotes but an IT problem. It's actually everybody is, it's now front of mind for everybody and I think this is speaking satnam to your uh, suggestion that we have to look at the governance first and we have to get the governance right across the piece.

Speaker B: One for sure that we know of uh is the truth is that if the promise of productivity uh is real and the experience of initial gains of productivity are also real that any sort of guardrail, guardrail or governance or control to prevent people from using that productivity is going to be uh, attempted to be circumvented at every turn. Uh so we know that to your point Jonathan, this won't stay in it. It's not in it. Marketers, uh, salespeople, financial analysts, uh, accounting, any function could get a material gain from using AI enabled applications. We should accept uh, that the usage uh is going to be vigorous and the testing of the controls is going to be vigorous as well. Uh so it brings us sort of full circle back to accepting that this cannot uh be stopped or slowed down. The promise is too great uh, and our approach then needs to fundamentally change as well.

Speaker C: Right Paul? And as you said it's not about it. I would like to maybe keep my points uh over here and say AI is becoming new it and this is something that we should be talking about that these controls that we used to have for IT, now we need to have for our AI systems and every other system that we are talking that we have within our organization has AI inbuilt already and we uh need to maybe classify which of the AI should be having what access and the objective to actually bring in those AI capabilities so as to protect the IT, to have the security in place. We talk about iam, DLP or uh, EDR or maybe like application firewall or maybe like cspm then we have sims or in place similarly for, for AI we need to bring in place not now, but maybe in very soon you will be hearing that there would be you know things coming in similarly as we have there would be a new EDR that would be only for, for, for the AI models and all those things similarly which is a need for IT nowadays. So talking about the controls it requires to. Because every other function within Our business is of course talking about AI integration and like taking the leverage and different models to actually speed up the work or you know have the automations in place. But we need to bring in the controls, the governance and that's a very key important part because if one, one prompt can actually give you the accessibility and the speed, one prompt can also you know malform the entire model right and can actually put uh, a entire industry or business into the risk.

Speaker B: There's a, not to get too too in the weeds Jonathan, or too technical but um, you know the fundamental protocols uh that we use to build applications uh are also undergoing uh, an evolution revolution maybe. Um, you know traditionally we built on tcp, IP stack, uh and leverage UDP and well known services, uh HTTP, HTTPs for transport, tls, things of this nature. Um but we start to see as Satyam indicated with non human identity that whole classes of authentication protocols are also not sufficient. Uh so there's a tremendous amount of research and work going into uh, the protocols that are going to govern agent to agent uh builds as well as non human identity access authorization protocols. Um and so there's a lot of, and even networking protocols like ebpf, uh to catch things even earlier in the stack. And so like right now even the underlying fundamental building blocks uh ah have been put under pressure and are changing and we're seeing a tremendous amount of innovation come from the research community as well to uh, allow us to do the things that we need to do with identifying data, with uh, verifying data. Um Hendrik put in the chat around ah hallucinations, three pennies if you could say that fast. Uh but uh, this is also a whole class of how do we verify actual fidelity of data itself. So um, this is an exciting time because anytime that the actual foundational protocols are undergoing this amount of innovation we always see uh, at least in our arc so far we see a tremendous amount of breakthrough uh in how we operate.

Speaker C: Right.

Speaker A: I think it's really um, you talk about sort of fidelity of data because I think I read an article a couple of months ago that was ah, ah a piece of research that's been done over the last couple of years was looking at how little it takes to actually poison data sources. If so if there is malicious intent or indeed even if it's done accidentally and therefore I think when we're talking about um, fidelity of data, validity of data, integrity of data, all of these kind of things around actually this, that we are using as our single source of truth for all of these agents to look at and to give us that kind of business intelligence. Um, is that part and parcel of the governance process now? Is that actually we have to scrutinize our data even more thoroughly than we may have done before.

Speaker B: 100%. 100%. Like a third of our respondents also indicated that they're already seeing um, attacks they can attribute to AI. Uh and that third that they identified was phishing, advanced phishing using AI, uh and deepfakes. Uh so if we're early in seeing these attacks we're going to see more of them. Uh and so um, there's good work underway right now to identify deepfakes and advanced phishing um through existing modalities of looking at uh, emails and demarcation and things like that. So we can reuse some of those techniques. But it will be a fundamental piece of uh, a new class of security control to verify the image, verify the audio, verify the video, that it is in fact not AI uh generated and it's not a deep fake. Uh, it's a whole new class of uh attack and defense.

Speaker C: Right. Certainly it comes with of course pros and cons. So like offensive security team are uh, always utilizing these models sorry for different uh, you know cases. And uh, in the case of uh any red team they, they would gonna certainly you know develop the, the malware to maybe bypass their internal controls or try to you know see if the, the EDR which is very fancy with the name can be actually bypassed. And uh, we, we have actually the similar you know challenges and uh, we executed it same at our uh organization where we were able to bypass a really huge well known EDR by the help of advanced AI level offensive things that we can create. And since it comes with pros and the cons and uh, you can always leverage uh the models which are approved and you can get the application approved from Anthropic under CVP which is their verified program. And uh, you know develop such kind of uh, offensive material that can help your organization to validate the controls, validate whether we have these really huge names, what are they really working in the background. And uh, the governance that we are talking that comes from the control. We can, we can seriously have everything over the paper when it comes to the reality. There should be a reality check that we can do with the help of advanced AI level models that gives you the ability to get into the offensive as well as defensive side.

Speaker A: I think um, just jumping off another point that was in the chat there. Do we feel that the ever growing list of um, sort of territorial and global um, AI governance is actually going to help. So things like the sort of ISO, IEC 42001, the EEC, AI act, um, other moves, OECD, UNESCO. Thank you to Hendrik for listing those off in the chat. Um, do we think that that's actually going to be really, really helpful in not only sort of raising this level of general awareness across organizations and certainly at board level, but generally getting that buy in and implementation across the piece?

Speaker B: I believe so. I mean anytime there's been a marriage between um, compliance policy, uh and technology we've seen a gain and some of those things have um, endured. I think of uh, the OWASP top 10. When we first started the top 10 of OWASP it was very much focused on applications uh, and compliance against that. And people use that as a benchmark and a framework. And even now we have the top 10 Olas for AI, uh, and things like GDPR, uh, things like NIST, they give us at least baseline to say okay, uh, are we applying best practices and assurance and the more researchers that we have involved and I think that's a really great lesson we've learned as a community over the last couple decades is that the formation of uh, vendors, researchers and policymakers coming together uh, generates something that's relevant, timely, uh, and benchmarkable, if that's a word, benchmarkable. Uh, but it does, it does give us, you know, it does give us ah, an advantage um, so that we're all operating in at least speaking the same collective uh, you know, technical language, you know, your language of choice. But you know, at least it gives us that um, solid framework um to benchmark ourselves. I think benchmarks are hugely important.

Speaker C: Right, you're right, I completely agree on this case because uh, you know, since it's a board level responsibility to actually now bring in the AI governance and uh, sort of like every other compliance that we are talking about is bringing, bringing in the AI controls and uh, the requirements in place which needs to be you know bring like governed and as per a part of the security architecture every of those principle needs to be enforced from, from the compliance side. And if we see like there are compliances who actually you know has enforced Red Team exercises and there are, there are compliances who has restricted the entire use of gen AI models. So SOX is one of them and uh, there, there are, there are NIS 2 and Dora that talks about the 100% red team mandate control requirement. Similarly there would be every other data framework that uh, every other security framework that we are Talking about will be bringing in all sort of validation controls and the enforcement in place.

Speaker A: So I mean it seems then that what we're saying is over the course of the conversation is global or territorial, um, regulations and legislation can be obviously helpful and can change hearts and minds. It can help us embed things a little bit more simply. Um, in terms I'd be interested just sort of as we're moving towards the close of the conversation just talk a little bit more about this kind of unified idea of how we're going to apply all of these things

Speaker C: towards uh, the security, I mean unified security architecture. As I mentioned I see it more towards a new IT and uh, a new IT risk. So we should be talking about the controls from all aspects from our iam or to have the data loss prevention or to have the entire you know, monitoring as your, you know like any of the other system or the EDR is doing. And then similarly there should be one centralized dashboard that can give us the visibility and see like what this agent is trying to access and what this agent is being processing from my environment. And this is something that is being going to be required like very, very soon to have the you know, user centric and the identity especially for the agents to see like what data identity or maybe action identity this specific agent has done.

Speaker B: I think that's spot on. And there's um, there's also this move that, that we're, you know, that we are very much encouraging. Um you know at checkpoint is this concept of an open garden, M versus a closed garden. Because for many years I believe we put the work of systems integration into our collective customers hands. Uh and we simply can't do that anymore. The pace of change is too fast. Uh, and so we really are moving from a value of awareness being diminished uh versus the value of action. Right. Whether it's remediation that takes place across the platform, it may be observed in product A, but it's going to be remediated in product C. And product C may not be one that you sell as a vendor, um, and that's okay. And that recognition that we are not um, psychologically a community, but actually in pragmatic terms a community of prevention, of security, of control, uh is one that we fully endorse. We made specific moves to uh, go beyond just information and trading logs but saying what can we do via API if we observe something happening as a critical vulnerability? We can essentially create uh, time for a full remediation by implementing a compensating control at the network layer at the AppSec layer at the endpoint layer. Uh, and I think we'll see much more of this coming in the vendor community. We're very happy to be, uh, leading in this area and we're constantly looking for uh, partners who will join in on uh, trying to really deliver that. One plus one equals three for the industry.

Speaker A: I think it's a refreshing kind of approach in an industry which is quite understandably for many years being extremely competitive and extremely cutthroat. The idea of this across the piece, integration and collaboration is something, it's a bit of a, uh, brave new world, I think, for a lot of vendors. But certainly to your point, I think it's something that we're all going to have to embrace, uh, a lot more. Um, I am very, very conscious of time and unfortunately time has caught up with this gentleman. But on that note, what I would like you to do is I'm going to ask you a simple question which I'm going to give you each a minute to talk about before we wrap things up, which is what's the one thing that you would advise, uh, our uh, listeners in today that they can do practically tomorrow that is going to make the first step on the road towards this new redesign. Paul, if I can come to you.

Speaker B: Sure. One minute. Okay. Uh, zoom out to zoom in, meaning first, zoom out and understand first and gain visibility of what AI is happening within your organization. Uh, and uh, don't leave any stone unturned because I fundamentally believe you will be surprised at where AI is happening within your organization. Uh, and then start looking at what is in the existing tool stack that can help you govern and control what is already happening. Then meet with your partners and say where is this going and what capabilities do you have and how can you help me take this step into the new future? Sachin? Go for it.

Speaker C: Right. And um, as well said by Paul, uh, it's, it's always about, you know, the controls and the uh, AI agents monitoring. So if I could recommend maybe the one thing um, that you can do as uh, the organization maybe from tomorrow morning, is to have the entire list of inventory of all the AI tools or maybe the AI agents or any integration that you have done within your involvement of production and any, any machine that leverage the AI to run that should have the identity and uh, it's very, very much, uh, you know, pretty clear that uh, you cannot, uh, you know, govern anything that you cannot see. So visibility is something that, that is a foundation of the AI security. As similarly we have the risk coming in uh, to. To AI and the it. So I would going to say like every, every AI, uh, agent that that should be there within our environment, should be having one identity, should be, you know, logged within our inventory and should be having one owner and the scope and objective of all the, you know, scope that IT can actually do, along with the audit trails.

Speaker A: Lovely, thank you. I think that's a great closing remark for everybody to go away is sort out that AI tooling inventory tomorrow. And I can almost hear the groans on the other end already knowing how many AI tools most organizations are currently using, whether they know about it or not. Gentlemen, um, thank you both so much for your time, so much for your insights. It's m. Been a fascinating conversation, I'm sure. I hope you've enjoyed it as much as I have and I hope you listening in, have enjoyed it as much as well, uh, too. Um, uh, it just remains for me to take a quick scroll through all of the chat that's gone on this afternoon and say, I think, uh, I think Hendrik's, uh, comment with regards to, uh, all of the government stuff, because that happens to be close to my heart in terms of governance and risk and compliance. Um, I'm going to go with Hendrik. So congratulations, Hendrik. Mug is on the way to you. Well done. Uh, and, um, thank you, Paul. Thank you, Satnam. Um, we, uh, join Tom next week for evolving identity and fraud models beyond human only assumptions. That promises to be another fascinating conversation. Um, and from me, let's keep talking. Thank you very much.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • When AI Stops Assisting And Starts ActingAI Proving Ground Podcast · on Non-human identity governance90 / 100
  • The Weakest Link in a Global Life Sciences Company? People. With Dr. Kevin JonesCyber Leaders · on DevSecOps88 / 100
  • Contextual Transparency - S2 E10Frankly, By Design · on DevSecOps85 / 100
  • Crown Jewels In, Crown Jewels Out - The Hidden Risk of AI with Devan Shah (IBM)ShipTalk · on DevSecOps82 / 100
  • Ep 11. Valence Security on SaaS-to-SaaS Mesh, Shadow Integrations and Generative AIGenealogy of Cybersecurity - Startup Podcast · on CASB (Cloud Access Security Broker)82 / 100
  • 117. Infrastructure at the Edge of Everywhere with Armada, Microsoft, and DISAAll Quiet on the Second Front · on DevSecOps81 / 100

More from teissPodcast

All episodes →
  • teissTalk: From manual triage to machine‑speed investigations - the rise of the Agentic SOC
  • teissTalk: Navigating cloud transformation and IT/OT convergence in CNI
  • teissTalk: Measuring the return on security investments for Cyber-Physical Systems
  • teissTalk: Quantifying emerging cyber risks from AI and quantum
  • teissTalk: Leading your cyber defence in an era of AI-driven ransomware extortion
Explore the best B2B Engineering & DevTools podcasts →
All teissPodcast episodes →