Go back

Evo AU #185 - AI vs Cybercrime Who's Winning in the Next Arms Race

62m 5s

Evo AU #185 - AI vs Cybercrime  Who's Winning in the Next Arms Race

The podcast discussion focuses on the evolving arms race between AI and cybercrime. Experts note that AI is empowering cybercriminals through tools like deepfakes and AI-generated phishing, making attacks more convincing and scalable. This lowers the entry barrier for threat actors, potentially increasing the volume and sophistication of threats like ransomware. Defensively, organizations struggle with architectural weaknesses, third-party risks, and lack of governance around AI tools such as Copilot, which can inadvertently expose data. In Security Operations Centers (SOCs), AI can significantly reduce noise and enhance analyst efficiency by correlating events and automating responses, but its success depends on correct implementation and guardrails to prevent misuse or hallucinations. The consensus is that while AI offers defensive advantages, the offensive capabilities are advancing more rapidly, urging leaders to adopt holistic strategies like zero trust, supply chain security, and context-aware controls to manage the escalating threat landscape effectively.

Transcription

10783 Words, 58246 Characters

English
Welcome to the Evolution Exchange Podcast, where technology meets leadership. This is a space for sharing fresh ideas, real experiences and practical insights from some of the market's most accomplished technology leaders. Our conversations aim to inspire, challenge and connect, giving you perspectives you can take back into your own journey. Please note, the views shared by our guests are their own and do not necessarily reflect those of their organisations. Welcome back to the Evolution Exchange, I'm Joel Hayward from Evolution Recruitment Australia. Today we're tackling what I think is one of the hottest topics in the market right now, AI versus cybercrime, who's winning in the next arms race. Today we have four brilliant guests, Shady Sultan, security operations lead as smart group cooperation, Mayank Vias, senior security architect at the missing link, Sanjay Sharma, infrastructure and security manager at GSN and Victor Babescu, head of cyber across APAC at FNCIS. Gentlemen it's great to have you all on today, if you could start with some warm introductions of who you are, what you do, and maybe one thing that you'll passionate about in your work or life right now, that would be great, Shady, start with you sir. So I'll start off, I'm Shady Sultan on the Subscurity Operations Lead at Smart Group. I've got over a decade of experience in subscurity, I specialize in cloud identity and enterprise environments, focusing on financial sector and health sector. My day-to-day is I deal with Microsoft Sentinel for my SOC, Defender and dealing with anything subscurity related to the company, security architecture, leading the incident management. Fun fact about myself is I used to be a bouncer and then now I've transitioned into the bouncer of digital security, so cybersecurity, so keeping the bad actors out and protecting what matters to the business, so yeah, that's me. Shady, I also used to work as a bouncer when I was 19 to 22 back in Liverpool in the UK, so I know they eat the fun and games that come with that. Oh, listen, Mayank, have a tea, sir? Hi, everyone, this is Mayank. I am a senior security architect with the missing link, being in the cybersecurity and network security space for a little over 15 years. I specialize in the cloud security and sassy space along with the GRC component associated with it. Looking forward to have this discussion on this topic, which I feel is really important and probably critical in the upcoming few years, because pretty much the whole cybersecurity industry depends on that, so yeah, that's a pre-forward question. Thanks, Mayank. Hey, all this is Sanjay Sharma, I work for black box as an infrastructure and security consultant. I take care of the pre-sales as well as the platform. What I'm passionate about is the cybersecurity, how it's tackling and keeping the hackers and keeping the space secure from the attacks. Thank you. Thank you, Sanjay. I'll ask a lot of these Victor. Thank you, Joe. I run the cybersecurity consulting business and infrastructure consulting, so I'll look basically after all of AsiaPak, which is quite interesting that it's a geographical region because you can see different types of materials. When it comes to security across Southeast Asia, in particular, across ANZ, where I would probably just like delineate Australia and New Zealand into slightly different patches, as part of the day to day, one of the things that keeps me passionate because spending like over two decades now, basically, in security and consulting and IT advising, more broadly, is always like solving problem statements or very unique problem statements that always have like a big impact, specifically for customers when it comes to technology simplification, when it comes to two proliferation, when it comes to zero trust, when it comes to identity simplicity, right? So it's basically across the board game, and this is one of the reasons why I think that this conversation now, in terms of figuring out where security is positioning itself, when it comes to AI where it basically can swing on both sides of the equations, actually so topical and so let's say impactful for basically the whole corporate landscape. Thank you, Victor. So yeah, I think we've got four complimentary lenses here today, you know, set-ups, architecture, platforms, and enterprise side leadership, which is great. So each of you has brought a thought-provoking question to the table today. I think Victor, we'll start with you across the landscape and economy of attack. So your question was, with AI and cybercrime as a service accelerating, how was the actual threat to landscape changed in the last 12 months, and what's coming next that leaders are not purchasing for, which I thought are not, Victor. Look, I think it's a very interesting one because the cyber threat actors that we've been dealing with actually for quite some time, they have been using different types of call it paradigms of hyper automation, may this be a lot of them, may this be any kind of AI, Gen AI, whatever you want to be labeling it, right? But they've been using this for actually quite some time. Now that basically called it the corporate sector has actually started to catch up with it since chat GPD basically saw the light of the world. Basically people start to figure out in terms of what are some of the paradigms and some of the methodologies that at least cyber threat actors are actually utilizing because on, let's say customer and organization side, it was always like, I just see that the threat activity is just like gradually increasing. I just see that I'm just getting bombarded with business email compromise. I see I'm getting bombarded with like DDS attacks, I see I'm getting compromised or bombarded with basically any kind of malware attacks and similar. So it was like, I think there is more awareness now in the corporate sector of what cyber threat actors are actually utilizing and how they actually they're going off the deal operations. I think what we'll see now, at least over the next probably 12 to 18 months is that the business case for actually becoming a cyber threat actor is just going to be improving right on let's say cyber threat actor side because all of a sudden you will see that it's going to be so much easier now in order to launch a ransomware campaign or to launch a DUS campaign or basically to compromise multiple different types of organizations at scale. So basically what now the question is going to be how will organizations be in a position to defend themselves against this or to change their narrative to say, I may not necessarily be in a position from the very beginning to defend myself against the gazillion millions of threats that are basically will be encountering on a day-to-day basis, but how can actually reduce this to hold as an ecosystem that I will be comfortable managing because I have the right to defend some place and I have the right let's say process it or automation to do defense or to basically just do a threat detection in response. I feel like that is probably where the industry now over the next 12 to 18 months potentially might actually be trending. Awesome. Thank you very much Victor. Yeah. Should any thoughts or not? Yeah, so I kind of agree with what Victor said, but I kind of want to put a different lens to it. Yeah. In the last 12 months, we've seen a lot more of the actors using AI. So I've been involved in some incidents where they're trying to use FaceTime, they're trying to use WhatsApp calls and they're using deepfakes trying to impersonate CEOs and calling new staff that join businesses from LinkedIn scraping. So they're using AI as a service to make it easier for them to get to the users. Now these days, the three actors don't even need to know how to script. They're getting LLM models to show them how to script and Lua and you're basic, you know, phishing MLs that used to come through was all checking for grammar mistakes. But now these days, they're fixing this and they're changing their tones. So I think that's one side. The other side of it is AI itself is now becoming the attack service. And for it to be the attack service is, we need to look at how can we understand what's the use for the business and the guard roles we need to put in place to try and protect it. So what the things that come to mind for me is looking at either using MCP or A to A with those controls. Looking at so back in the days, it used to be or when AI came with chat GPT. It came with prompt engineering, but now there's a new lens of how to protect protect it, which is now called context engineering to prevent data leakage, red teaming prompts. Yeah. So that's my view is trying to increase the guard roles because you're seeing more and more where people are just, you know, in chat bots on random websites. They're injecting certain codes and commands and getting the bot itself has access to certain systems to go through and use different agents to do different actions. So I think as a business budget sometimes is not always there, but we're just trying to see what we can do with the budget and the technology we have to put the guard roles up to enable the business to push forward with, you know, delivering new technology, but at the same time enabling them and securing them. Yeah. Thanks for that, Shoddy. Sanjay, are you seeing the same sort of patterns in your space? Well, yes, definitely. I think, you know, I don't know, I don't know, at this point regarding the defects was creating a video or creating a picture used to be a tedious task where it was a recourse prohibitive. It would take, you know, maybe say weeks for you to generate a proper video. Nowadays it has become very simple with just couple of prompts and some engineering may be couple of hours, you would be able to generate big videos. Now how that is impacting cyber is in terms of we when we go out there and you know, can our users cause usually in cyber, we say, you know, the human is the weakest link out there for the cyber, but we are training them for is you know, you need to verify who are you going to verify when the deep fix the video itself, you will not be able to distinguish between a real person and the video, you know, so that is where the lines are blurry. Still, I think it has got some time to be still you can distinguish between, you know, our deep fake or robotic because there is a bit of a pause in terms of the voice, the the videos are not that good quality, but I think the lines are blurring in some time we would see where it will be really difficult to distinguish between a real person and a deep fake that has been generated through the AI. So yes, the lines are, you know, that that is increasing on the the access service. And also in terms of yes, definitely and also in terms of the blind, blind spots, you know, for the business, what I see is in terms of the supply chain, you know, and the third party air risk, specifically as an enterprise from our perspective, we will put in the safeguard students to some compliance parameters, the islamist programs to save our hours, our things, but now it is the supply chain. A lot of attacks are coming through your third parties. So that also has to be taken care of. Your third party control mechanisms needs to be strengthened on top of that. I believe the insurance industry, the insurance and regulatory, you know, those gaps are still there. Those needs to improve so that overall, you know, the posture or the security of what the enterprises can be taken care of. Thanks, Andrew. Yeah, it's funny just going back to the deep fake and voice cloning aspects of AI. I was listening to a song a couple of weeks ago on Spotify, right? And the the artist is called Nick Hussles. I was listening to it and I was thinking this is amazing. This sounds like, you know, Sam Cook asks, can I hear an amazing voice? What not? I was like, right, Nick Hussles, I've never heard of it. I googled it and it was an AI artist. I was blown away by the fact that this was created this year in 2025. And the music, everything was just perfect, which is scary, right? So you don't know what's going around the corner if you're an artist. But yeah, my aunt, is there any sort of architecture debt that makes these AI driven attacks, especially costly, you think? Yeah, so first of all, I kind of agree, particularly with what Shaddeans and J has mentioned over there with the amount of all these deep fakes and the way the phishing emails and all these specific components have become so tricky to be identified. It's no longer just your usual, okay, there is a grammatical error or there is a way, they are going to a different link altogether. It's no longer the case. It has become much more challenging to detect them. What I do see apart from that, and I feel like that's also an area of, that's also an area where organization should focus and probably should think about from a budgeting perspective as well, there is a couple of areas. One, the reliance on so many third party tools. So at this point of time, in any organization, we use so many tools, right? And then co-bilot can be a very good example, pretty much every Microsoft, every organization who has Microsoft 365 e362d license is using co-pilot, right? It's a fantastic tool, it works really well, it integrates with all your Microsoft applications. And then there is a good, like users are relying on it as well, which is, nothing is bad. It can summarize your emails, it can summarize your calendar, it can start booking things out for you, all of that is good. However, what I see a particular challenge is, there is no, and I won't say no, but there is a lot that needs to be done in terms of governance. What's the inherent risk that needs to be understood at the organization's level, and then that needs to be clarified and users needs to be educated. So again, we all say in cybersecurity space, it's always people and processes. So people, and it comes to people, humanized factor, as Sanjit mentioned, we have to educate them, what needs to be shared, what not need to be shared with them. Yes, Microsoft says that in their towns and conditions and everywhere that we don't use this data for training and metadata and all, but the fact that you're giving the control to an automated system to perform a lot of things is not bad in general, but again, you're kind of losing the control if you look at it like this. Just going back a few months ago, we had an attack where the AI chat board, which is a legitimate chat board, they paid for it, and an organization was using it, they summarized an email, they identified one of the S3 buckets which has publicly exposed, which has a public exposure, and then they got the data out from there. So it is like, yeah, so from a governance perspective, that's definitely a field which we all should be looking at. And on the same lines, I feel that the organizations should start looking at it from a budget point of view. They are paying a lot for all these components, but at the same time, I feel like on the security and the rest side of it, there is a lot that needs to be done. And probably in the near future, we will all start working on towards that. Yeah, thanks very much, brilliant. So it certainly sounds like the attackers' unit economics are improving. Let's talk about whether the SOC can keep pace and shudder your question next. Will AI create more noise in the SOC, or will it finally reduce it to something a lean team can manage? Shudder, what's your thoughts on that? It's actually a great question. I think it can go both ways. So simply, if you simply just drop AI in a noisy SOC, all you'll get is to summarize events. And there's a difference between how you design it and how you govern it. So if you really embed AI properly, you'll start to see an example I'm going to use is Sentinel and XER, just for this scenario. But what I've seen is Microsoft Sentinel and XER actually reduce noise because it tries to piece through AI detection, understanding what the behavior is doing and trying to create a baseline. So it stitches 15 to 20 events together into one event. So there, it summarizes and tries to give a view for the three analysts to understand what's happening across the endpoints. What's happening across the user identity and its stitches are all into one email for an incident. Now, Sentinel co-pilot doesn't just summarize alerts. It actually helps the analyst with their role and basically helps them create through hunting queries, create KQL queries to try and stitch together the context of the engineering, which I believe is critical. So it's a tool to help reduce noise if set up correctly and to help analysts focus on what's real and to do that. So there are some risks that I see as well. So if it's not, you don't put proper guardrails, AI can be misused or can even hallucinate. And hallucination I think is one real big thing with AI because if you don't give it the right prompt or it tries to learn and understand the wrong thing, you're going to be going down a large rabbit hole and usually with SOC, it's time sensitive. So if they spend a lot of time going down the wrong rabbit hole, it could open up the business to big security risks. This is why I think using tools like MCP, Brokering Style or A to A to try get the AI to use the right AI agents to log action, use playbooks to know which playbook to initiate and moving forward. So with that, you can go from spending an hour looking at an incident to sometime even seconds and working and doing that. So yeah, it can really work both ways. And what I usually say is the future is SOC won't get bigger. It will become leaner and faster, but assisted with AI. But humans are still there to make the final decision or efficient. Victor, what's your take on that? I think that raises a very, very interesting point around how to actually use AI in a proper way, because at this point in time, right, the lens came with that that's not necessarily something that is applicable only to security, but every one of us would have a complexity, chat, GPT, and the usual. And you see that there is an efficiency game because like Charlie mentioned, right? The threat analyst will be supported because all of a sudden just can summarise or enrich different events, right? They can just group or cluster stuff together. So you'll see that there is an uptake in terms of your personal efficiency. On the threat attacker side, however, you see this efficiency is not necessary by the factor of, let's say, 20% increase or increase or 40% increase. It's going to be by a percentage of like 203, 100, 500% increase. And why? Because their tools are significantly more discrete and they know how to materialize effectively on it. And this is something that will haunt us or to speak at least in the private sector, because the question is then going to be how do I actually manage in order to keep up with the way how the cyber threat landscape is evolving, where those attacks are from moving, but then Charlie's nodding because obviously being in set-up scene, he knows this and he feels the pain, right? When you basically are not exposed necessarily to 10 or 15, for example, potential compromises or potential security incidents on a daily basis, but where you actually get into the 500, the 800, the 1000 mark territory on a per day basis. So I feel like that is probably what we need to sit down at least. And this are some of the conversations that I have with clients that are all originating towards. I bought a tool. That tool has a nine AI within it. How can I use this properly? Right? And to Charlie's point, right? You need some sort of an integration or cohesive integration layer until you basically build that security fabric that will help you across the entire tool trend. Because then by the end of the day, what you see from different vendors at the moment is everyone is putting AI front, left and center into basically whatever their tool of choice is. May this be supporting instant response? May this be supporting the sock? May this be supporting GRC or security architecture? But nothing is really cohesive. And that is for something like MCP or A2A or similar protocols where it comes to exchanging that level of context in between. All of a sudden becomes a new frontier because that's going to be your level of intelligence or your level of your point of view. The challenge with that is going to be context hacking is basically then going to be like the next point of it because somebody will then actually try to compromise that level of context in order to basically proliferate your entire tool to it. So it is always an arms race and it's always going to be like a conundrum because once you start to figure out the new paradigm in terms of securing not only infrastructure but your organization, then all of a sudden somebody will try to see how can actually plug the holes or at least as they explode vulnerabilities within this. So it's it's an interesting time in the market at least. Yeah, I love that Victor. Thank you. Just a quick question to you as well Victor. What do you think one metric is that tells you the AI is helping and not hurting is it false positive rate is it cases per analyst is it taking so open percentage what do you think? I think it's always hard to say but I think one of the ones that we actually see is just like the amount of activity in a short period of time right because this is something and Shari will probably be closer to this especially on a day-to-day basis but generally what we see is it's the amount of activity that you see and basically how let's say cyberclutching can actually be executed right because the way how cyber threats or let's say AI assisted or AI led cyber threats are actually evolving. You see that if you drop any kind of threat or any kind of malware for example into an environment may this even be air gap or similar it starts to make autonomous decisions and those decisions the time span actually shortens because your threat basically will know or will have the right paradigms in terms of how to pivot or how to move literally or how to compromise and say in vulnerable system or anything of that nature your decision trees pretty much matched up and that is basically what you see this is something that otherwise until you if you have for example somebody who's on the cyber threat exercise until they actually connect those dots and make those meaningful decisions the time spend just increases so I feel like time is always an interesting one happy to see what Shari has to say or what his thoughts are because obviously he's dealing with this on a constant daily basis. Yeah so exactly what you've said you know it's really you know you can get thousands and sometimes hundreds of thousands come through to a scene and what happens is sock analyst become a alert fatigue and part of alert fatigue is it takes just one incident that can make a proper big you know crisis so utilizing what we usually do is we look in what comes through and then how fast or how the business or the analyst come to a decision to either remediate or to classify it so we look at it as in numbers in and to numbers or how it's being remediated so that's how that's how I look at measuring this but at the end of the day you know some days it can be you got one thousand and some days it can be hundreds of thousands if you're being targeted and he's just really trying to help the sock analyst from being having the alert fatigue and to make the right decisions because you know let's say you're going on a long drive with your family and it's a tour of our journey towards the end of the journey you know you're gonna start to becoming less wary of your decisions on the road and stuff like that so that's why they always usually tell you take some breaks along the way so utilizing tools like AI and using those matrix is trying to reduce trying to reduce fatigue for for analysts yeah yeah my eye can they thoughts make no I think both Shaddy and Victor have actually touched some really critical points and Shaddy in particular because I think they are in the thick of things when it comes to sock analyst satellite what I feel like and then this is this is something that we have seen from the architecture perspective as well like in in the discussions where we had been asked to look into building out some of those architectures where security operations are also coming into the conversation one of the the aspects that have come out is that AI is definitely useful in the sense that pretty much all the security vendors are coming up with their own AI agents be Chad be automation what it does good or what I especially what I have seen something which is good is in the sense of understanding the patterns understanding the patterns understanding the behavior the way it's been when an attack is actually happening understand the behavior at that point of time and giving the at least the right frame of mind to the to the users and in this case the users are the sock analyst were actually looking at it so giving that sense is is useful because now as Shaddy said that having that humanized layer of taking the final decision is more important but you're in the right direction which is more which is which is critical when when the actual attacks are happening you don't want to start looking for a de-dose when it's actually not a de-dose it's it's something else but it shows a very specific behavior because remember nowadays an attack is not like okay yeah we are going to be de-dosing them it's not like that it's usually a combination of various different attacks happening almost in parallel where the actual agenda might be different but and usually the focus of the attackers are to move your focus away from the actual goal like what they are trying to do they might be targeting something a specific service a specific application things like that but they might want your defenders to move away look away and the best thing easiest way to do that is okay let's bombard them let's do stuff where they would not focus so I think AI is definitely helping in that area what I have also seen is it's not like one single solution for everything so that is something which AI I believe will get better at in the sense that okay every organization is different you can't have a similar architecture for a fortune 500 company do a small or a mid-cap organization a fortune 500 company will have global presence offices in China offices maybe offices in Russia as well right you can't say if somebody is logging in at two o'clock Australian time from Russia that is a threat active for them it might be a legitimate case right so I think it is it is evolving definitely but yeah I think from a stock perspective it is going in the right direction thanks very good and Sanjay the final thoughts my smile guys yeah I think this does have covered a lot of points and interesting points actually you know and I would agree you know the the AI is certainly helping in terms of the stock or from the alert fatigue it is it is helping out the agents to chew on more you know reduce the time to respond on to under a particular thread now of course what has happened is with the AI in place and the the cyberculture in the time to execute the cyberculture that has actually reduced so that how that is translating as it is now there are more attacks happening onto the enterprises as a base piece as well and in terms of if I locate from a costing perspective say if it is an enterprise and you go out there because when it comes to the recommendation the recommendation is to either you build out your own team or you know outsource it to an MSB which do do the stock services as they are bread and butter they have caught the the people technology and everything well-trained people and technology they do it and they end day out but how this impacts is with respect to when you cost a particular solution especially with respect to the stock it is on an event for event basis right say you have got event per second say thousand events per second but with the AI the number of attacks increasing now instead of having thousand EPS you have to cater for it and thousand EPS or maybe more and that further increases your cost to handle those you know attacks and not only just the attacks you know your your agents who are actually handling those alerts are also getting pond so it it it goes both ways it is helping our stock agents to maybe analyze the attacks in a better way because AI does most of the churning most of the analysis gives you a summary and then you can take the call but it is also increasing the attacks that are happening throughout the IT space so yeah that's what I I generally see out there in the market and when I'm consulting with with the customers you know instead of reducing the cost it has the AI has actually increased the customers cost for keeping them secure yeah thanks Andre it's a super interesting thoughts there guys and thank you in Shari brilliant questions so excellent for that um let's tackle accountability upstream now and my uncle question that works well for this you said if an AI system is used in a cyber attack who should be held responsible could it be the model provider the tool integration the hosting platform or the attacker alone and how do you design for accountability I'm so buying could you want to fix off yeah so well this is a question which actually kind of came in from one of my recent discussion with an organization where we would we were trying to build up a security solution for them where like on the architecture wise we are discussing of all sort of things starting from a micro segmentation to data loss prevention with respect to what you can what your users can share out in the world with these various chatboards and other aspects the the fact that now as as we have been discussing AI can be very easily used for for by the threat actors for creating these scripts creating these phishing campaigns it can be a very specific targeted attack or it can be a general attack on the organization level from our probably decades of working in the in the security space it has always been that okay who has triggered it right that that person is usually the the one who is accountable for okay yeah you know what we have given you all the trainings but you still went ahead and clicked on that spam link and hence we got into the trouble and then yeah that has been the pattern that we have been seeing we see the you the the organizations having those third parties and those third parties might not have the same level of governance control on their tools and they might be using some sort of like a freewares and they got hacked and from there the actual pattern organization got hacked and all those stuff happened with AI it becomes little bit tricky because why I'm saying that the attacker will always be the person to be blamed for yes you that the intention is always malicious you went ahead you did this okay but what about the the plate forms what about the integrators who are providing these tools why and I'm not saying like okay they should be accountable every time an attack happens but there has to be some sort of accountability in the sense that what about your guardrails what about the factors that you are putting in to ensure that companies have certain controls in terms of what we can do so going back to my initial example of using co palette for are you giving the controls to the organizations so that they can secure themselves or at least provide certain controls on them so at this point of time I don't see that because I feel the when it comes to guardrails it still belongs to the actual platform so what they have done that's it right like apart from that you still have to rely on okay what sort of proxy mechanism I'm using what sort of deal P controls I have something like that so definitely something from an accountability perspective I also feel like that we are going in the right direction in terms of like if you say EOAI act that's that's good and kind of a situation which Australia I feel in particularly needs to invest and look deeper because we don't have something like that and we are not I just feel like that we are not thinking too hard enough around that so yeah that's that's my thoughts and I'm really I would be really happy to hear your thoughts probably from you Victor from you Victor if you can just chip in because you raise a very interesting point my right I mean if you think about right whoever let's let's take that hypothetical scenario example right you're going to have a GSI or similar who's just going to come in gonna deploy any kind of AI tool AI solution in order to automate a particular task somebody's going to compromise it and trick or manipulate the model into carrying out an attack who's going to be responsible that is a very very tricky question and the reason for that is or also what comes alongside with it is all of us as trained security professionals who spend a couple of decades in that space right we all grew up basically with the CIA tried in terms of this is let's say that one of the most objective or the highest objective we need to uphold right some of us that have done work in the how it utilities or basically more in the operation technology space will know also health and safety which sort of jump into this but now all of a sudden with this high bottomation trend with basically the way where and how AI is going all of a sudden we have additional trust primitives right so for us now basically like the authenticity of whatever a system or solution is designing or coming up with becomes very very foggy important or the veracity of it right in terms of can I really trust it basically can I really place trust into whatever comes out of the model because if I can't validate whatever the model is going to be coming up with then that basically raises a completely different question with regards to who's accountable for it right so you basically need to be building this in or you need to have to the safeguards the mechanisms order call it the material takeaways in order to determine is if the model has been tempered with or is the solution has been tempered with how would I pick this up because that's that's a whole point right even in any kind of system even if the the CIA tried will be uphold you still will have doubts or questions in terms of cannot really rely on whatever the system says right if the system itself still does what it says on a tin or basically whatever the model design or developer basically came up with but somebody manipulates the model the model basically is I don't want to necessarily say not at fault right but you need to ask and challenge the social construct around it if whatever guidance or whatever it's a terminology comes out of the system how this has actually actually has been used so I feel like trust primitives is probably something that we will have to question or to challenge them moving forward in terms of how do we actually really rely on whatever a hyper automation solution and LLM or any kind of AI system is coming up with I expect that Sanjay I can probably consider it from AI secretly perspective as say for example right now if I go and ask AI how I cannot act particularly by example the technology there are some controls that the AI you know model providers have for time where it will not give me I script directly or a bit executed but if I go there interact with the AI model and say say I'm a researcher I'm a research student or something and give me some recommendation and then it will start giving you a lot of data you know how to executed what things you should consider so probably either I think we should create AI as we are treating our other solutions right say for example in the telecom industry the owners is on the service provider or the product provider to put in the guardrails to keep the products secure or at least to put in the controls waiting for the product which you can activate right so those controls need to be strengthened that should be the responsibility of the whoever is the modern provider which they and users can activate another can be you know probably right now I can go there and just interact with any I model data subscription and start interacting getting through response probably the subscription model would be increased you know and some end of mechanisms because we introduced where you're actually going and verifying for what purpose the AI is going to be so safe for example if I interact with charge GPT if if I'm a general user I should not be able to query I should not be able to query or get the responses for attacks it is not much of right so in a subscription say it is like a general subscription where you will give a general data whereas for the professionals likes invite hearts or people who are doing the actual research before giving them the actual you know access to the AI tooling itself you have to validate like how you do with your certificates as in you are actually going and verifying whether that particular enterprise is actually holding or has the ownership of what you are doing so similarly when you are giving the subscription you can take you know you can do some verification as in whether it is a particular you know user is is responsible enough and whether it those models will be actually useful utilized for the right purpose next thing will be you know there the next control can come in on to the actual users or the enterprises for say for example in telecom industry the you are running a contact center and then owners is on you to stop this bank calls right to stop those kind of SMAP goes routing through your network so similar kind of guardrails or owners should be put on the enterprises so that necessary you know the SMS programs are run onto the AI space necessary guard roles so that you know the checks or the attacks are reduced or the attacks of this so that is my thinking around around this you know thanks actually and Shari finally any further thoughts on this I agree with everyone's points yeah but I kind of want to take kind of different links to this I think the responsibility has to be a layered approach and you know we need to go back to the basics the attacker is the one who's committing the crime so that's one layer so the the the one who is doing the crime should be in trouble for doing the crime but we need a look at it from a different lens how do we stop the model providers or help them building abuse resistant guardrails so that's another lens that we need to put into it the other lens is the the hosting for providers then it ensure that they're they enforcing the abuse terms as well from a defender's defender's perspective we need accountability which means logging every AI action every prompt every tool call so we can understand when and how and where so these days you're seeing online people are learning how to jailbreak LLM models to get it to do things that it's the guardrails so trying to understand how we can protect that there now the other lens is I kind of want to take it one step back depending on the country that you're in is I think the government should be more involved in forcing some governing laws to help the vendors enforce this and doing this so like for example let's say an attacker can go to Bunnings Warehouse for example and buy a hammer you can exactly go to the online get a subscription to chat gbt so they have availability of the tools but if they go and attack somebody with a hammer that's when they're they're in trouble there are laws going that so just taking those views is you can have access to these tools but you need a teet to adhere to these laws at a higher governing body to help protect protect protect us none of you yeah fantastic make sure my gay any final thoughts before we move on no I think this has been done completely yeah love it guys no brilliant exit and Sanjay last but not least your question if the next 12 months in effect are an arms race what operating model and budget mix actually bends the curve in favor of defenders and how do you prove it to the board Sanjay do you want to start us off? yeah sure so the way I see AI is almost similar like the the encryption race that was happening in the early 1900s where everyone was chasing for the you know the next best head encryption algorithm and everyone was chasing how that can be cracked so take AI in a similar way you know now AI is kind of helping us out for you know handling the attacks so what we can do is in terms of the operating model it needs to be an AI augmented defense where you pair your you know usual the regular solve with the AI agents so that they can work in tandem then again you know need them to need some feedback loops where every you know incident or positive becomes the training data and then your stock is ahead for the train to take care of it in terms of the budgeting what I see is probably we need to increase really to invest on the people process and technologies the way I say it is probably people needs to be trained more so I would unlock it and be safe what if percent of the budget or more budget on to the people training so that they have a better understanding of what's going around and so that they can handle it in a better way I'll say around 30 30 could 30 35 percent of the you know the budget I would allocate to the training because that also needs to be real you're shooting needs to be upgraded so that and constantly keep that updated to handling new threats on top of that you know maybe some additional services got all of you know cyber is a constantly changing landscape so the tool or technologies or the services that you have right now may not be good enough for say in another six months or another three to eight months so you need to invest in some services maybe some advisory or some you know try to mitigate your service then something or so so probably around maybe 20 to 25 or 20 to 25 percent I would say you know invest in the train in terms of the boat you know into a boat does not bite what they want is to reduce the risk so how we can show them in terms of the risk reduction is your need time to respond right need time to detection and this how that is coming down with these kind of investments or say your attack surface with these kind of investment how you attack you are reducing your attack surface how your shock efficiency is increasing and how you're kind of reducing the overall risk maybe through your risk reduction in mitigation transference of all those sorts or maybe your you know in terms of the insurance or how you're reducing those so those are some of the things which would really be interested on though how you're reducing their overall risk and balancing it out together so that is my view in terms of you know this yeah everything so thank you sounds right big dranny thoughts on the operator model and budget mixes from your view I think I have a probably slightly different way at least based on the interactions or at least the customer discussions that I'm privy to the problem is the paradigm is not new right I mean unfortunately and I really hate to say this right cyber is not revenue accruative right it's always a cost broker right and it's always going to be perceived as such as I see nothing faces yes and that is not going to change with AI right unless anyone is going to come up with a view and unless you're probably going to be part of a business where for example security is going to be part of the value chain you're going to deliver a service or similar that's where cyber over security can be considered as a competitive edge but in a regular organization it's going to be considered as it's another line item or like another line item in my pnl that will increase now from x y and z to abc and so on and so forth so proving the value here we've been doing this for like decades to use risk management but it isn't working to the degree that you actually can securitize at least quality infrastructure or applications or services so that in itself is still going to be a challenge I generally believe and I mean I'm in securities on pessimist manager right I generally believe that what wouldn't what will need to happen or what might happen at least over the next 12 to 18 months is that with the rate of attacks increasing and increasing like substantively people will start to realize you know what we actually need to have like proper line of defenses right we can't I'm just going to picture ID's example right we can't basically try to continue to get away with the software is basically completely understaffed just because we don't have enough people in order to look at least after managing our attack service and those sort of conversations will need to start to evolve towards what I what is actually security worth well to us right if we are in a business that is basically B2C and customer phasing how much do we put as a price tag onto our reputation if I'm if I'm a tell call if I'm a data provider if I'm in any other kind of if I'm a retailer or similar right do customers put faith into or trust into the brand just because I haven't come forward over the last 12 to 18 months because I have been breached right and I think these are some of the discussions because trining with the user risk management we've been doing this for a while but realistically speaking we've been seeing that at least investment into security has been diminishing at least over the years right so it's like it's not necessary that this is going to change like this principle is still going to be there but I feel like we need to come up with new narratives or with new ways in order to justify the spend already still increase the synchronization of assets of solutions of softwares and so on and so forth because the reality is anyone who is outside of techy land or who sits outside of cyber will have no appreciation for this so we need to basically bring the narrative into a business where it's going to be like you know what you can invest this year 10% less into your sub security spend that's okay boja is going to be increasing probably by 400 percent because we actually can't cover our tax service that is as simple as that and if that happens that's going to be the price or that's going to be like the decline share price or the next three months if you're willing to absorb this that's okay but I'm just here in order to put the facts out then I feel like that is probably somewhat that conversation that narrative that at least will need to be start to spun a little bit differently yeah I was interested in the chart any further thoughts on it but I think both of you have answered the question really well um I think it's it's it's the lens that I want I want to say to the businesses is it's always going to be a battle you know technology is rapidly changing and with it rapidly changing sometimes a six month plan and a 12 month plan can change because of how fast it is you know since we heard our chat gbt came out the AI a lot of businesses wanted to invest and invest and the landscape is changing dramatically so what I what I usually try and tell businesses is it's not about reducing head count it's not about um using tools it's about making sure that your tools that you have in place are used correctly are used to the right right methods plus educating stuff you know this is new technology maybe a user doesn't know how to use AI or your team doesn't know how to use AI it's utilizing them correctly now just to follow on to what Victor said about budget and that aspect is the way I try and perceive these views to the boardies is let's say the business is impacted by a denial of service and they're offline for X amount of hours how much does that cost the business X figure relating that to the business is can you take this much downtime can you take this much money loss or can you invest some more or some less into the into the budget just to give them the view you know we can use many vendors that have been impacted that either have lost a lot of shares or lost even business brands because of a cyber attack or a breach so utilizing those examples there to learn and protect because all it takes is one incident and you could lose a whole business yeah so that's that's my view yeah fantastic thing Shardy am I anything else to add before we finish off yeah see again really good discussion and a very good question as well and I think from a budgeting perspective I think all of us all big all of you guys have all kind of hit than Neil I only think that the and then probably in extension to what Victor has said repetition and trust are the key factors for the board we all know if it is security in general is not a revenue generating aspect for a lot of organizations so you have to justify that what's at stake and I believe repetition and trust factor with the stakeholders the shareholders in the market the valuation of the organization those are the things that the board actually cares for okay they won't care about all the fancy tools or the next level of advanced cyber security aspect we can bring in so I believe from a budgeting point of year I think the any before going into the numbers side of it that aspect should be taken care of that let's bring what sort of value you're bringing in what sort of risk exposure you're getting into if you're not basically getting ready in terms of the tools and services what I feel like is all the security vendors are already trying to leverage the AI when it comes to the for example Sentinel and all these software appliances as well as all these next-gen firewalls and other aspects so I think from a vendor's perspective we are going in the right direction but what I also feel like that the focus should move a little bit more from the defensive side of security towards the offensive side of security so maybe the likes of pen testing use utilizing agent AI for pen test those are the kind of things that we should leverage more so that the organizations are probably a little bit better ready for the next wave of cyber attacks that's going to happen because I think somebody very correctly said in this podcast that it's getting changed very rapidly you are going into an agent AI space where it will start taking their its own decisions and that would be a very scary thing if you think of it from a defender's perspective so probably be a good idea to get on the front foot and start thinking of it like okay what would happen if we are getting attacked by an agent AI where from the beginning till answer from the reconnaissance act to the execution sector everything is being done by AI no manual intervention required and it can take decisions on its own pretty much all your defensive tools will probably not work in that scenario so getting ready for that and showcasing the value to the board would be probably the better way to cover it that's my thought really I experienced some amazing suggestions there super interesting guys before we wrap up I'd just like to ask one final question my question being kind of one piece of advice for technology leaders out there who are worried the AI is outpacing their defences it's the one piece of advice that you can give Victor Starrodita sorry need to unmute look I think there's a general acknowledgement that by the end of the day that it will be just a matter of time until you're going to be subject to a compromise right it's a conversation probably that you could have had like a month ago with Jaguar Land Rover right back in the UK I mean Joe you probably would be very very familiar with this but the reality so I think this is probably how the narrative is shifting or is changing to say whilst we are not going to be in a position to defend ourselves or basically to invest like copies of most of money until we're going to be bolstering up our defenses in order to cover up for 95 96 98 percent of all different type of threats or attackers that basically might try to compromise us the narrative should be changing towards saying let's increase at least the level of securitization so that at least we're going to make it at least for the vast amount of threats that we might be subject to like all in a cybercrime or activists or somebody who's just going to be doing this for you know fun and giggles are going to Sunday afternoon let's increase the bar of securitization to become an unattractive target right and that basically will then mean that you can decrease at least the amount of final of people that you actually really will need to watch for depending on the type of environment or infrastructure or call it vertical that you're going to be in right if you will be natural critical infrastructure that is obviously not necessary the strategy that would work but for large corporates for vast amount of corporates that will basically will need to deal with somebody who is in for this as a commercial gain it's probably the easiest way to say or it's probably say the more sensible way to say just try to at least make the or change the business case from the cyber threat attack aside so that is going to be commercially unviable so they're going to be possible to compromise you or to compromise your crippling infrastructure but let's make it at least to a level where it's not going to be commercially to the degree that they basically will try to go for because that way you can always deflect them in order to just go after an easier target or something like that is at least in the corporate space and to the circumstances or the constraints that we have now made this be let's say sour being cost prohibitive and basically being not necessary revenue generating that is probably the most sensible approach at least over the next six to 12 months until we probably will see how the market is going to be shifting and who knows whatever's basically going to be coming up there this is at least a conversation or say a narrative that I have with different customers to say let's focus at least on those let's say tactical opportunities before we can actually get into the state of the longer term the strategy mix because your cyber security uplift programs that is going to be something that will be in the millions and a lot of companies or organizations are not prepared for that just yet that's awesome thank you Victor Shari was sure one piece of advice I think you really hit the nail on the head Victor there just to follow on to that I think advice that I'll give to leaders don't wait for perfect maturity operationalize what you already have use AI if you already have it and with guardrails attackers are already using it and moving fast to defenders and businesses need a match to speed so I think that's my lens that I would add to what we just said yeah that's it thanks Shari as Sanjayi will fall to now I think these guys have covered a lot of interesting points I think I will say two things in terms of the protection I will say you know don't it reinvent the wheel put your you know AI policies or the AI standards based on this standard existing tools and control that will make it easier for you to unfold the AI and utilize it also in terms of the AI threat landscape that is constantly changing everyone is going to use AI no matter if you're on board or not people are going to use it so it cannot be avoided so but instead of you know being afraid of AI utilize it reduce your risk and you know reduce the risk and use it logically as you come back away Sali thank you Sanjayi am I in care anything else to what guys I've actually covered a lot so I will try to keep it very small I just feel like that yes AI is changing a lot of things and definitely the attacks of this is also getting changed we should still focus or probably the leaders should focus that it's still going back to the basics you still have to ensure what your how how exposed you are go go back look at that what are your existing tools what are your existing processes are they resilient enough because I feel like even today when we are talking about all the the risk AI is bringing in or the cyber attacks are happening most of them are still leveraging some really simple techniques or I should say lack of processes so probably make sure that whether your existing processes are resilient enough would be the first thing that they should look at it does not necessarily require any budget or monetary allocation so that should be the first step that needs to be looked at at the second step I would say yes start looking at things like in getting a little bit more investment for the security services probably expand your security personnel not only from a resourcing perspective but also from the tools perspective be smart about what you are using probably as I said like start leveraging offensive security a little bit more because I feel like that's one area that not a lot of organizations look at to actually strengthen their environment but they look at it more of a check box at oh yeah we have this is a new application we have done a pen testing for it and that's it you should start looking at it at a different angle you should start focusing on your organization so yeah that that those are the things that I feel like should be important for the leaders to consider I mean thank you Mark I'm not just about wraps up today's conversation on AI versus cybercrime this has been super insightful for me guys a huge thank you again to Shadee Mayank Sanjay and Victor for the key in size today and if you or somebody in your network would like to feature on a future episode of evolution exchange then please message me on LinkedIn directly I'm Joel Award from Evolution Recruitment Australia and we will see you next time

Podcast Summary

Key Points:

  1. AI is accelerating cybercrime by enabling more sophisticated, scalable attacks like deepfakes, voice cloning, and polished phishing, while also lowering the barrier to entry for threat actors.
  2. Organizations face challenges in defending against AI-driven threats due to architectural debt, over-reliance on third-party tools, insufficient governance, and supply chain vulnerabilities.
  3. In cybersecurity defense, AI can both reduce SOC noise and improve efficiency through automation and intelligent alert correlation, but it requires proper implementation, guardrails, and human oversight to avoid risks like hallucinations.
  4. The threat landscape is shifting toward a scenario where attack efficiency vastly outpaces traditional defense capabilities, necessitating a strategic focus on ecosystem defense, context engineering, and proactive risk management.

Summary:

The podcast discussion focuses on the evolving arms race between AI and cybercrime. Experts note that AI is empowering cybercriminals through tools like deepfakes and AI-generated phishing, making attacks more convincing and scalable. This lowers the entry barrier for threat actors, potentially increasing the volume and sophistication of threats like ransomware.

Defensively, organizations struggle with architectural weaknesses, third-party risks, and lack of governance around AI tools such as Copilot, which can inadvertently expose data. In Security Operations Centers (SOCs), AI can significantly reduce noise and enhance analyst efficiency by correlating events and automating responses, but its success depends on correct implementation and guardrails to prevent misuse or hallucinations. The consensus is that while AI offers defensive advantages, the offensive capabilities are advancing more rapidly, urging leaders to adopt holistic strategies like zero trust, supply chain security, and context-aware controls to manage the escalating threat landscape effectively.

FAQs

AI has enabled more sophisticated attacks, such as deepfakes for impersonation and improved phishing emails without grammatical errors. Cybercrime-as-a-service is making it easier for less skilled actors to launch large-scale attacks like ransomware and DDoS campaigns.

Leaders may overlook the risks from AI tools like Copilot, which can inadvertently expose sensitive data if not properly governed. Additionally, supply chain and third-party risks are increasing as attackers target less-secure partners.

Implement strong guardrails like MCP or A2A controls, context engineering to prevent data leaks, and red teaming prompts. Focus on educating users about AI risks and strengthening third-party security controls.

AI can reduce noise if properly integrated by summarizing and correlating events into actionable incidents. However, without correct setup and guardrails, it may hallucinate or create inefficiencies, leading analysts down incorrect paths.

Humans are essential for making final decisions, validating AI findings, and managing governance. AI assists with efficiency, but human judgment ensures accuracy and addresses complex, nuanced threats.

Attackers gain disproportionate efficiency, with capabilities increasing by hundreds of percent, enabling scalable attacks like deepfakes and automated phishing. Defenders see more modest efficiency gains, requiring better integration and tools to keep pace.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.