Enterprise Security Restructuring & The AI Vulnerability Boom with Alma Paul

TLDR;

  • Now more than ever, basics matter the most: knowing what (the landscape, resources, assets) of security is and where you want to get to (your North Star).
  • Embedding security early on into your culture helps you avoid cleanup at a much later point and makes it relatively easy to implement programs.
  • For vulnerability management, prioritize based on business context (public-facing assets, exploitability indicators, application priority, etc.) vs trying to fix all vulnerabilities.

Transcript

Host: Hi everyone, this is Purusottam, and thanks for tuning into the ScaleToZero Podcast. Today's episode is with Alma Paul. She's a senior corporate security engineer at FAIR, and she's a specialist with a strong educational background, industry experience, and in-depth knowledge of security tools, techniques, and practices. Alma, thank you so much for joining me, joining with me today in the podcast.

Alma: Thank you for having me, I'm very excited.

Host: Sounds good. So let's before we start, maybe do you want to talk about what does a day in your life look like?

Alma: It obviously depends on the day. But recently I've s started a new job. So it has been learning a lot of new things as quickly as possible, getting getting up to speed, understanding the environment, understanding the business, meeting with different teams, stakeholders, getting to know the tools that we use in the environment. And then while I'm doing all of that, I I I do understand that I wouldn't have this luxury of time later on.

So I'm also kind of like making sure that I'm taking mental notes and actually writing down any risks and any gaps that I find so that we can, you know, we have like a registry to work off of when we when we want to kind of chart out like a bigger plan.

Host: Okay. Sounds good. So so today we'll cover on enterprise security and vulnerability management. So I hope we can touch on some of the risk registers, some the learnings that you have had recently and how that plays out with your work. but before we get into like the security questions, one of the things that I wanted to start with is like you started your career with is a very strong academic foundation, right? Like with masters in information assurance. Versus some folks who may start with by getting their hands dirty, maybe hands-on experience. There is no I mean, there is no right or wrong path, right?

Both have their pros and cons. how has this like the academic foundation help you approach the enterprise security problems compared to maybe someone who has come from the other way around? Like how do you see that?

Alma: Excellent question. So as as you know, a lot of like people in the industry, like a lot of hackers, right? Like old old school hackers, they did that by breaking things and that's how they learned. There a lot of them didn't have formal education, amazing individuals that we all look up to.

So I I I think a lot of a lot of very very impactful colleagues that I've had, like a lot of impactful people in security field, necessarily don't have don't come from like that… Educate like academic background and are able to be very successful. Me personally, I think what having a formal education, what it helped me with was gain a lot of breadth of in understanding. So it wasn't just one area that I specialized in. I I took a class on risk and compliance and this secure coding and then you know actually like getting my hands dirty and breaking things and doing offensive security. So like a lot of different areas of security I was able to touch.

Also, what education really helped me with was getting my foot in the door. It was a little easier for me to get started in the field because I had a lot of support from the university to get those internships and get those co-ops and convert that into a full-time job. I will say this: a lot of things in security are learned through a lot of pain and experience and breaking things. So I I don't think there is one right way to approach it. Both are fine.

you have to continuously keep learning and improving to do better in in this field, regardless. I will say this that I did kind of have to make sure that over time I gained more in-depth experience in those verticals and those domains that I lacked experience in. so it fills up, but you know, I think there's pros and cons to what both.

Host: Yeah, yeah. No, that that's a very good way to put this. Now a follow-up question to that is like often academics helps you with gaining knowledge, right? from your instructors or from your teachers. Now in the AI age, knowledge is available, right? You go to Chat GPT, Claude, and you ask questions, you find answers. what's your thought of on like the degree led education for security and its relevance maybe let's say five year down the line.

Alma: I've been thinking about it quite a bit. I have a toddler and I'm like, why, by the time he is college going age is that concept still going to exist, right? so I don't necessarily have like an answer of like if that will be valid in like 15 years or whatever.

I do think there is value to formal education that it teaches you how to think, it teaches you how to learn knowledge itself has been democratized for a long time, right? Like even pre AI, we have had YouTube, we've had podcasts, we've had free resources online, MIT put out puts out coursework. so there is a lot of free resource available at all times. and just because you're kind of like you've gotten your your undergrad or your masters doesn't mean that is the end of free education either. You're continuously learning your ev all the time. I do think that it's like formal education gives you a little bit of structure.

I don't think that is the only way to gain knowledge. I understand that there's another aspect to it, which is also like financial, right? Like it it is expensive to get an education, a formal education, especially like we're talking like two, three degrees. So I am very grateful that we have this democratization of of of knowledge.

I think what we need to be mindful of is just because we have AI doesn't mean that it's gonna like replace traditional knowledge like traditional like way of learning. We still need to get really in depth and really good at at at things. and that's kind of like where mm we have to be very mindful of is we have these this this vast information available to us, but we have to like still put in the effort to to make sure that we are painfully getting to the depth of things and understanding things thoroughly. that's that's my two sense.

Host: No, I mean yeah, tha that's a debate which is going on in the industry now, academics and non-academics, that hey, how how should how what would be the relevance and things like that?

I think one thing that you pointed out around like the learning the depth of it, right? Like today if you use let's say claude or codex you can generate code, but if you do not understand what is being generated, if you need to fix something, how do you how do you do that, right?

Like even though you cannot just say that hey the agent has written it and I have no idea. Like you own it, right? So that means the you have to have those foundational knowledge or the basics understood really well and that's where academics helps you a lot. so yeah, I even I am conflicted as well not conflicted, but I even I am not sure where it j how kids of this generation or the come next generation how will they look at academics compared to what AI is providing.

I guess mm future we'll find out in the future. Yeah, yeah.

So the next thing that I wanted to touch on is around the security, like enterprise security. One of the things is enterprises are complex, right? Like they have so many tools, so many processes, programs, everything is going on. So for a security leader who is trying to let's say build or restructure maybe an interest enterprise security program, let's say if you are doing that, what are the let's say first three things that you would look at. and you would fix them first before you maybe overhaul everything or bring a major programme.

Alma: so I think from from a specifically like a leadership standpoint, right? the first thing that we need is visibility. We we need to understand, like we cannot protect something that we just like don't know about, right?

So, and that's this is like what we've done at different companies that I've worked with as well was cataloging and making sure we have a really good asset directory. We know like what are the things that we own, we know what our footprint is, and we are able to like kind of like put them all like centrally in in in one location location. So we understand we then then we can kind of like do the risk analysis and build that risk registry of like what are we trying to protect? What are we what what are our gaps and what is our north star? What does if we are able to deploy everything correctly, if we're able to build a very successful f program, what does that end product look like? What does that end state look like?

So having that North Star along with like these like fundamentals correct I think it's very important.

Then the next thing is and I and I know like this kind of like changes and evolves over time, but as much as possible, having a way to have a cons consistent risk risk model, right? So regardless of who on your team is doing that that risk analysis, they're able to kind of like come up with the exact same criticality level. So making sure that your giving guidance such that your risks are mapped to the workplace that that that you're working on and because everyone has like different risk level like it does it's not one size fits all so giving that guidance on consistent on having a consistent risk model is very important.

And lastly I think are you leveraging the tools that you have today we get very excited and we kind of like want to like do new things, but if you're not leveraging what you have today in the environment, mentally you're kind of like, Yes, I have some coverage, but do you actually have coverage? Are is is someone actually actively it doesn't have to be someone, it has to it can be AI, it can be like some automation, but are you looking at the alerts that the tools are spitting out? Are you able to are are you leveraging all of the all of the capabilities it has? And then kind of like proceed to the next next thing.

Host: I like how you structure that, right? Like first thing is what. The what aspect is very important. If you don't know what you are protecting, how will you protect them, right? the the North Star aspect, I have a follow up question. For a security organization, what would you say would is your North Star?

Alma: Yeah. so I think maybe like it it I didn't f it it isn't like one thing, right? And it's gonna keep evolving and changing. I think we chart out the different specifically for enterprise security. What are the different domains that we care about? is it it's like s identity, say endpoint endpoint security, all of those different things, those different pieces of the puzzle that like make up enterprise security, one manager, like different components, right?

And what is your maturity level in each of those things? Right. Are you you know, like on a scale of one to ten, where do you where do you rate yourself and where do you want to be? Do you want to have like zero mull in like in your environment? Is that like your end goal? Or are you like, okay, we are able to remediate most criticals and highs within like three, four days? What whatever that like, whatever benchmark you've set for yourself, I think that's kind of like what you evaluate against for all of these different domains that you have, what is the maturity level I expire to be in each of those domains? That's how I would kind of like go and approach it.

Host: Okay. Makes sense. The third thing that you mentioned w was around like the tooling, if you are adopting it the right way or if you've fine-tuned it the right way, like the for your organization or not. And that's a very big challenge we see, right? That as you mentioned, like we get excited that there is new AI and there is a new security tool there with it. We say that hey, we want it, we buy it.

And then we go to the next thing and we do not adopt or do not fine-tune and use it. So that often means even though you have the tools necessary for your job or for improving your security, you're not using it the right way. Now the question is like how do you like what metrics then you look at? Like what KPIs do you look at to see that you are using the tools or your your health of the security program that you want to incorporate. And any misleading indicators that you should avoid.

Alma: Yeah. so I would say avoid vanity. So like when we're talking about metrics, I have a love hate with metrics, right? I think it's a pain to produce, but I think they are

Host: I think everyone has sorry, but yeah, I think everyone has that love hate relationship with metrics because they like sometimes they do not give you the real picture, right? but yeah, sorry, I didn't mean to interrupt.

Alma: Yeah. Yeah. No, I think e everyone has like very strong opinions, right? they're they're pain to produce. They're they're they have to be very accurate; they have to be updated correctly. So they there there is like a whole program that needs to run to like make sure that if you're relying on metrics that they are like they're telling a picture.

We need to really steer clear from vanity metrics and by that like we kind of like, we have like had hundred thousand ones being reported in the last hundred like one year, like it doesn't mean anything, right? Like it doesn't it doesn't tell a story of like how well you are running your program. so metrics for your program needs to tell a story of like how well you have done over like a period of time. So last year if like if we were you know you know like if if if we were going to focus on and endpoint security and well management.

A year later, your metrics need to be defined in such a way that it's able to tell us how much risk have you reduced over time, how much coverage have you had over time. And and I think that's what like a powerful metric says, where it it reflects the hard work that you've done and it shows the value that you've added to the company.

Metrics also do another thing, which is which again is very important for security teams because we are usually kind of always understaffed. so it's it's an important so it's a important tool to kind of like see if if that is do we need more automation or do we know need more engineers? If why is it that we're if you're missing if you're not able to hit a certain metrics, why is it? And doing analysis on that and remediating that so that we're able to like make more of an impact over like over the next year maybe. I think that is another story it tells.

It needs to be fl.. with anything, any kind of program, it needs to be flexible enough. If something if we need to pivot, we should be able to do that easily without being penalized on it, right? of course if you're committing to something that we should most likely deliver those things, but we also should be flexible enough to say that you know some cult fallacy this is we focus on this area but it wasn't something that we should have. Let's pivot, let's redo. So I think I think metrics should tell a story. It should tell a story of growth, hopefully.

Host: Yeah, I think the last part that you said, right? That it should tell a s story or it should at least show the progress that you have been achieving. If it's a six months program throughout the six months, where did you start and what's your North Star again to connect to what you said earlier, and how far are you or how are you trending towards the North Star?

Maybe that gives you more information or the it tells a better story than saying that hey, we have fixed 200 vulnerabilities. What does that even mean, right?

So so now like when it comes to enterprise security, security teams are understaffed, as you said. You have to work with many other teams, right? Like business units and engineering, product, all of those. Now, from there is an aspect of culture which often plays a big role in here. So how do you balance the tension between like enabling the businesses to move fast or enabling the engineering to move fast and at the same time making sure that you like whatever you had outlined as your North Star, you are progressing towards that. like the balance between business moving fast and a strong security posture. Like how how do you do that?

Alma: I feel personally like obviously everybody understands security is important, right? That's why we are funded, that is why folks help us like achieve our goals despite it being painful. I think as security professionals, we have to understand that security and we have to be very mindful and it has to be like always back of mind that security comes with a cost. It could be a dollar value, it could be you know, like a degradation of service, it could be deprioritizing other things that another team would have had to do.

So it has a real cost associated with it. So whenever we make a decision of or of having like a policy or like introducing something new, we have to be able to defend it very thoroughly. It has to be a very thought-out, very thoughtful process. And we have to kind of like have that internal monologue of does it is it needed? Can we make it better?

Like, if we're able to make it as frictionless as possible, that is a win for for both security and and and for the business. At the end of the day, we are here to like enable help the business, right? We're like not two different functions. we're we're all like working on the same team. so sometimes, of course, we have to say no. There when and and sometimes there are there are regulatory reasons why we have to kind of like do things because we, you know, because they're they're necessary.

But most times I think we can work with our with with our partner teams to kind of have as frictionless as possible of an implementation as as we can. But yeah, at the end of the day, we're you know, it's it's a science and art is what they say, right? There's like a lot of there there is a lot of making sure that in in addition to being like technically strong, you also have like those very strong relationships with your partner teams that then like help you kind of like move your security agenda a little further.

Host: Yeah, yeah. I think y like you're spot on with that relationship part, right? The more trust the other teams have with on security, the better outcomes you will get from a security perspective, right? Like you can move along like or you can push some of your agenda further. yeah, tot totally.

But if I want to maybe scale it down a little bit. Like enterprises are complex, we understand. How does that compare to a let's say a startup of let's say five people or ten people or twenty people or thirty like compared to an enterprise if I'm looking at it from a for a smaller organization, how do you see them being different?

Alma: So I think for a smaller company, and I so I joined as the first enterprise security engineer here at my current job. having said that, I think and I'm I want to give them kudos here because in security was embedded in their DNA, like in in IT team's DNA from the very start, right? So it's not an afterthought that like a enterprise security person will have to like come and clean up. They've built things with security in mind. That is like one of the the the the founding principles. And I think that is the only way that we can scale. We're not again we're security teams are usually like understopped, underfunded. for us to be able to make a very large impact, it needs to be a cultural shift where security is everybody's business.

And if everyone is doing doing their part, then for us as like a centralized security team it becomes easy to kind of our job becomes easy because then we are kind of like writing those policies and standards and we are the we're kind of like a g guy giving that expertise and guidance to like help help teams make the right decision.

But I think like culturally that that shift needs to happen where everybody knows that security is important and and they're able so here's my like here's the other thing too, right? Like a systems engineer pro understands that system extremely well probably like better like they understand the system that they're building better than anybody else. So they also understand like the flaws and they also understand the the ways to like best secure them as well. So their expertise is very much valued and needed. that's that's my two cents.

Host: I'm glad that your current organization has that deep security mindset, right? Like often what happens is when you are a startup, your primary focus is just to build things and get to product market fit, right? And so you're not thinking about security, it's always an afterthought.

And for no no fault of theirs as well, right? Like because security is not the f not the driver of your business. You're trying to build a business. but yeah, it's amazing to hear that your organization has that, had that or from day one, maybe so that you have a better security posture and or foundation which helps you build more programs and improve it even further.

Alma: Yeah, the the only one last I think like this is one of my colleagues at some point had mentioned this, that you know, like instead of like seeing security as as a cost center, seeing it as something that will like help your business. because when we do vendor management, you know, like we evaluate vendors and on the security controls that they have.

And so and we're also like selling product, and so like someone else is evaluating us as well. So having good security practices kind of like helps us gain more business, gain more trust. So i that change in mindset I think like was also I I I thought it was like very interesting and amazing take. And I think that that shift in mindset is really helpful.

Host: Yeah, yeah. And I think it ties back to what you said earlier, right? Like it goes back to the culture that you have at an organization level, how and that sort of drives the rest of the organization, not just security like rest of the organization to also feel responsible when you're doing when you're focusing on secur security. you're not just thinking that hey, security team just gave me bunch of vulnerabilities that I need to fix. And you you you do not have that mindset, right? That hey, how does it help and things like that?

Speaking of vulnerabilities, now nowadays we hear a lot of vulnerabilities being discovered. every day we hear hundreds of CVEs being found because of like fable or mythos level models becoming available. now, how should enterprise teams prepare for for a world where there are like volumes.

Like even today without AI, like if you do a scan there are hundreds of vulnerabilities, right? Or even thousands of vulnerabilities. Now bring in AI, on top of that, there are even more. So how how do you prepare for it?

Alma: Yeah. amazing question. And I I I'm very passionate about vul management. I've done it for like a little bit. And I am of the opinion that even yes, of course, there's an increased volume. There's no denying that there's models are getting those those ones existed. We're just getting really, really good at finding them. The models are of course like just leapfrogging through and finding so many things that I I I I I think the the hugging face one was like the recent one that happened, like yes, so they they they're doing amazing work.

I will I trade like I will state this though that the number of finding ones hasn't haven't really been the issue. Fixing fixing them, right? Like that has always been the challenge.

You mentioned this already, like even before AI we've had like volumes and we didn't know like what to how to like manage that. All organizations prioritize one management. very few are able to like be are able to kind of like get a you know get a hold of and say yeah a a lot of organizations focus on a prioritised wall management but very few are able to kind of like get the program correct and the reason for that is we need to first understand that just because something is marked as a CVSS high or like a critical or or CVSS 10 or a critical or a high doesn't mean that it translates that way duh that translates that way for your organization.

We need to add more context to things, right? Like is there like an exploit available for that, for that one? Is it remotely exploitable? Is the service that that this one is on, is it like exposed to the internet?

So there are like a lot of these contexts that are very important that will help you prioritize what are the things that I need to take action on immediately are. What are the things that can like wait a few a few days to a week? And what are the things that I'm okay never never touching?

I think AI can kind of like help us there as well, where it can add a lot of that context, triaging those ones, being on you know, like unless you have like a huge team kind of just doing this day in and day out, it's very difficult to kind of like even triage them, prioritize them and get it in the queue. AI can kind of like help accelerate that, kind of help identify the ones that we need to have our immediate attention on, group them together, club them together, see if there are compensating controls that we can add to kind of like lower the risk.

But it's no at in the post-AI world, addressing ones I feel is no different than the one like what we've done previously. I think we have to get the fundamentals right. We have to make sure that we are emphasizing on patching on a cadence one or no one get into that habit, right? and and and have a program around it.

And once we and and having a very robust and extensive well management program that we have buy in from from from different teams that we have that that we are able that they have their time, they card out time to help remediate those things and we have metrics again we've going back to the metrics to like show how much of a progress that we've made. I think all of these little moving fundamental pieces still hold true in a post AI world.

Host: Yeah, I love how you connected to the like building trust with other teams so that you ha can have some carved out time for vulnerabilities, fixing vulnerabilities now that the, like volumes are going high, we are let's say leveraging AI for the context, the organizational context on top of it, so that you can reduce that volume to a manageable chunk in a way, and then work with other teams to get those addressed.

A question that Danny has asked in the same for the same thing is like how has this vulnerability how has vulnerability management changed with the influx of disclosed vulnerabilities or bug bounty reports? Like for organizations they might have, right? Like bug bounties or vulnerability disclosures. Now like famous curl project has paused their bug bounty entirely. Like how do you think about that?

Alma: I I think it's important to acknowledge like teams are overwhelmed, right? Like with the amount like submissions that we're getting, of course, like everyone's overwhelmed. There's like there's a lot of volume to go through and we're figuring it out in real time, right? Like it doesn't I think like we'll have a more definitive answer like two years from now.

I do again, I wanna reiterate like those fundamentals, right? Like that we've always had and have we've always built if there's a bug mount, there's like a pipeline that we that it comes through, there's a val validation process, there's a verification process; all of that. I think like they all still hold true. Volume is the problem right now.

And I think again, making sure that we're using AI for a lot of that automation, a lot of that con enriching that context, even like drafting those PRs to like help get like teams started. I think leveraging those things have is probably what we're gonna like is probably the only way that we're gonna like be able to scale, adding more engineers.

Yes, it will help to some extent, but we have to leverage automation to to a larger scale. and I think again, making sure we the the other are other principles where once exists but also like are we able to like segment things off? Are we able to add more compensating control so it like buys us a little bit more time? that's another p another part of that's important.

Host: One of the things that you mentioned, which I want to maybe double-click on it, is that when the volume is high, we can certainly leverage AI to add the business context and things like that. But that also means you need resources as in let's say tokens or AI capability or humans, right? For organizations who are already short staffed in security.

Like let's say the COVID project, right? They were getting bombarded with so many reports and they were like we can't humanly it's not possible to do it. So they said we are just pausing it entirely. So for organizations maybe who where they do not have enough resources, this will impact them a lot, right? so that's where like there is an argument coming up where vulnerable management is a losing game, we cannot do that, it's not manageable, we should shift to detection and response. what's your thought on that approach?

Alma: I don't think it's one or the other, right? We've always emphasized it layered security. We it's I I think of more i they're kind of like they go hand in hand. So we need to have good, very robust, very strong well management program to address things before becomes a problem. But some things are going to become a problem. We are going to miss some things, and that's where like detection response is gonna be like absolutely important, extremely important.

So I think it's kind of it it's always going to be layered security. Why we cannot even if we're able to we're never going to completely eliminate risk, right? Like completely eliminate no preventative control is like 100%. There's always going to be something that slips through.

And that's how even pre AI, that's how we build things, is making sure we have these layers. So like if like one gets like something gets missed there's like another layer to kind of like catch it and hopefully like mm remediate. So I think both are important, both are necessary, I don't think. I also like think if you take away resource from malmanagement and put it to detection you're gonna now have the same problem where you're gonna have to like have a humongous detection response team. So you're you're gonna have like deal with it at some point. I would rather deal it upstream and kind of like keep building these layers to to to hopefully like catch as much as possible.

Host: Makes sense. Another.. like you mentioned about let's say vulnerabilities volume, one way to manage is maybe at the business context using AI tools to reduce the volume in a way or focus on the prioritized ones. or sorry, focus on the ones which have would have potential impact for your organization. other than that, like any other effective ways to prioritize between the like with the all the noise? What other attributes, let's say you look at when you are trying to prioritize the vulnerabilities?

Alma: As I as I said, like business context, what is important for your business? What is the worst day security-wise that like that that looks like for your business, right? Identifying your important very high-risk and very valuable assets. that's like important to know. and then kind of like mapping those ones and translating that that that risk score for your environment is important.

So as as I already mentioned, like I think looking at different parameters of is this something that there's like an exploit available for you as it like if it is exploited this will be super bad. But like we do do we even have like a working POC for this? is this is this one on a service that is exposed to the internet then I will like probably call an incident and like pass it right now. But if it's something that is like a segmented off and you know like I can I it'll buys me a little bit more time.

So business context and mapping what that one means into your environment that I think is it's always been important, and I think like, even specifically right now when we're gonna like deal with so much volume, it's gonna be super important and critical that we prioritize the things that that make the most impact for us.

It is very easy to kind of get you know be like okay like it's too much to triage and we'll just like kind of like just say anything that critical we'll just like call that like as high priority and and and that is and I I don't think that's the wrong way of doing things.

I just think that it because of like things and trends that we're seeing in the industry, it might become very overwhelming for teams patching that because now every the every other day you're gonna have like a very critical one that like just needs to be all hands on deck. So this is where like security teams have to be like very mindful of like what we are sending, sending along. And if you're saying something is critical, then other teams will be like, okay, like they've done their diligence, they this is like absolutely something that needs attention.

Host: Yeah, yeah. Yeah, and versus if you say everything is critical, that means nothing is critical, right? Then everything is reprioritized in a way. so I think what what I gathered from you is like business context like things like whether the asset which has a vulnerability is a public publicly accessible. If it is not, maybe it is of a lower priority versus some other asset which is.

Alma: Yeah, yeah. Nothing is critical, yeah. Ex exactly.

Host: Whether the vulnerability is exploitable or not, and if there is an exploit available somewhere, whether there is a patch available or not, things like that, right? Like imagine if there is a vulnerability which has an exploit, but it is not being exploited right now, or there is no patch available, even though you prioritize it, there is not much that you can do, right? So some of those factors definitely help you with the prioritization. Makes sense. One of the things, like since we are in the AI age.

AI is being thrown at everything, right? Hey, you can use you can use that for prioritization, you can use it for fixing and both attackers look at it to generate maybe exploits and attack, and defenders look at it to see how we can be one step ahead of the attackers. What's your experience been so far using AI for like security?

Alma: I haven't played around much with AI for defense side sorry, attack side of things. From a defense standpoint, I think so. For me personally, AI has been like really helpful in automating away a lot of mundane things. So, like for example, like risk reviews, right? Like there are very set parameters based on which we kind of like do our analysis. And if we're able to like it's a repeatable process and it's something that you can add context to, and it's something that AI can like do very well.

I've also like use it very heavily for brainstorming if there's like threat modeling things like that to kind of like make sure there's like completeness and I am able to repeatedly like give similarish or like I'm a consistent consistent advice and that's kind of like what that that's some something that I like, help use AI to, like help me ground.

There is significant productivity gains gains from from a securities team standpoint. As I mentioned, I recently started a job, and being able to ramp up this quickly would not have been possible if it wasn't for AI, right? So there is a lot of productivity gains. I I I kind of like keep telling my like this this example of like it AI is like a very, very smart toddler. So it is it is like it still needs to be grounded correctly, it needs to be challenged.

It it you still are the one in the driver's seat, at least right now, right? Like you're still the one driving it. so help it to like augment your program. Don't use it to like replace engineers. I don't think we're yet there yet. I think we have to understand the limitations. We're we're kind of like we have the we're in a very unique position where we're finding all of this in real time, right? Where what are the limitations? What to your point, like if you're there are even like cost based limitations that maybe at at some point it might not be as effective to just kind of just like throw tokens at a problem. So I think they're st still figuring it out real time. The productivity gains and the gains from AI, they're undeniable, huge proponent of it. I am a big fan. however I'm also like very cautiously optimistic where I I I understand that there are limitations that we are still like figuring out.

Host: Makes sense. One of the things that you had mentioned earlier, right? About let's say you have tools but you are not adopting it, you are not fine-tuning it, using it. One of the questions that Eric has asked, and I'm connecting to AI and security tooling, he's trying to under ask, like he's asking, should people consider to use AI security solutions or run away from AI security solutions? Now that we we are still in the driver's seat, right? We are just maybe guiding maybe a smart toddler. Should we do that ourselves or we go towards a secret distribution?

Alma: I would say walk very carefully, it's slowly I'm kidding. I think the fun i re reviewing or ex adopting an AI tool would be similar to like reviewing anything else in the market, right? Is it solving a problem that you have, like your organization and has, how well is it solving it and is it delivering on the things that it's saying it's delivering? so just because something has AI in its name doesn't mean that it's like good, right?

The value of the product is is it actually solving is it actually solving like something a gap that exists in the market? And if it is, then absolutely, why not, right? there i there there's there again, there's a lot of gains, especially specifically in like the detection response team. one of the things that I'm really excited about was DLP for example. It used to be like with regexes, it would be like like very black and white, right? it either it it matches or it doesn't matches. But now with AI there's like context that it can it it can look at and and and making it context aware maybe makes like this huge problem that we had with DLP a lot easier to solve.

We'll we'll find out, time will f time will tell us, but there are areas that I I have a feeling that AI is gonna be extremely beneficial in. some overpromised, but some well deserved so.

Host: So another question from Eric on AI and security is how do you think people are getting AI wrong in security today?

Alma: Hmm. I think thinking again, thinking that it's going to replace humans, replace like security engineers, I don't think that will happen like immediately. I don't know. I again I can't predict the future, but I think we still use it for like productivity gains, use it to kind of off offload the problems that you would not want to like spend time solving, but and then conserve that time and spend it on.

There's no lack of problems, right? Like we're we're always kind of wanting for like we're that there's there's always new things to solve. But if we're able to like offload the the more mundane, more repeatable things to AI, then we free up a little bit more time to focus on the things that actually matter. so yeah, I think using it wisely makes makes a lot of a difference.

Host: So one last question on this front is like if you think about it, I'm trying to compare it with the autonomous driving, right? That is one of the use cases which took a lot of time and it took a lot of yeah, it took a lot of time for us to get confident and now we can sit in Waymo a little comfortably, right? do you like this is more of a prediction that maybe I'm asking from you.

Do you think it will take ten years for us to for us where AI will be in the driver's seat or it's maybe a couple of years from now?

Alma: The way that things have progressed, it's been very, very incredible to see. I think I if we keep out at this trajectory, I think I think we're gonna I think we're gonna eve I think we're gonna like see a lot of improvements. But my my point being, even if like all development for from like AI from an on an AI standpoint like stopped even today, the amount of gains and amount of things that we're able able to do even right now, right? That's incredible. We haven't utilized the potential of it a lot of times the bottleneck isn't even like the technology itself. It's like people and processes and a retrofitting AI to like fit to your organization. And I think solving that is go what is going to be like the challenge and that is gonna like need humans and that's gonna need time to figure out. I do think like the technology is gonna like explore and be amazing.

But if we are not able to like s like solve for the other parts of things to be able to adopt it correctly. I think that you know, we're not gonna be able to leverage it to the to the fill capability.

Host: Awesome. With that, like there is hope for humans to continue for some more time, I guess.

Alma: Hopefully.

Host: With that we come to the end of the podcast. But I want to ask one last question before we end. like do you have any learning recommendation for our audience? Like it can be a blog or a book or a podcast, anything.

Alma: Yeah. so I think for me most of my information, most of my learning comes from like peers. Like of course, like ScaleToZero is like absolutely amazing. Definitely like people should check that out and have more podcasts. But also like for me like a lot of information sharing and a lot of learning happens through networking, and my mm be it my professional network on LinkedIn or be it like in-person meetups that I that I that I go to or you know events that I go to or like even my colleagues. So think making sure you're tuned in to what is happening in the industry is extremely important.

Pick whichever is the most comfortable path for you. I also like, because we've been talking about AI so much, one of the things that I I you know I I I've set up is every day like it kind of like I've I've ha I asked Claude to kind of like go and give me like a debrief of everything happening in the industry that is specific to like enterprise security that I might be interested in. you know, along with like what are the things that I need to work on, just things like that, right?

So it's gotten really easy. It just I think like making an effort and being in tune with what is happening around you is very important in security. We don't have unfortunately the luxury of kind of turning off or like going offline. A lot of things change so quickly at such a such an interesting pace that we have to kind of like keep up.

And a lot of things that become like obsolete, obsolete very quickly, and and so does our knowledge and so do we if we don't keep up. So keep learning.

Host: Yeah. yeah, it sounds like you have a well defined not an it's not an RSS feed, I understand. Like a a feed of yours that Claude gives you every morning so that you know what digest like a digest. Yeah. It's like a copy.

Alma: Yeah, yeah. It with my coffee, yeah. Like this is what is going on in the in in in in the in in the in the industry. but yeah.

Host: Coffee time with Claude. so yeah, thank you so much, Alma for joining and for sharing your knowledge and insights. it was an it was a blast.

Alma: Thank you so much, Purusottam. It was it was really cool being on the podcast. And I'm I'm really really looking forward to the all the cool things that you do.

Host: Thank you, thank you so much.

Get the latest episodes directly in your inbox