Ep 111 ·
AI: Your Next Tool or New Colleague? Next-Gen Security Skills with Priyanka Chatterjee
Priyanka Chatterjee (London School of Cybersecurity) says treat AI as a colleague: trust it for SOC analysis, keep humans on response, and build skills.
Topic
Detecting and responding to real attacks — ransomware, SOC operations, incident response playbooks and the shift to detection and response.
18 episodes · 12 questions answered
Should security teams treat AI as a tool or as a colleague?
Priyanka sees AI as the first technology that augments our thinking rather than just automating tasks, and because it can talk and challenge you back, it takes on a human flavor. She recalls spending a whole night at IBM analysing a 9,000-row vulnerability spreadsheet, work AI can now turn into a prioritisation in under 30 minutes. The better you build your relationship with it and tune it, the better you deliver, which is why she treats it as a colleague.
Priyanka Chatterjee · London School of Cybersecurity
Which security operations workflows can you trust AI with today?
She would trust AI more for reporting, finding data, triage in a security incident response center and investigation, where false positives have dropped a lot, though they will never reach 100%. She would not hand over autonomous response, such as disconnecting a machine from the network or disabling an account; those decisions need a human in the loop. Any tool needs tuning with your organisation's context, and its results are only as good as your data quality.
Priyanka Chatterjee · London School of Cybersecurity
What makes AI different from SOAR and earlier security automation?
Platforms like SOAR and next-gen firewalls were bought, but their automated response was rarely adopted: trigger points were inconsistent, triaging the data still took a lot of effort, and most organisations lacked mature decision workflows. As she puts it, if you cannot run something manually, it cannot run automatically. AI makes the analysis much easier so trigger points become clearer, and it can challenge you back instead of following an if-else model.
Priyanka Chatterjee · London School of Cybersecurity
What will a SOC analyst's job look like in three to five years?
Priyanka pictures AI colleagues running triage overnight, ending graveyard shifts, and having a shift handover report and a list of decisions and judgment calls ready when the analyst comes in. Most of an analyst's time today goes into going through data; in an AI SOC the job becomes making decisions, so more of the workforce will look like today's level three analysts. Whether you are working or about to enter the workforce, she says you need to learn AI.
Priyanka Chatterjee · London School of Cybersecurity
What is the difference between a knowledge economy and a skills economy?
Knowledge is knowing about something, which is what schools are structured to give you; a skill is knowing where and how to apply it. Pre-industrial work valued skills, industrialisation and the internet created a knowledge and information economy, and now that information is cheap and abundant, value is shifting back to skills. She says people with agency, who are driven, self-motivated and follow through, will be more successful.
Priyanka Chatterjee · London School of Cybersecurity
How do you get hired in cybersecurity without experience?
An ATS-compliant CV opens the door to an interview, but a portfolio that proves you can apply your knowledge is what gets you hired. For a SOC analyst role, that could show you can look at logs, have set up a SIEM at home and have tested with the open-source Nmap scanner, and AI can tell you how to build a home lab. Certifications prove knowledge but not application, so a certification plus a portfolio is hard to beat.
Priyanka Chatterjee · London School of Cybersecurity
How has ransomware changed compared to five years ago?
Behnaz Karimi says encryption is becoming almost secondary: many groups now steal sensitive data and apply pressure through legal, compliance and reputational threats, DDoS attacks, or by contacting customers, partners and regulators. Attackers also go after managed service providers to hit thousands of organizations at once, and the human factor, including insiders, is growing. Even strong backups no longer make you safe.
Behnaz Karimi · Tramarena
What are the stages of a ransomware attack on an AI system?
She describes three acts. First, the supply chain: a malicious model on a public repository passes your benchmarks and your team pulls it in. Second, persistence: it weaves itself into the ML pipeline, through preprocessing hooks and model checkpoints, and waits, around 72 hours or less, long enough to clear anomaly detection. Third, detonation: checkpoints are encrypted, endpoints go down and the ransom note surfaces through your own API and dashboard, and recovery means full pipeline reconstruction and retraining from scratch.
Behnaz Karimi · Tramarena
What is the most overlooked entry point for ransomware in AI systems?
The AI supply chain: model repositories, public repositories, third-party pre-trained models and ML framework dependencies. Security teams focus on perimeter firewalls and endpoint detection, while a model pulled in during a routine cycle passes benchmarks with malicious logic sitting dormant inside. Many organizations still lack basic AI-specific controls such as integrity monitoring and validation of model artifacts.
Behnaz Karimi · Tramarena
Are small and mid-sized companies at risk of AI ransomware?
Yes. Behnaz calls the idea that smaller organizations are overlooked a dangerous myth: they have data, and ransomware as a service lets people with little technical skill launch complex attacks. Smaller companies adopt third-party AI tools quickly without the same protection, often without tracking where models come from or monitoring what enters their systems. She recommends treating AI models and data as critical security assets, with proper validation and continuous monitoring.
Behnaz Karimi · Tramarena
How can an organization assess its exposure to AI ransomware?
Ask whether a normal IT attack can reach your AI systems, and whether a compromised AI component can affect the rest of your IT environment. Then walk through your systems step by step, honestly and thinking like an attacker: do you only use trusted models, can models run code, can a compromise spread, and do you have clean backups? Check that you know which models and ML libraries run in production and where they come from, and adapt existing security frameworks as a baseline.
Behnaz Karimi · Tramarena
How should incident response change when ransomware hits AI systems?
Isolating and eradicating is a good starting point but not enough, because attackers can quietly poison a model and it may behave incorrectly long before you notice. Behnaz says you need a way to verify models, such as tracking where they come from and confirming they have not been changed, and an investigation into how the model was trained, what dependencies it used and how it has behaved over time. If you are not fully confident the model is clean, do not restore it: retrain from scratch in a clean environment using trusted data.
Behnaz Karimi · Tramarena
Ep 111 ·
Priyanka Chatterjee (London School of Cybersecurity) says treat AI as a colleague: trust it for SOC analysis, keep humans on response, and build skills.
Ep 109 ·
Behnaz Karimi (Tramarena) explains how ransomware now targets AI models, pipelines and supply chains, and how incident response must change for AI.
Jason Jordaan on digital forensics, the importance of meticulous documentation, and preparing organisations for investigations.
Reanna Schultz, founder of CyberSpeak Labs, on modern threat detection, false-positive handling, and staying ahead of threats.
Mauricio Duarte on building resilient security culture, behaviour-based awareness programmes, and incident-response speed vs accuracy.
Giorgio Perticone on the incident-response lifecycle from detection to recovery, staying calm under pressure, and containment.
Cloud incident response with Hilal Ahmad — monitoring MTTD and MTTR, and why out-of-the-box security tools are never enough.
Kailash Havildar on logging, monitoring, and detective controls in cloud security — what to capture and how to act on it.
Pablo Vidal on incident response and detection, cross-team collaboration, and hiring for mutual fit in security roles.
Josh Pyorre on threat hunting, creative security research, and the role of GenAI in uncovering new attack vectors.
Jeffrey Wheatman, Cyber Risk Evangelist at Black Kite, on third-party risk management, vendor prioritisation, and procurement decisions.
Gerard Johansen on incident response, digital forensics, threat intelligence, and training engineers on evidence collection.
Ashwin Patil on security applications of Jupyter notebooks, data analysis for threat detection, and interactive investigation workflows.
Emily Zakkak, cybersecurity specialist at Senowit, on defending against social engineering, phishing, and MFA best practices.
Karan Dwivedi on blue-team operations, partnering with red teams, and preserving forensic data accuracy.
Rodrigo Montoro on AWS security monitoring, threat modelling for new services, and restricting high-impact IAM permissions.
Paul Dyer on red, blue, and purple team operations, threat-landscape awareness, and open-source security with SBOMs.
Swati Anuj Arya, CISO Office leader at Amazon Pay, on simplifying cloud security and responding to data breaches.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.