Skip to content
Scale To Zero by Cloudanix

Topic

Detection & Incident Response

Detecting and responding to real attacks — ransomware, SOC operations, incident response playbooks and the shift to detection and response.

18 episodes · 12 questions answered

Detection & Incident Response: questions answered

Should security teams treat AI as a tool or as a colleague?

Priyanka sees AI as the first technology that augments our thinking rather than just automating tasks, and because it can talk and challenge you back, it takes on a human flavor. She recalls spending a whole night at IBM analysing a 9,000-row vulnerability spreadsheet, work AI can now turn into a prioritisation in under 30 minutes. The better you build your relationship with it and tune it, the better you deliver, which is why she treats it as a colleague.

Priyanka Chatterjee · London School of Cybersecurity

Which security operations workflows can you trust AI with today?

She would trust AI more for reporting, finding data, triage in a security incident response center and investigation, where false positives have dropped a lot, though they will never reach 100%. She would not hand over autonomous response, such as disconnecting a machine from the network or disabling an account; those decisions need a human in the loop. Any tool needs tuning with your organisation's context, and its results are only as good as your data quality.

Priyanka Chatterjee · London School of Cybersecurity

What makes AI different from SOAR and earlier security automation?

Platforms like SOAR and next-gen firewalls were bought, but their automated response was rarely adopted: trigger points were inconsistent, triaging the data still took a lot of effort, and most organisations lacked mature decision workflows. As she puts it, if you cannot run something manually, it cannot run automatically. AI makes the analysis much easier so trigger points become clearer, and it can challenge you back instead of following an if-else model.

Priyanka Chatterjee · London School of Cybersecurity

What will a SOC analyst's job look like in three to five years?

Priyanka pictures AI colleagues running triage overnight, ending graveyard shifts, and having a shift handover report and a list of decisions and judgment calls ready when the analyst comes in. Most of an analyst's time today goes into going through data; in an AI SOC the job becomes making decisions, so more of the workforce will look like today's level three analysts. Whether you are working or about to enter the workforce, she says you need to learn AI.

Priyanka Chatterjee · London School of Cybersecurity

What is the difference between a knowledge economy and a skills economy?

Knowledge is knowing about something, which is what schools are structured to give you; a skill is knowing where and how to apply it. Pre-industrial work valued skills, industrialisation and the internet created a knowledge and information economy, and now that information is cheap and abundant, value is shifting back to skills. She says people with agency, who are driven, self-motivated and follow through, will be more successful.

Priyanka Chatterjee · London School of Cybersecurity

How do you get hired in cybersecurity without experience?

An ATS-compliant CV opens the door to an interview, but a portfolio that proves you can apply your knowledge is what gets you hired. For a SOC analyst role, that could show you can look at logs, have set up a SIEM at home and have tested with the open-source Nmap scanner, and AI can tell you how to build a home lab. Certifications prove knowledge but not application, so a certification plus a portfolio is hard to beat.

Priyanka Chatterjee · London School of Cybersecurity

How has ransomware changed compared to five years ago?

Behnaz Karimi says encryption is becoming almost secondary: many groups now steal sensitive data and apply pressure through legal, compliance and reputational threats, DDoS attacks, or by contacting customers, partners and regulators. Attackers also go after managed service providers to hit thousands of organizations at once, and the human factor, including insiders, is growing. Even strong backups no longer make you safe.

Behnaz Karimi · Tramarena

What are the stages of a ransomware attack on an AI system?

She describes three acts. First, the supply chain: a malicious model on a public repository passes your benchmarks and your team pulls it in. Second, persistence: it weaves itself into the ML pipeline, through preprocessing hooks and model checkpoints, and waits, around 72 hours or less, long enough to clear anomaly detection. Third, detonation: checkpoints are encrypted, endpoints go down and the ransom note surfaces through your own API and dashboard, and recovery means full pipeline reconstruction and retraining from scratch.

Behnaz Karimi · Tramarena

What is the most overlooked entry point for ransomware in AI systems?

The AI supply chain: model repositories, public repositories, third-party pre-trained models and ML framework dependencies. Security teams focus on perimeter firewalls and endpoint detection, while a model pulled in during a routine cycle passes benchmarks with malicious logic sitting dormant inside. Many organizations still lack basic AI-specific controls such as integrity monitoring and validation of model artifacts.

Behnaz Karimi · Tramarena

Are small and mid-sized companies at risk of AI ransomware?

Yes. Behnaz calls the idea that smaller organizations are overlooked a dangerous myth: they have data, and ransomware as a service lets people with little technical skill launch complex attacks. Smaller companies adopt third-party AI tools quickly without the same protection, often without tracking where models come from or monitoring what enters their systems. She recommends treating AI models and data as critical security assets, with proper validation and continuous monitoring.

Behnaz Karimi · Tramarena

How can an organization assess its exposure to AI ransomware?

Ask whether a normal IT attack can reach your AI systems, and whether a compromised AI component can affect the rest of your IT environment. Then walk through your systems step by step, honestly and thinking like an attacker: do you only use trusted models, can models run code, can a compromise spread, and do you have clean backups? Check that you know which models and ML libraries run in production and where they come from, and adapt existing security frameworks as a baseline.

Behnaz Karimi · Tramarena

How should incident response change when ransomware hits AI systems?

Isolating and eradicating is a good starting point but not enough, because attackers can quietly poison a model and it may behave incorrectly long before you notice. Behnaz says you need a way to verify models, such as tracking where they come from and confirming they have not been changed, and an investigation into how the model was trained, what dependencies it used and how it has behaved over time. If you are not fully confident the model is clean, do not restore it: retrain from scratch in a clean environment using trusted data.

Behnaz Karimi · Tramarena

Episodes

New episodes twice a month

No security question left unanswered.

Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.