AI Security: What Enterprises Are Getting Wrong
The CSA Alliance has released their annual report on AI and security. In this interview with Alan Shimel, Dr. Anton Chuvakin of Google’s office of the CIO and Hillary Baron of CSA Research, they discuss the state of AI security and governance, how companies are actually adopting ai (both agentic and generative) and most importantly how organizations are integrating this into their business practices in a secure manner.
Transcript
Hi everyone. Welcome back here to Text Trunk tv. I'm happy to have these next two folks on here with me.
Let me introduce you first to Hillary Baron, who is the a VP of Research for Cloud Security Alliance. Hey, Hillary, how are you? Doing well, how about yourself?
Very well. So I gotta ask him our, well, I'm gonna come back to you one second. Let me introduce our next guest too, though he needs no introduction to those in the cybersecurity world.
He's a friend of mine for longer than we both care to admit, but, um, he's currently in the security advisor. He's a security advisor in the office of the CISO at Google Cloud. It's been with Google Cloud now for a number of years.
My friend, Dr. Anton Traian. Hi Anton.
It's great to see you. Hello there. And the fun topic.
It is ai, right? Absolutely. So, Hillary, back to you.
Yeah, Anton and I have another friend that we know a few years who's recently joined Cloud Security Alliance. Uh, friend Rich, mogul Rich, Yeah. We're happy to to have him on board.
I bet. Well, rich is a great guy too. Do you work with Rich then in research or is he more an analyst?
Uh, he's working in a slightly different capacity, but we certainly lean on him for all of his, uh, years of expertise, certainly. Yes. Yes.
And so it's Rich. I think he's belonged in the CSA for a long time. I'm glad to see him there.
Oh, yeah. Why don't we talk a little bit about your role at the CSA though? Yeah, so I am a VP of research, as you mentioned.
Um, a lot of what I'm doing is helping to lead a team of analysts to do research on everything related to the cloud. We do it in a number of different ways. Um, so we have local working, or not local working groups, excuse me, but we have, uh, virtual working groups that are topic specific on, um, everything from, you know, blockchain, when that was really popping off at one point.
Um, things that are more cutting edge like AI and quantum, although those are becoming a little less cutting edge and more just actual part of reality. Um, and then, you know, more kind of classic, just like cloud security, um, controls and the cloud controls matrix. So our portfolio really runs the gamut.
But yeah, I just help lead the team and we're always exploring and looking at new topics and AI is one of them. Very cool. Anton, you are here.
Well, I, as I mentioned, you're a security advisor in the office of CSO and Google Cloud, but you are also, and you've been involved participating, volunteering with the CSA for a number of years. I mean, it's interesting and of course, uh, kind of a fun collaboration, but at the same time, I continue to be surprised that for some people it's not AI that's new, it's cloud. And to me, that's why the mission of CSA is so important because I, while I encounter CSOs who are new to this technology disruption, and I assume it's ai, and sometimes I discover too much of my surprise that what they mean is cloud.
So it's interesting how the mission of CSA, even in the original sense for cloud is hugely important. But of course now there's AI and CSA is helping quite a bit with all this work. Excellent.
Excellent. Hillary Baron talked a little bit about CSA and their mission. You know, Anton and I were probably at RSA in that early formative, meaning, geez, was it 2005 or 2006 maybe?
Um, mogul was there, and of course George was there, and, uh, Jim Rivas was there. Uh, Hoff, Chris Hoff was there. But the, the CSA has, it's certainly grown, changed, morphed, as you mentioned.
The research aspect of it is, is, has a pretty broad charter, but there's the working groups, there's all of these that the, the, the events, I'm sure you'll be at RSA this year on Monday doing the CSA. We're usually in the room next to you in our DevSecOps, uh, uh, event as well. So there's that.
What else about the CSA? Can we tell people? Uh, I mean, we really do anything when it comes to furthering best practices and standards when it comes, when it comes to cloud security and kind of anything related to cloud security, which, you know, AI ends up being an extension, which is how we kind of got into, um, that as being part of our portfolio.
But yeah, we do a, a number of different things. I mentioned the working groups, because obviously that's near and dear to my heart. Um, we do ad hoc research as a part of that with, um, our members.
We have chapters, so if folks are looking for something that's more local to their area, um, whether it's a state or country, those are also available for folks to meet, network and learn more about the latest of, um, what's going on with cloud in their local area. Um, there's also events, again, those run globally. We have a lot of virtual events, um, and we found that people really like those.
Um, so that's been, um, probably a, a big change. We used to do a lot more, um, that was in person, but we still do have our in-person events. Um, as you mentioned, uh, we have our, our RSA summit that's always at, or excuse me, our CSA summit, that's always at RSA, too many essays going on in those acronyms.
Mm-hmm. But yeah, we, we really do a, a whole number of different things. We've got trainings even, so you name it, and it comes to research and, and furthering people's knowledge about cloud security and cloud related topics.
We're doing it. Very cool. Very cool indeed.
All right, guys, let's dive in. Mention, uh, Anton, you mentioned AI once or twice. Mm-hmm.
This is a new report out of CSA, the state of ai security and governance. I mean, I'm not gonna ask you why ai, because, you know, we all know why, but, um, why now? Right?
What is it? Did something trigger it? I think that the, well, first is, I think it's not the first SER survey on the topic we are doing.
Uh, I think it's the second, the third I, Hillary knows better for the exact number. Uh, sorry if I fumbled it. But it's interesting that the, the why now is kind of more about the tracking it over, over tracking the changes year after year.
And I feel like this year we've noticed a lot of the mainstream shifting because if you judge AI progress based on, you know, Twitter or social media, you assume everybody is far into the future. And then you briefly look back and you realize, again, as I mentioned before, that cloud is new for some people. So to me, this survey, uh, this year, uh, showed signs of the mainstream adoption of some of these elements.
Mainstream concerns about security of ai, mainstream understanding of governance. And of course there is a lot of hiccups about how quote unquote, the mainstream is doing it. But to me, that's the why now moment, is that I see the mainstream move, not the innovators and leaders, not just the innovators and leaders.
Fair enough. Fair. Um, Hilary, if you wouldn't mind before we jump into the, like, let's the findings of, of the report, give us some demographics behind the report.
Yeah. So what we're looking at for our audience, it's, you know, primarily going to be CASA audience. So we're talking about people that already primarily have an interest in cloud security and in tech.
Um, so we can kind of view the majority of these folks kind of through that lens. Um, but when it comes to location, it was pretty evenly spread. We had about 36% that are from North America.
I think it was like another 30% that were from the AMEA region. Um, and another like, I think 25, 20 7%, something around there, um, coming out of Asia. So pretty even split when we're talking about globally.
Um, so broad, very broad when we're talking about, um, who, who we're talking about is in terms of location. Um, the organization sizes tended to be on the two ends of the spectrum. So we had a lot that were kind of on that lower end under 5,000 employees.
And then that upper bracket of like 10,000 plus employees. So not a ton in that kind of like mid range. Um, and then when we're talking about like the job levels, um, we had I think about 20% that were C-level or executive, another like 15% or so that were at that director level.
And then a third, the biggest portions were that manager and and staff level. So those kinda low, that lower end. So these are more the boots on the ground people that are actually like implementing some of these.
Um, and then obviously as I said, primary industry that we're talking about is gonna be tech, but there is a fair amount that we get from the financial services and education and healthcare usually. So there is a fair number of folks that are coming for, um, from, excuse me, more regulated industries, certainly. Mm-hmm.
I regulate that's actually very similar to our own audience demographics. Right? 52% are manager or above.
Or above. Mm-hmm. That means 48% are basically single contributor and uh, only about 11% are C level, but another, I think it's about 15% are vp.
Mm-hmm. You know, or above. So it, it, you know, closely checks our own audience here.
Um, let's ask like, you know, I know no one, you know, I've asked this question before. People do surveys, right? What were you looking to get out of this?
We want, we just wanted to hear what people said, but everyone has an angle. Everyone, you know, we have motivations. What were you looking for here?
I, I am super tempted to go with, we just wanted to learn what's going on, but I feel like I'll go and double, double down on my previous question. I wanted to make sure that quote unquote, normal mainstream organizations are dealing with this. And I looked for signs of that because I've about headed with people who say everybody uses AI and then they mean their three friends in San Francisco.
And while if they journey to another country or another region of the US and they look at not at the Bay Area startup that launched three months ago, but at a bank in Belgium to begarian them, example, or a manufacturer in somewhere else, how do their use of AI looks like? Do they, do they know about it? Like, I've met a client, uh, not a client, really more of a prospect in a certain, um, AsiaPac country.
And they kind of pointed out to me that for them, AI is a long-term plan for now they're dealing with cloud and it's going not so well. And so there are people for whom AI is a 10 in a, on a 10 year plan, not an a 10 day plan as perhaps in Bay Area. So to me, the critical question I was curious about is to, is mainstream moving and not as, is AI a good thing?
I mean, it's pretty obvious to me. And again, I wanted to get out of my quote unquote bay area tech company soup and look outside and see what's really going on. So I, I do this too, Anton, I, so, you know, it's funny, we just passed the holidays.
I use my wife's family as a litmus test. They come to my house for the holidays because they all come to my house for the holidays. It's a free meal.
What the hell? You know how in-laws are. But while they're there, look, as long as I'm feeding them, I ask them and I ask them, what are they doing about ai?
Well, what do they know about ai? Are they using ai? What do they think about ai?
And, and it's a good mix. 'cause there's young, there's old, there's in between, there's kids who are in college, people who are working older people. And it's amazing how, without even really, really knowing it, how afraid they are.
I, if you had to ask me, what's the biggest reaction you get to people when you say ai? It's a fear. It's a, it's a, a lack of trust.
It's a fear of, of maybe taking my job, right. Making me obsolete. It's, it's, it's so new and, and in the wrong hands, is it going to destroy humanity?
You know, the, the, the, the doomsday scenarios. I don't think tech people have that anymore, though. Hey, there, you know, there are plenty of people out there who believe that, but there, there is, uh, a negative connotation.
And I'm wondering, did that show itself in the survey? Guys? My pressure?
Not necessarily. Sorry, go ahead. No, I was gonna say, not necessarily.
This didn't really come up in, in this survey. 'cause you know, a lot of who are talking to are people who are a lot more excited. Their boards are really pushing for this.
Mm-hmm. They're actively working on projects. Yep.
Or planning for projects that, where they're implementing. I would say in our prior survey, um, I, I'm trying to remember Anton, was it to 2024? 2023?
I, I think 23 in the first one, there was a lot of hesitant. Yeah. Hesitation.
But I think hesitation, if I recall 2023 survey hesitation was not because AI would take over the world hesitation was because they would fail with ai. It was the fear of missing out, just expressed differently, right? There was fomo, right?
It was diff well, fomo, the current report is also full of fomo, but the early FOMO and late formal are like two different brands of fomo. Perhaps in the beginning they were afraid to fail with ai, like they're not good enough. But now I feel like they would just afraid they aren't moving fast enough or they're not adopting fast enough.
So it's more of a fear of falling behind versus fear of failure. I may be hallucinating this, I may be an LLM Maybe, maybe wait, will wait. It could be a deep fake.
But, you know, here's the thing. I, and I've seen recent surveys developers more than security people. Mm-hmm.
But 90% of developers think about that. 90% of developers, nine out of 10 are using AI in some, in some way, you know, in helping them with their development. However, 40% of them don't trust it.
They don't have any trust. 65%, two thirds of the people say it's, it's introducing instabilities into our code base, but yet 90% of them still use it. Now, is it FOMO that's driving that?
Is it just craziness? Is it a, is it a defect in the, the data gathering? I don't know.
But those kinds of numbers tell you something is missing. You know, there's a mis a disconnect here. I can, I can actually explain it because oddly enough, uh, I think somewhere last year I had this somewhat unpopular blog called an untrusted security advisor use an untrusted security advisor.
Because people always joke about how you need to have a trusted advisor, but what if you can have an untrusted advisor? And to me, there are plenty of use cases for an untrusted security advisor. For example, if I hire somebody to test my network, I don't really have complete trust in them.
I don't want to give them a crown jewel and whatnot. But there's a, a bit of trust, but I'm okay without complete trust. So there are use cases, um, where trust is not truly necessary or complete trust is not necessary, but the value is there.
And that's how I rationalize this to me, because I've, I've seen the same exact concern is like formal plus lack of trust, but in the same head, how does it work? And to me, that's how it works. It, they use it without complete trust and they either mitigate the lack of trust or they aim it at use cases where it's not necessary.
Fair enough. Guys, let's, we, we've spent all this time catching up, but let's jump into the actual results here. I always like to know what were the big three, what were the big three key findings that came out of this?
Well, I can even boil it down to probably the two of the biggest findings. I think that we had, one of the ones that really jumped out to us was how much governance is a differentiator with adopting AI and having successful implementations. So when we looked at the folks that had more comprehensive policies, we were just seeing that they're, they're using, you know, agentic AI more broadly in their organization.
They are testing AI with, um, within security. So using AI for security as a use case. Um, and then their boards tended to be more familiar with the risks, um, that they might be introducing.
There was more confidence in their ability to use it effectively. They're training their staff on ai. And that was one of the biggest associations that we really found was that governance really was kind of this indicator of overall, how well are you really doing with your implementation of, of ai and, you know, kind of whatever capacity that is.
The other big one that I think really came out was that usually what we see with security folks in particular is that they tend to be the naysayers the last to adopt. They're the, they're kind of the gatekeepers for technology. And in this case, a lot of them are already testing or have implemented AI in some capacity within their security.
Um, and that they are continuing to test that and find new use cases for it. Um, and so I think that that's really fascinating because, I mean, part of it is there's just a clear use case I think for this type of technology when we're talking about like actually implementing it. Like when we're talking about iot, I'm like, whoa, what, you know, what are security people going to do at that?
Of course, we're gonna be the gatekeepers in that scenario. Um, but yeah, security folks are, are excited about being able to utilize AI with security, which I think is, is huge. We're not the laggards for once.
That's Good. Yes. That's good.
I like the, I wanna double down on the governance, because to me this was, yeah, it's literally the first, first key finding, but it's also the, um, to me, oddly enough of a fun one because people assume that governance is dry and boring and it's like so eighties or whatnot, but it is quite central to a lot of success and it's correlated to a lot of other success metrics. So if you have rampant shadow AI ramp and shadow agents, lack of governance. Governance is not even post hoc, but basically it kind of never, or it's disconnected from reality, you're not gonna succeed.
There's almost a certainty that, uh, either a failure of projects or a disaster or both are likely. But if you do have decent governance, everything just starts looking good. And to me, this is perhaps counterintuitive because we use a, we use something fairly classic and old, like data governance, but it is strongly correlated to success, like across the board.
Absolutely. So look, in every one of these reports, there's always something that comes up that you kinda give you one raised eyebrow to maybe two raised eyebrows even, right? It wasn't on your bingo card, didn't see that coming.
What was, what was the outlier here that you didn't see coming? Um, I don't know that there's anything that we didn't necessarily see coming. I think the, the, the AI being part, being integrated into security already was a surprise.
I mean, I, I think in the back of our minds, we kind of knew that there was like a use case for it, which is why it was something that we wanted to ask about in the survey in the first place. But it was more so we wanted to see, you know, like out of all these use cases, out of all these potential, uh, ways that you could implement ai, are you doing it for security? Um, but the fact that, you know, we were already seeing progress there, I think was, was quite surprising.
Um, I think the only other thing that I can really think of was that when it came to, um, leadership, there's this big push to utilize AI and, and have these projects and adopt them and find ways to utilize AI within the organization, um, without fully understanding the risks. Um, so that was kind of something that I, you know, it's to be expected when we're talking about leadership, a lot of times we're talking about people that, um, don't necessarily understand the, the tech in the same way that the people that are, you know, boots on the ground, um, understand it. So it, it's somewhat to be expected.
But I think that that was kind of one thing that w was interesting that they're still pushing for it be, uh, without fully understanding, um, you know, what, what the potential risk is for the organization. I have one actual surprise and I have one that's sort of like, again, as I said, uh, fits the short but not surprising bucket. Uh, I mean, the second one is, um, exactly the one that Hillary said is that there is a, uh, we know we should do it, but we don't understand it.
It's a lot higher with executives compared to technologists. It's not surprising, but it's also so visible in the report where, uh, the leaders say we want it now, we don't understand it, but we still want it. And technologists are a little bit more, uh, yeah, let's understand it.
But the actual shock to me was the percentage of people who use private self-hosted models. I expected this to be really tiny, need a freaking microscope to, to look at it. In reality, it was sizable, and I still don't know what to make of it.
I feel like people maybe are using open source models or do whatever else, but it is that, that to me was a genuine shock. I I did not expect that. I did not expect to see a high prevalence.
Oh, high, anything is above tiny would be high here. High is high prevalence of self-hosted models. That to me is, is a real genuine price.
No, you, You know what, look, I think if you would've asked two, three years ago, you would see it would be microscopic. Anton, you're right. But I think today, you, you know, you have companies like Pine Cone that offer a, a hosted self model, right?
They'll suck all your data basically into the, uh, into the, uh, vector. And, and you could have a, a model. You, you know, and you still have that big frontier model behind it, but you're using that self-hosted, or, or let's call it model as a service, small model as a service or something like that.
And it's not just Pinecone, Mongo, a lot of them are doing it. Um, I, I think, I think that's actually the future. I don't think people are gonna be satisfied with a one size fit all world model.
Right? They'll have it as a background, but they're gonna want customized to their data, to their world. Guys, we're, we're almost outta time for people who wanna go maybe download the report or take a deeper dive.
Hillary, where can we send them? So you can find the report either on the Google or the CSA website. If you, um, if you find it on the CSA website, it'll be under our latest publications, and you can filter by survey.
It'll be the latest survey that we published. Okay. And Anton on the Google site, uh, it's supposed to somewhere.
You should probably just Google it. Google it. All right.
Well, Hillary Baron, first of all, happy New Year. Second of all, thanks for coming on and, and giving us a little insight into this new report. Keep up the great work.
If I don't see you guys before, hopefully you'll see you at RSA. Absolutely. Perfect.
See you there. Hillary Baron, Dr. Anton Sian here on Techstrong tv, talking about the Cloud Security Alliance, state of ai, security, and governance.
We're gonna take a break. We'll be back.