Jim Reavis on AI Integration and the Future of Cloud Security at ROCon 25
ROCon 25 welcomes Jim Reavis, CEO of the Cloud Security Alliance. Key topics include the integration of AI in cloud security, the need for organizations to adapt to new technologies, and the importance of risk management. The discussion wraps up with predictions about AI’s future in security, highlighting hyper-customized solutions and a proactive approach to emerging threats.
Transcript
Hey everyone. We're back here. We're live at Qualys Rock on our day two coverage.
I'm really happy to have my friend Jim Riva sitting here with me. For those of you who don't know Jim, and if you've been in the security world, you, you should know Jim, but Jim was the founder, co-founder of the Cloud Security Alliance 2005 or 2006. That was 2008.
There you go. I was thinking about it before that. Yeah.
So, you know, I'm kind of slow, slow on the draw. 17 years I was at RSA when we had the meeting at RSA was 2008. Yeah, yeah, yeah.
I always thought it was, I, you know, I guess in the midst of time it's gotten pushed back further. 2008. It's for Jim still.
It's been 17 years. Yes. Yeah.
And my goodness, what a, what a 17 year trip this has been, right? Yeah. The CSA has really expanded its wings, really kind of fulfilled their mission.
But, you know, just when you think, what do they say? God laughs at men's uh, plants. Yeah.
Just when you think you've got your hands around things, something new comes out. I was thinking of more Al Pacino and Godfather three. Okay.
Yeah. When you're out, they pulled you back in. Yeah.
Oh, that too. That too Godfather. God.
Yeah. Well, I guess it depends who you are. That's right.
Um, but anyway, first of all, let's get a, just an update on what's going on with CSA. Yeah, absolutely. So, you know, there is this aspect of like, cloud, like where are we at with cloud?
It's getting pretty mature and honestly it's a full two thirds of our research and work and, and demands from the community is around what are we doing about ai, which is really, it's really merged with cloud now. It's just, well, it's merged with everything. Yep.
It's, yep. You know, everything has to be looked at, I think, through the lens. Yep.
Yep. How does AI affect us? Yep.
And, and so like, we're getting good indicators of what we think is gonna happen next. And kind of how I would, if you wanted to characterize where we're at, it's like version two of our AI journey where now we're getting into, and it's can be a buzzword, but age agentic, meaning we're, we're not just using the chat bots and going back and forth, but now we're trying to actually build autonomous systems. We gotta figure out where the human in the loop needs to be.
And so it's like all the building blocks, all the security best practices we need to do around that. That's, that's probably the biggest single area we're focused on right now. Got it.
Um, I, I just feel compelled to say that you, you've added a new analyst in residence over there. Mm-hmm. Our friend Rich Vogel.
Yep. Rich, rich is a guy that it's like he's is, uh, I, I hope he is not watching it. 'cause he is a little bit of a Michael Jordan to me and like really being able to execute and think about things.
He's helped so many different companies. He's, he's done, you can't defend against him like Right. Like Michael.
And so he's our chief analyst. He meets with our, um, corporate members. Here's what their strategy is, what their like real pain points are and kind of helps guide 'em.
And you know, we, we've got like thousands of documents we've worked on over the years that a curation of like those best practices can help organizations maybe a lot more than they think. But he's their navigator now, so we're like pleased to have him and Sure. I like making, you know, I'm just look thinking of the visual though.
Rich Mogul Mike Jordan redhead. Well, they both don't have much hair these days that, that's true. But I don't know if anyone's ever compared him to Michael Jordan.
Yeah. Who? Rich.
Rich. If you're watching this, you heard it from Jim's mouth, not mine. Yeah.
Um, anyway, let, let's get back to Class Security Alliance and you know, we're here at this QUALIS event, which is no longer the Qualys Security Conference, but is now Rock con. Yep. Right.
Risk Operation Center. Jim, how does this whole look? Managing risk was always at the heart of security anyway.
Yeah. But how does the emphasis on risk management you think affect cloud security and cloud security practitioners? Yeah, so, you know, we've had some dominoes that have happened in the world and people like getting in trouble and, um, corporations not like treating this right.
And so they've gotten the message CEOs, CFOs, they've gotten this message that cyber is not just like some it risk, it's overall corporate risk, financial risk, like operational risk. And so we got the seat at the table and like the issue is translating like how we operate our cloud securely to the right language and the right metrics that those groups understand. So we're getting more and more of the budget, we're getting more and more of that, Hey, you've gotta be in the quarterly like audit committee.
We need a cyber report, everyone. And they're asking better and better questions 'cause they have some personal liability around this if they don't get it. And so, um, but we're, we're still, I think there's some struggles between like people's ab I talk about the CVEs that we've sort of mitigated and patched or you know, we, we, um, these certain incidents, we stopped this certain phishing attack and like, okay, what, what was the overall financial impacts on the organization?
Did it create any sort of delay in our ability to release new products and service the customers? Things like that. So we're, we're getting there and like the better, like CISOs, I think they understand how to translate that, but the, the cloud itself, it produces, the answers are in the data somewhere.
Right. It's like finding it the needle in the haystack or the needle In the needle. Right.
And that's, and that's actually, and it kind of goes back to like some of what I, um, saw summed here talk about in some of the new solutions and what we're seeing in the industries. Well, you can actually use some of the ai 'cause it's a big data management problem to actually sort of surface like the, the information at the level that the board wants as, you know, finding specific incidents, putting the right context and doing compliance. Like, hey, I can take like how we are compliant to one standard, put it into AI and at least gimme a good 80%.
This is how you comply to something else. Sure. And so, um, but yeah.
So we're getting there, Jim, to how, how does, so you come here, look, Qualys has been a partner of the 30 Alliance right? From day one. Yeah.
Just like day one. Um, how do you take what you hear here and what you're seeing here and how does that filter down to the membership of, of the Alliance and I mean, look, the Alliance has, there's a ton of Yep. Of the vendors in this space, but there's a lot of end user practitioners.
Yep. How does what, you know, how do you filter this in? How do you, how does it become, you know, part of the bedrock if you'll Yeah.
Well we, we've always sort of had this philosophy of like, let's, let's have like a healthy, positive symbiotic relationship between practitioners and the technology providers. There's a lot of like areas where it's pretty antagonistic. Yeah.
And it's like, okay, we're, we're, we're gonna put 'em through the paces and we're gonna like, you know, test 'em and be like very tough on 'em and or we're not gonna allow the vendors into like meetings, which there's can be like some reasons where you do that, but this is where you get the information. Like on, you know, when a company like Qualys and there's definitely like several others, they aggregate, aggregate so much data that they tend to see things before. A lot of people are gonna see it.
So like we, we try to sort of create those, those, uh, communication lines. So, hey, you gotta listen to what doesn't mean you have to buy everybody's product, but you gotta listen to the things that they're seeing and how they're tweaking their technology to address these issues. Uh, 'cause we gotta be a lot more flexible and a lot more agile.
So we try to like make it, Hey, you know, positive fun, let's communicate. We're all first responders here, whether you're the practitioners or you're, you know, at a SOC that's managing a lot of different customers as well. So that's the philosophy.
I get it. I get it. Jim, we, we briefly talked to you and I beforehand about RSA coming up.
Of course I saw you last of the black hat. You know, the, the, the CSA is ingrained into the industry. Mm-hmm.
But as you sit here, it's, it's, you know, we're coming into the end of 2025 and we are ears deep in, in this whole AI agent, AI and generative AI and disruption and data sovereignty, cloud sovereignty. There's so many issues you didn't think about in 2008 for sure. Right?
Yeah. Yeah. If I had to ask you to look in your crystal ball about the cloud security alliance and where it's going the next not too far out, let's just say 18 months to three years, what do you think?
I think we are gonna have to level up our game and be much more smart to like, to handle just how much more rapid we're going to see bad and good things do. And like, I'll give you an example. We've been struggling to like create course for AI and we had this sort of breakthrough, let's have the course just have these evergreen principles and let's create prompts that you could run two years from now to say, Hey, based on these evergreen principles you articulated, give me the latest knowledge that I need with the versions of, you know, chat GPT eight or nine or whatever it is.
So like, I think we're, we're CCSA is gonna be a lot of this AI with the human in the loop to kind of guide, like our white papers are gonna get generated. Like I think next year they're gonna be generated to a degree with ai, but then like tuned. But then we'll give, like people like Rich Mogul we talked about, he'll be able to use that to say, I'm gonna create guidance reports specifically for one company.
I think we're gonna see security, just like people are talking about you're gonna create, with ai, you're gonna create applications that are unique to a person. I think you're gonna create like security solutions that are hyper customized. Hyper localized.
So I think we got some opportunities on like the data sovereignty issues and all of these things. It's just, I wish we were more proactive. 'cause we're always like, react.
Well I, I wish we were too, Jim, but, you know, you can't escape the laws of nature. And I, I I think it's almost reactive. Yep.
You know, until quantum comes in, then we could be proactive and reactive at the same time. Schrodinger's cybersecurity security. There you go.
Exactly. Jim, it's great seeing you that always keep up the great work. Good luck with CSA.
We'll, um, well if we're some source I'll see you at ours. Yes, for sure. But maybe before.
Yeah. Love that. Alrighty.
All right. Okay. We, I think, uh, the folks have you scheduled me every month or two now?
Okay. Strong tv. Okay.
Not in person, but yeah, yeah, yeah. Almost. Yes.
You I'll do those. Okay. Although you smell fine in person, so.
Alright. Thank you. Alright.
Jim Reeve is here on uh, our Qualys Rock Con coverage. I think we're taking a break for lunch. We'll be back in about a half hour, but we've got a full afternoon so don't miss it.
But for now we're out text on TV.