AI’s Transformative Role in Cybersecurity | Security Boulevard Podcast Ep. 5
In Ep. 5 of the Security Boulevard Podcast, Mitch Ashley, Tom Hollingsworth, and Fernando Montenegro unpack how AI is reshaping cybersecurity — from large language models (LLMs) to agentic AI and beyond.
They discuss:
-
How AI is being integrated into modern security operations
-
The cautious approach many professionals are taking
-
The evolution from LLMs to autonomous AI agents
-
Insights from the AI Field Day event and the companies driving innovation
-
The future of securing AI systems and initiatives
This episode offers a grounded look at AI’s transformative impact on cybersecurity and what’s next for the industry.
Transcript
Hey, as always, you know, we're floating in the clouds, you know, looking for more AI, bots, robots, whatever we think we need. Welcome to Security Boulevard, the cybersecurity podcast from the Futureum Group. Every episode explores a variety of topics within cybersecurity and the technologies that drive it.
com, security boulevard's, YouTube channel, Textron tv, and all of your favorite podcast platforms. Let's meet the panel for today's episode. It is my two favorite co-hosts.
Mitch, how are things going today? Hey, as always, you know, we're floating in the clouds, you know, looking for more AI, bots, robots, whatever we think we need, that's gonna happen. No, we're doing really good.
It is, it is conference season. Fernando and I are on the road, if not every week, pretty much other week. I think we fly by each other.
They go into different things or attending virtual events. So it, it's, it's actually Christmas. It's come early.
We get lots of presents right now, so it's a lot of fun. Absolutely. Speaking of presents, so yeah, uh, we're, we're recording this in, uh, in late October.
And, um, as I, as I speak to you from, uh, from Toronto, the, the, the Blue Jays are the World Series and whatnot, right? So, uh, and tying this to event, uh, last week I attended a local event, and, um, uh, and, and I'll get to that. I'll get back to this.
Then there, there, there's a, there's a relevance to the topic, but I attended the local event, and, uh, I, I was fortunate enough to win an official Blue Jays jersey on, uh, uh, the, the, we ran a cahoots game, like, and I was, I was the fastest with the, with the things that was fun to, to, to win an official jersey. So I, I had that. So, yes.
Uh, so Christmas came early. Yes, and yes, Mitch, we are all, uh, we are traveling a lot. Uh, this week I happened to be home, but then I think I travel five of the next six weeks or something like that, That that's our life, right?
Is once we get into the fall, it's time to go out and do stuff. If only we had something that could take care of all of that for us, some kind of magical solution that would think for us and do all the things. Oh, wait, that's right.
I forgot that that's ai, that that's the promise, right? Like, I, I keep seeing all of the things online about how it's, it's gonna make my life easier. And, and then I think about all the security that that has to deal with ai.
And, and we've actually seen that a lot recently. Uh, if you look in the news, there's a lot of companies that are making moves to kind of shore up some of their AI things, and, and some companies flat out need to add capabilities to get ready for that. And so, I, I think maybe, you know, we, we've kind of danced around it in a few episodes already, talking about how AI is changing the landscape of security.
And, you know, uh, last year, LLMs were the hot thing. Um, you know, or as I like to refer to it, uh, slightly advanced in schizophrenic auto complete. Um, and now we're into the agent, uh, realm, you know, uh, trench coats and glasses and, and trophies, uh, walking around and trying to look all cool and swab when in fact they're, they're probably more like the bumbling keystone cops agents right now.
Um, and I'm not biased or anything, but I, I wanna open this up to, to you guys because, you know, you, you kind of see this from the forefront of the research side of, of the future and group. How, how has agentic AI kind of leading this charge to redefine security as we know it? Well, security is your area.
You just need to go first there, Fernando. So lemme start by saying that I absolutely love the conversations we're all having as an industry around this, and I think that we should continue having them. And I am, uh, I'm surprised and, and heartened by how well we've, we've dove into the topic.
But I think that one of the things that, and and tied back to conference season, like when, when I, when I speak with, with executives and vendors at events and, and, uh, was it George B. Bernard Shaw that said that the, the, the greatest thing or the, the folly of, of communication is thinking it happened, or something like that? I forget what the, the exact quote is.
And I mentioned this because when we are talking about this, I always find that we need to, to, to ground things, right? Uh, depend on ground truth and anyway, but, uh, the, the way I like to frame this is that we are talking, we, we should, we should make, there are at least three major topics that we need to talk about. One is AI for security.
We are applying all the artificial intelligence and machine learning we've been developing since the 1950s to address security needs, right? This is the, the let's review code. This is the let's use agent to, uh, to, to investigate events.
This is the, uh, let's use, uh, uh, entity recognition and whatnot to recognize, to do data classification like AI for security. The flip side, of course, is security for ai. Your organizations are, uh, doing their, their AI initiatives, and it come in multiple shapes and sizes, and they all need security.
And we're seeing some very clear patterns there around how do you secure your agentic workflows? How do you secure the data that's going to be used for ai? How do you secure the identities that are going to be used in the, in the context of, of ai?
That's so security for ai. The third one, people don't talk as often, is this notion of, I, I call it security from ai. From ai, right?
And not here to, to Christopher Hoff who did, uh, a similar framing like years ago about cloud, right? Security for a cloud from cloud, et cetera. But the security from AI piece is, listen, if you do nothing else, if you think that AI is a fact, if you think that, uh, we're just gonna keep doing what we're doing, sadly, I have news for you.
Your adversaries are using ai, and we're seeing this rise in multiple shapes. We can talk about those in a bit. But that's the third major lag, which is security from ai.
If you'll, how do you change your defensive using AI or not in light of adversaries that are using ai? So those are the major three pillars. One other distinction I want to make is, we always talk about, I think, I think it's helpful to talk about the distinction between what I call workforce AI versus workload ai.
Workforce AI is all of us as individuals, how we are using AI in our day-to-day, within our workflows, within the tasks that we're doing. We're using, uh, LLM of choice to help us with editing. We are using, uh, uh, whatever service we wanna, oh, give me a, a summary of this particular topic or, but how AI is affecting user level workflows, right?
That's one. And the, the workload AI is the one more associated with, okay, we are building ai, we are using AI within our organization to, within an application we're building, we have a chat bot in our, in our portal, we have a, um, we're using predictive AI within something like we're, we're building it into the software that we are deploying. That is a different proposition, right?
And organizations need to address, frankly, both. So I, uh, getting off my soapbox for a second, but it's basically let's, let's keep all of these in mind. Security, uh, AI for security, security for ai, security from ai, and then workload, workload ai, and workforce ai.
So after that, we can have, we can continue the conversation. How Do I provide nuance and subtlety in a topic? I was just told that I had to go buy AI and all my problems will be solved.
Yeah. Uh, Yeah. You know, you know what it, I think, uh, I've come to the, the realization that every product segment goes through its own AI evolution, its own AI lifecycle, and it just, at different starts, at different times, it moves at different speeds.
And you can see security, the security market largely at the, let's use natural language as an interface. Let's use AI for particular generated AI to reduce some of the toil writing, uh, incident reports for you, writing your strategy for you, um, pulling, writing other content for you that normally a person would have to put together. Um, we also see it, there's already been machine learning algorithms used in correlation of events and things like that, and we see more of that even with generative ai.
Um, but what we haven't seen a lot of yet that we're starting to see in other segments is creating, having AI do work for us, AI agents doing work for us, moving eventually to agent. And I think, you know, security folks are, are cautious bunch, right? They're skeptical bunch.
And they're, that's just how we're wired. And that's okay, because if, if they're gonna deploy it, uh, it's gonna be secure. They're not gonna be you like the software guys who wait to, you know, forget, forget about security until we've already built it, and then we go add security in.
So they're naturally gonna be, I think, more thorough and cautious of it. So I, I'm waiting to see, or looking for, let's put it that way. So what's the breakthrough, uh, moment in AI in security products and either moving to something more like agent based or agent or, you know, uh, Cisco had their Cisco data fabric, right?
They're solving their own data problem that they need to contextualized, be able to use AI across not only the security products, but other others. So it's interesting. I'm, it's, I'm not pessimistic.
I'm optimistic about it, but I think it'll have its own curation rate and, uh, how it goes into market. Part of me wonders, will it, will it ever get to that point though? Like, because everyone looks at this and says, oh, this is the next cloud revolution.
And, and I agree that there's gonna be a huge impact on it, but I also think back about a lot of the other things that I've seen that we're gonna completely revolutionize and upend the market that didn't. And, and I have a bigger pile of those things over here. And part of it is that, and we see this all the time in the, the hype cycle is there's a magical revolutionary thing that doesn't have a really good use case right now, which means we're gonna apply it to every use case, and then we're gonna hit a point when we realize that no, it's really only good for a few things, and it does those things really well.
And, and if we apply it that narrowly, it's a success. But the people who are trying to convince me, or you or anybody else out there, that it is the panacea for every problem that you could possibly have are the ones who wind up walking away disappointed. Conversely, they're usually the ones that walk away to a different technology and go, no, no, no, no, this is the one, this right here.
I know I said that last week, but this is the one that's gonna change everything because, and then they try out the same arguments that they trotted out again and again and again and again, because they're, they're trying to imagine a future that has something that, that, that they need, or they want, and they're not finding it, but rather than creating it, they're latching onto the next thing that they can sell to people to do that. Again, I, you know, I'll say, Mitch, I am the pessimist on here. Well, I have one, I'll be the pessimist for a moment.
I have one word for you, blockchain. That was the, the savior of the, the, uh, security world. That was the next big thing.
It was gonna transform everything that we, that we do in security. And at the time, I was very skeptical. I'm like, I get what it does, and I see the uses of it in, in crypto and some logging kind of applications.
But it took a while for it to shake out and say, okay, here's some really good uses of, of blockchain. We have some great implementations and we have some startups that made a lot of money, but it didn't, it hasn't revolutionized, revolutionized the industry. Now, will AI revolutionize it more so, or, or is this the next 3D tv, right?
We all rush down, get 3D tv and like, never have you ever watched 3D TV on a 3D tv? No, probably not. I doubt it.
Yeah, should, but, but Hold On. I don't think it's that. But, But, but I, you, you hit on something important there, and I think that people need to understand this.
We, we bag on 3D tv, right? Like, that was, that was a weird thing. Uh, thank you avatar for doing that.
But one of the side effects of 3D TV is that by forcing people to make them, they got better at making TVs. Because I dunno if the people who are listening to this podcast, remember, but before three TVs came out, the low end of the market was kind of crap. Like, like you really could go out and find like a seven 20 p panel that was kind of middling LCD performance for what we thought at the time was a reasonable price point.
Now, that same price point is like a 4K tv. And the reason why is because in the race to make 3D technology more affordable for people, they figured out how to cut costs on that. And I think that that is one of the benefits of AI is that we're putting it in there to add feature sets and do things that will enhance productivity overall.
So maybe things with AI and security don't fall out quite like we want them to. But kind of to Fernando's point, let's say on that first thing where we're doing, um, you know, AI for security, maybe by having those agents running in there that are summarizing systems and giving us recommended actions, and, you know, doing something su as simple as looking up the end of life, uh, information from vendors to make sure that there's a supported firmware release or something like that. Like those are things that would enhance the product overall, even if AI doesn't solve all of those problems.
So this is where I like to take a step back and, and I, I, I use a tagline like, oh, I never, I post something on LinkedIn, whatnot. I, I often put a tag line, never adult day in this industry, right? And I, I strongly believe that, and this is where I love how we can tie back all that's going on, right?
We can tie back the, we were, we were chatting about nation states the other day, right? We're talking about software supply chain. We're talking about like everything is coming together.
And if I have one message, like i I, for security practitioners, uh, throughout their careers, whether you're, whether you're a junior just starting, whether you're somebody wanting to get into cybersecurity, whether you are, uh, a, an executive who's been around for a while, where wherever you are, the message that I would love to give, I, I want people to take from this, is that cybersecurity is now across the board. Cybersecurity is now, uh, embedded everywhere in society. And I'm sorry for the, for the cataclysmic, uh, wording, but the thing I want to bring up here is what Tom just mentioned about the evolving panels, right?
I urge people to look up two, uh, frameworks of concepts, right? One is, uh, Simon Ley is, uh, widely maps for those who are not familiar, like widely W-A-R-D-L-E-Y. So Simon Ley is a, is a, a researcher.
Uh, he's been involved in technology for the longest time, and he writes more around, I, I'm, I'm simplifying it too much, but he writes more about technology evolution itself, right? And, uh, he has a, a framework where you think about is the technology that we are working with absolutely brand novel. Nobody has ever done this before, is this technology that, uh, is around it's brand new, but you can now customize it a little bit.
Is this technology that you can buy commercial off the shelf? Or is this technology that has now been commoditized? And the dynamics of, of, of this evolution is that as technology becomes more commoditized, one of the things that is really interesting is that the moment that it is a commodity, you can then base newer technology on top of it, right?
So, uh, why are we now why are we discussing, uh, I mean the, the, the simple example is electricity, right? Electricity is commoditized and the world runs on electricity. We, we may argue AI is, parts of AI are moving towards that commoditization, but so that's framework number one.
The other framework I think it's interesting for people to be aware of is, uh, David Snowden's Kinesin framework. Kinesin, I believe is a word in Welsh that's similar for habitat. And what he talks about is the relationship, again, it's not a security centric thing, but it's the relationship between cause and effect.
You can look at problem, they call it a making framework, and you can look at problems in the relationship between what's the relationship between cause and effect on any given thing, right? Kinin is spelled the C-Y-N-E-F-I-N fin, right? And what's interesting about the Kinin framework is that it breaks the world into four major, five major areas, but four, four, there are problems that are very clear, right?
It's a c sees for clear, uh, there's a direct simple relationship between cause and effect. If I drop a glass, it's gonna break. How do I clean the glass that breaks?
Well, I, I, I clean the glass, right? There are things that are complicated, which is, there is a relationship between cause and effect, but it takes a few more steps. It takes, uh, it takes some sort of expert knowledge along the lines to investigate it, right?
Okay. How do you troubleshoot, uh, flapping, uh, L two connections, right? Uh, okay.
You, you're not, you're not just going, oh, it's just this, you, you, you'll usually go through a series of troubleshooting steps. There are problems that are complex, complex problems are those that you don't really know what's causing them. So you run a series of experiments.
Okay, let's try this, you know, work, let's try that work. So it's a mindset of complexity, right? And then the fourth one is what they call chaotic, which is our, there is no direct relationship between cause and effect, and you're just trying to, uh, staunch the bleeding, if you will.
And you're just trying to move to a different type of problem. These two frameworks, the connecting framework to understand what kind of problem you're in. And the, the worldly mapping ideas of how technology evolves, I think should be required reading for anybody looking at AI and star, whether that's cybersecurity or development or networking or whatnot.
Because those things come together where ai, where, where these things come together in a really nice way is where do agents fit in? Well, if you look at the, if you look at the, the, the fin framework, you can derive that. Look, agents may be particularly good at the clear problems because it's relatively easy for them to understand what needs to be done.
They can be good for the complicated problems because they can reason to a series of steps, or we can infer we can teach them to reason to a series of steps, right? They may, they may even be good for the complex problems because those are the problems where we're going to run multiple experiments, try different things, and then you have a human at the top to orchestrate, okay, does this work or not? They may not be as good for the chaotic problems because that's where the human capability of intuition and creativity and, uh, communications and whatnot may take up.
And I know I'm, I'm monopolizing the, the, the mic, again, I do apologize, but I think that it's really interesting to observe the AI evolution in cybersecurity, not only from the perspective of the, the specific areas we're touching, but how technology itself is evolving, right? So, I'll, I'll, I'll stop here and summarize widely maps and the, the Ian framework should be required reading. I feel like every time I do a podcast with Fernando, I come away with like a required reading list that's gonna take me until the next episode to get caught up on.
I'm waiting for him to say there's a quiz on Friday. Oh, Crap. Now I gotta study.
But, but yeah. Don't, don't use AI to summarize. But, But that's a, a good point though, is that we are in a world now where people really would do that.
In fact, I almost cracked the joke, uh, for now to just gimme the website and I'll have, you know, notebook lm gimme some flashcards on it. But like, that's the problem that we're running into, is that a lot of the knowledge that we use to troubleshoot these systems is institutional knowledge that is accrued over failure after failure after failure. And we've seen this through systems throughout time.
We're trying to shortcut through that right now. We're hoping that if we load all of that institutional knowledge into a giant database and make it easily searchable by not us, um, that it will somehow be better. And I, I'm toying around with this idea of AI is really useful for people who have people who do things for them.
Like, like when you think about everything that AI is being positioned to do right now, it's all about making us into the kinds of people who say, Mitch, take care of that for me, like the, the, the idea of doing research on something is gone. Like, I don't want to do research anymore. I want this thing to tell me what I should know about something.
And I get the value of that. Like, if, if I'm about to jump on a phone call with Fernando and, and I suddenly need to know everything there is to know about kin and economics, give me a one pager. But don't assume that makes me an economist.
And I think that, that people are starting to rely on AI to do that, right? And we've seen this a lot when people are like, oh yeah, it's like a security analyst in a box, or it's like an army of security analysts in a box. Yeah.
It is until it hits a problem that it doesn't understand. You know, Mitch, to your point, like I was thinking about something I'm dealing with with my car right now where there's a light that comes on. So I've done the thing, well, that didn't fix it.
Well, I did the next thing and that didn't fix it. I'm literally going down the checklist trying to fix all of the things that could cause that light to come on, and none of them are fixing it. So now I'm deep down in that list of, it shouldn't be this, but it can't be anything above that list.
'cause I've already fixed those. And that's where AI falls over. And, and we've seen this over and over again.
Like, it does not know how to create a novel solution to a security problem. And what happens when someone is using something new or different in an oblique way. And, and we go back to the F five hack, right?
That that happened and people got access to unreleased vulnerabilities that, that the public doesn't know anything about. So if I get hit with one of those and my AI system pops up and goes, wow, this shouldn't have been a problem because this isn't exploitable. Well, it is.
You just don't know about it because the information that you're dealing with is not out there. And so it might take somebody thinking outside the box to turn the phrase, to come up with that idea. That's, in my mind, that's a complex problem as defined by Fernando a problem with no immediate easy solution.
And, and I think what we're gonna run into is that the more we have AI solving the mundane problems, the faster it's gonna fall over when it hits the problems that it doesn't know how to solve. Well, I think, I think part of what you're describing too, Tom, is that AI can do a succession of things for you. Um, but it starts to fall down when you really need a specific context around it.
Like I can say, write me a report on the sta the state of AI and cyber, right? And it'll write me a report just like I could ask anybody else to do one. Uh, it just has immediate resources.
Well, no, that's not actually what I want. What I want to, your earlier discussion, Fernando, I wanna know about securing a AI models and I wanna know who's doing what and what the techniques are, and if there are any emerging trends and if there are any kinda leaders in this area, right? So I have to give it the things that I want.
It's not just ask it to do something. You can ask it to do something. Um, so there's a lot of, and you can say that's prompt engineering or whatever, but even with doing that, it doesn't mean you get what you asked for.
I can't tell you how many times I've said I want a solution that doesn't involve writing code. Pretty soon it's recommending code, writing code for, I'm like, I don't want that, you know, for everyone. It just, it's a, it's like, um, you know, kind of that teenager you need to remind, uh, you know, turn off the lights and shut the, shut the door when you come in the house, right?
It's not gonna do it every time. You're gonna have to make sure that, that it actually gets done. Sorry, teenagers, we all did it.
So, um, it, it's, it's not there yet. So, uh, it, it is not ag agent, it could just turn it all over and it's gonna run security for us. But I think it, I think it's not only things you would ask somebody else to do for you, for what I find is training myself to take the things that I'm doing and ask it to do for me.
I don't wanna do that. That takes a long time. That's a lot of effort, not a lot of busy work for me to do that task.
I want you to do it. But, and the thing then you get into, you know, automation candy, I think is what you called it, Fernando, of trying to get AI to do the work for you. But, but I think you bring up a good point, Mitch and I, I wanna pick up on something that you said prompt engineering, right?
Like I, I've heard that term for a while now, you know, there, there's people that are actually teaching classes on it. You know what I hear when I, I hear prompt engineering Google searches, because that's basically a form of prompt engineering when you type in that, because there, there's the very generic, you know, why does this light come on? And then there's the kind of things that we do, right, where we type in a very specific error message and we exclude these sites and we wanna look for PDFs that have that, that loaded in there like that.
We, it took a long time for us to learn how to efficiently search through the crt, for lack of a better term, to find things that are important. And how do you impart that to a, to an ai? Like one, one of my favorite things is to see all of these, uh, you know, systems online that are teaching LLMs how to write like certain people and like, yeah, you can teach it to write like Hemingway, because Hemingway has a lot of, uh, information out there about who he's, but how do you teach it to write like, I don't know, a a security analyst?
How do you teach it to write a report that sounds professional, but also with the right tone, but also not saying, here's the deal, or it's not x it's y or sound like a marketing bot. Because that's one of the things that we're running into, like think about, you know, I I, I'm a grammar person, like the EM dash problem, right? Like, oh, it has em dashes in it, so it must be an ai, no, legal people use EM dashes all the time, and Fernando does too, but like, the reason why it uses them is because that's what it was trained on.
And so like, we're, we're running into these problems where we want AI to think like us, but we're not telling AI how to think like us, and it's trying to extrapolate and it's doing a terrible job. So when we teach AI agents to be security people, how do we teach them to be properly paranoid about making sure my VPN is up when I go to Black Hat and other things like that? Or do we just say, you know, version one's never gonna be what we want it to be, so we'll move on to version two or something like that.
So this is where I would love, I I, I, my, my another rallying cry for security practitioners worldwide, right? Is these problems are affecting us in the way that we are not going to, they're not going to stop, right? They are not going to stop because AI is too interesting across the board, like the, it's been, it's been dangled, right?
Uh, sorry for the video, it's been, but it's been dangled in front of people. Look, we can, and, and we have to address this. So what practical advice do we have for practitioners on, okay, how do you deal with this?
Well, step one I would say is you need to learn this stuff, how this works. I absolutely adore the way you, you summarize like prompt engineering of, of advanced Google searches because, uh, first of all, I think that that, that, that tracks, but the other thing is why are we doing those? Why did we, why do we have to do prompt engineering?
Well, we do prompt engineering, just like we did more custom Google searches because the tool that we were using did not learn, right? No matter how well, uh, I mean, of course Google Learns profiles and, and whatnot, the, the, the web search learn profiles, but you always had to give it context, right? You always have to say, like I said, don't search for like search only for PDFs or, or only from this site, from, from this period and whatnot with prompt engineering and context engineering, right?
What we're doing now is we are trying to teach the, the, the LLMs, right? Look, this is, uh, all that I can tell you about this problem that we're trying to solve. And, uh, please do your best, right?
And I think that there's two motions here for practitioners. One of those motions is you need to understand that this is the current state of the art as it relates to agentic systems and enterprise environments, and you need to play this game. So, okay, so you work with, what are the specific kinds of problems in my workflow where having a, an agentic capability that I have to coach all the time about what it needs to be told, like about the context, what are the problems that it can help me with, right?
That's it, right? So you as a security practitioner, as a network professional, uh, of a developer, you need to understand your own work processes. Like Mitch alluded to that help me do the stuff that I do.
You find that the steps in that work process where AI with context can help you and you take a position of, let me as a security practitioner within my organization work with you dear business developer, whatnot, on how to address this, right? So that is step number one. Like understand the constraints of AI LLMs, understand why we have those constraints and work with those constraints.
And step number two is to the extent that you can stay on top of how this is how this is evolving. I'm not saying that you have to go on archive and start reading LLM papers, those you have the time, that's wonderful, right? But it's stay on top of what the, develop what the, the, the, the, the software, the AI vendors are doing.
So one of the things I'm excited about is, uh, anthropic just announced the Claude skills, right? Maybe that's an area we can touch. Um, we have the, the, the, I mean, Tom, you brought up notebook.
It's, it's wonderful for, for some things, right? So my message to to practitioners is understand those constraints so that you can be effective securing AI and using AI for security and securing from AI within your organization, and stay on top of where that, that evolution is coming because it is coming all the time. Like never adult day in this industry.
I think we, oh, go ahead, Tom. I, I was just gonna add that the, the Google comparison works, but it also is bigger than that. Mm-hmm.
There are times when a, a kind of a single shop prompt, you know what, what's this, right? Find this, tell me this. Um, and you can give it a sentence, right?
A short one sometimes, and it'll do what you want it to do. Most of what prompt engineering or context engineering is really laying out a description. It's more like a one page product description, if you will, of what you want with instructions, right?
And, and that's when you're most likely gonna get what you're looking for. Now, the problem is you may not know all what you need, and so you'll evolve that over time. Um, and there's also a way to ask it to write the prompt for you saying, here's, here's what, here's why I want you to write a prompt about, and I'm looking for these things and have it write a structured prompt for you.
So there's, you know, in a security context, you know, do you want every security engineer to be writing a random prompt to answer a standard type of question? Probably not. I mean, if it's an important one, if you're looking for a particular kind of output with certain kind of constraints, et cetera.
So we're, we're dealing with the where state of the art of what the technology is today. In some ways, we're kind of training the model of it, and we're training ourselves how to, to use it, because you have to be in so instructive of what you need to have. Um, and I was gonna mention skills, cloud skills also, because that's a great addition innovation step forward that adds context and retains that context as a skill or information that the model can use to respond to whatever prompt you it's working on.
Um, which is another problem is memory and keeping, you know, it's, it's body of knowledge to enhance it with what you want it to know about. So it's, it's, it's evolving and it's evolving quickly, but in some ways not fast enough to live up to the hype at all, because it doesn't do what the hype says it'll do in many cases. All right, I think we're gonna have to wrap this episode.
I mean, we really probably could go on for another couple of hours. The good news is, is that we have more episodes, so we'll have another episode on this. Uh, but we hope that we've given you some things to think about in terms of how AI is transforming security and why it's not as easy as it might sound on the surface.
But one of the other things that has wonderful hidden depths, of course, is the work that we do here at the Futurum group. I know, Mitch, you and Fernando are both working on some great things. Mitch, what, what are something you've got on your plate right now that people wanna tune in for?
Um, I'm just gonna be, uh, producing a, uh, report on eight trends for late 2025 going into 2026 around agents and software development and the evolution of where it's moving next. Um, some of them are big trends, some of them are kind of natural evolutions of where we are trying to point out, like how do we, how do we make the right decisions and how we adopt these things. The other is, um, as I mentioned this is, this is a lot of gifts on the tree, presents under the tree.
This is Christmas season. So in a way, Fernando and I and everybody else, all of our listeners are gonna be inundated with the next announcement this week. It's GitHub universe next week.
It's you pick your, pick your poison, whatever the conference is. And some of those are announcements. Some of 'em are product announce, it's a feature, right?
So Microsoft comes out with a planning capability and, and copilot, yeah, it's a feature. But what it is, if you, in a bigger context, which is what I look at, is that's one of the steps of broadening beyond co-generation into the work that's performed, the tasks that are performing development with bigger context and bigger intent that you're driving it. So a lot of what I'm looking at is, yes, there's 50,000 announcements that happen, you know, between now and Christmas.
There's a handful that are really important to pay attention to. And then there's a handful of things that, that, that is telling us where we are and where we're going. Yeah, I'll be brief.
Yeah. Uh, I'll try to be brief. So there's a, there's a couple of things.
I, of course, AI is, is, is, is front and center. I just wanna comment that, uh, I mentioned an event that was here in Toronto, uh, last week. Uh, this was, uh, an event by Veeam, who last week also announced that they, they're, they're acquiring security ai, right?
So this interplay between data protection with cyber resilience and, and AI is really interesting. It's one of those areas we're, we're, we're tracking. We wrote, we wrote up about the the acquisition.
We'll be following stuff like that. The other thing that, um, that we're working on is I am working on, on security operations platforms, right? This, how does the evolution of, let's call it the evolution of the sim XDR and others, right?
Uh, with ai. So that's coming in the, in the not too distant future. And the other piece I'm, I'm, I'm working on is almost going back to the earlier point where we talked the other day about nation states and whatnot.
What does the, the, the landscape look like for a security organization nowadays in terms of what has to be global, what has to be local and, and, um, uh, data residency and, and, and concerns around those areas? Of course, AI plays a part too. So, um, that's what I have in, in, in the, uh, in the draft board right now.
And, and it's working its way towards, Well, if you're very interested in ai, maybe in general, not specifically about security, uh, AI Field Day is happening this week. com, you can see a lot of companies that are working on these very problems and learn a little bit about how they're trying to solve them. But don't forget that we have a lot of video about this from a lot of different, uh, events throughout this year.
com/tech field day. I also wanna thank each and every one of you for listening to this episode of the Security Boulevard podcast. If you enjoyed this conversation and you want to get more reading homework from my friend, Fernando, please subscribe on the YouTube channel or your favorite podcast application.
We don't want you to miss an episode. We also appreciate you leaving us a review that helps the show grow. com and RUM Group.
com, the Techstrong TV website, or check us out on the Techstrong TV app that's available on Apple tv, Roku, and other smart devices. Follow Security Boulevard on X, Twitter and LinkedIn. Just look for security BLVD and you get lots more content besides just this podcast.
Thank you all for tuning in, and we'll see you next week.