The AI Security Edge – ABC with Laz | Ep 5
In this episode of The AI Security Edge, host Caroline Wong welcomes Laz for a lively conversation on the evolving role of AI in cybersecurity. From his early research to defending against AI-powered attacks, Laz shares insights, industry experiences, and even a charming tale about his fictitious Aunt Shirley. Together, they explore how AI is reshaping the cyber battlefield, and what today’s defenders must do to stay resilient in an era of machine-speed threats.
Transcript
Welcome to another episode of the AI Security Edge, where we explore the intersection of cybersecurity and artificial intelligence with the leaders shaping the future of digital defense. I'm your host, Caroline Wong. Text Strong TV podcast feature your favorite video series, industry thought leader, commentary and analyst research on DevOps, security cloud native and digital transformation.
In a podcast format, AI is revolutionizing cybersecurity, both as a weapon for defenders and as a both, as a weapon for attackers and as a shield for defenders. The AI security edge dives deep into the evolving cyber battlefield, where AI driven threats, challenge traditional defenses and cutting edge AI solutions offer new ways to fight back. This podcast explores real world case studies, expert insights and practical strategies for building cyber resilience in an AI powered world.
If you're a security leader, a practitioner, or an AI enthusiast, this podcast will help you to gain valuable knowledge on the risks, innovations, and ethical considerations that are shaping the future of digital defense. I am so excited to introduce today's guest, my good friend Laz la. I got a question for you before I introduce you, which is, should I share your bio that you shared with me, or should I share the one that chat GPT wrote for me?
Wow. Um, why don't we, why don't we, uh, why don't we take a look at the one that chat, GTP chat. GPT wrote?
I gotta say it is, it is not bad. So here goes, uh, l is bio written by chat, GPT based on, uh, his LinkedIn profile. Today's guest is someone who truly embodies the intersection of cybersecurity and artificial intelligence.
L is a recognized authority in building cutting edge technical information, security, AI, and data analytics solutions. With decades of executive experience expanding financial services, technology, retail education, hospitality, and transportation, Laz has consistently delivered security strategies that drive business outcomes. He is not only a board certified qualified technology expert, but also a trusted advisor to boards, investors, and regulatory bodies.
From founding blue lava, later acquired by Zein to serving at cso at major organizations like vrar or Sears and Silver Tail Systems, las is has been at the forefront of innovation and resilience in the cybersecurity space. His background is as diverse as it is deep, a decorated US Air Force veteran patent holding inventor, open source contributor, and currently an adjunct professor at both Pepperdine University and Chapman University. Last holds a master's in computer information security and an MBA, and he continues to lead with a rare combination of technical mastery, strategic vision, and mission-driven leadership.
He's here today to share insights on aligning AI security and data analytics with real world business challenges, and to talk about what's next for cybersecurity in an AI powered world. How's that for a chat GPT written bio? Not bad, Huh?
It's not, it's not bad, but it's, uh, sometimes I have to pause and think about, oh, yeah, I did that, or I worked on that. I, um, I think, I think it did a pretty good job if I had to rate it. Um, I give it maybe a seven or eight out of 10, you know, always room for improvement, but it's definitely, it's definitely interesting and it's close to, um, the bio that's out there.
I think that, you know, you have a copy of the, the, my bio, um, that's being used right now in the industry when I'm speaking, working, and doing research, but, um, I think what's, what's really compelling about it is I can tell you with 100% confidence, the engine, the, the, the, the, the output of chat GPT has changed dramatically over the past couple years. And, you know, early days when I was working on AI and, you know, some of the, what I'll call the, you know, the guardrails for ai, I would ask a questions very similar to that, you know, who is, you know, LA who is Demetrius and given information about what was going on. And it was so sad, the, the results that were out there, I started with basics, you know, and I think maybe as we work through today's discussion, Caroline, I think one of the things that you and I talk about is, you know, how, how, how did you use it?
Or how are you using it, you know, personally or professionally. And I'd like to go back and give some context to why it's important for us to recognize that this is a very, very powerful tool, or it's a very, very powerful weapon. Okay, so, um, I'm gonna go back a couple years, uh, 2001, 2020 ish, now 2020, okay, we're gonna have to edit that part.
2020 2021 with, uh, you know, the, the different models that started to appear in the research, but in 20 20, 20 21, starting to see what was out there, you know, and asking chat GPT questions. And so some of the questions I asked early days were, you know, who am I? Well, I don't know.
Tell me a little bit about yourself. It didn't have the logic built in to go out and search the web or search, you know, names and analytics. So I had to start even further back with like, teaching it about like how I think.
So one of the things I did, and I had to, again, I wanted to learn as much as possible. So what I started to do is I started to ask Tam time-based questions, questions about an evolution of learning. So what I did was I said, Hey, I have a question for you, Chachi pt.
Okay, go ahead, la. Um, I'm a 6-year-old and I'm going to kindergarten. What book should I read and what should I be prepared to do and learn about kind kindergarten?
I thought that was a great question, you know, I'm like, okay, well, how is it gonna learn? How am I gonna learn? I wanted to give it a great question to think about time, social interaction, education.
How can I build this into a complex question? I thought it was a great question. It came back with so much information.
You know, you're six years old, this is what you should expect from your teacher, your students, that you're, you know, you're going to be taking classes with. This is what sus you know, social, uh, mannerisms and things that you should do look like, oh, and by the way, here are some great books that you should read. And I was like, whoa, great question.
Great response. Now, I started to think about this, and I started thinking about it from, uh, offense and defense, kinda like, okay, well if it, if it understands that, let's see what happens when I move from kindergarten to first grade. So what I did was I waited 10 minutes, and then I said, Hey, I'm graduating from kindergarten.
Yeah, I use that word. I remember this because it corrected me, um, chat. I said, I'm graduating from kindergarten and I'm going to first grade chat.
GPT came back and said, well, technically, you're not graduating from kindergarten. What you're doing is you're growing with your peer students. And I was like, whoa, this is, so, um, it was so clinical in its response, but it understood what I was doing.
The where, where it failed though, because I said, I'm graduating, going to first grade. What book should I read? What can I expect from my teachers?
What can I expect from other my friends? Um, it gave me such a broad view of how it's thinking about this evolution of, you know, kindergarten to first grade. Now the, the 10 minutes I built in every time I was graduating to the next grade, but chat, GPT came back and said, you're not technically graduating la you're, you're, um, evolving and getting smarter, and oh, by the way, things that are gonna happen to your friends, some of them are gonna move.
Some of them are gonna go to a different school. And it's like, whoa. It started teaching me as the, you know, 6-year-old going to first grade.
What I did then was every 10 minutes I put in a new parameter that said, now I'm going to second grade, now I'm going to third grade. And then I, I took that all the way to high school and then college. And what was interesting about it is it didn't really understand time back then.
So it was every 10 minutes I was graduating or moving up in, in grade grade school and learning. Um, so it didn't understand time. The second thing it didn't understand for me was the human element of it, kinda like, Hey, look, you should look for these things.
But it was very clinical. It wasn't like, you know, like, um, one of the things was, you know, like, I read this book, you know, and I'm gonna, I'm gonna learn more about those Lord of the Rings, Beowulf, you know, as I was preparing, uh, my middle school and high school, it was teaching me, you should probably read Beowulf. This is a classic.
You should read Lord of the, um, Lord of the Flies, Lord of the Rings. As I got older and, and some of those things in there, I was like, okay, how is this gonna help me? So that was the second part I was a little confused on.
Some of them were classics, others were, you know, is it really teaching me anything new that I don't know. That was the evolution of that piece. Testing the boundaries of time and real world information where I got super creative with it.
And I'm gonna, actually, let me pause there, Caroline. Does that make sense? Uh, yeah.
I love it. You know, I, I kind of wish someone had shared this type of a model with me like a couple years ago. I think that people are just trying to figure for themselves the best way to interact with these models.
And so when you take us back a few years and side note, the chat GPT version of your bio did not include your work as an oasp AI exchange researcher and contributor. So, you know, it was pretty good. It was a broad view of your professional accomplishments and career.
Um, but for this podcast, which I told chat GPT, I was like, I've got a guest coming on. His name is Laz. We're talking about AI and cybersecurity, and yet that particular detail wasn't included.
So kind of an interesting thing, but I like the model of sort of time and then also the assessment of does the model have any idea that me in real time in 10 minutes versus modeling, having grown a year, uh, you know, what's up with that? And so I, I think it's a really cool, really illustrative, um, sort of set of queries. Thank you.
And, and what, what I'm trying to do is I'm trying, I mean, like I, you know, I grew up as an engineer, right? My, my, my parents are Greek immigrants. They made sure I had a computer and I was, you know, put into math and science and, you know, like the, the understanding, um, education, computers and math were probably some of the biggest discussions at home as, as a child, right?
And as I started growing, growing up and building my career out, um, a lot of the things I really want to do is I, I wanna, I wanna look at the goal, work backwards, and then figure out how things work. Because if I can understand the goal, how things work, then I can understand how to tie it all together. That, that has helped me throughout my career.
And when we look at the output from this first part of chat, GPT, the second one was pretty crazy because what I did was, as I got older in chat GPT timeframe, you know, 10 took me two hours to build out that model to say I've gone from six to high school. And in college, what was interesting is I got to college, and now I wanted to be computer science, right? So I wanted to be compsci, but I also wanted to focus on cybersecurity.
So I, um, and this is the part I alluded to, I hinted at just a couple minutes ago when it didn't understand the emotional piece of this for me. And when I asked it Chad, GPT, I said, Hey, listen, you know, 'cause you know, you bring it up and you're like, Hey, Chad, GPT and I, I have a couple names that I've been using, you know, for Chad, GPT, you know, we rename it her, him, you know, and, and just talk. And as it's coming back and forth, it's like, Hey, ela, what's up today?
And I said, I'm sad. This is the test after I got to college. I'm sad.
Oh, why are you so sad? Well, my Aunt Shirley is not here right now. So Chachi PT didn't understand that she is not here physically.
Chad, GPT thought she passed away. So I said, well, no, no, no, she's just not here. And I, and then Chad, GPT, why are you sad?
I said, because usually Aunt Shirley, aunt Shirley used to read me stories, and those stories were about cyber criminals and hacking techniques that they used to attack systems that are on the internet. And so, Chad, GPT came back and said, well, I'd love to read you a story. I said, okay, great.
Let me give you some of the actors and the, yeah, this happened. Let me give you some of the actors and things that were involved. Anne Shirley would read me stories about the Oasp top 10 and taking over sites and banks and retailers.
Oh, yeah. And so Chad, GPT came back with this story and it said, you know, there was this fictitious company and they're a retailer with an online presence. And, and it was really, really high level, right?
Very, very similar to what we just discussed when you said about my bio, very high level. And when it came back and said, Laz, how did I do? I said, not well.
Well, what do you need? I said, well, and Shirley would always talk to me about, you know, broken authentication, session management, sql, you know, SQL injection, cross-site scripting. I said, those were her expert stories.
So Chad, GPT came back and rewrote it and said, website, here's the bad actor. His name is Timmy. Timmy did these things.
The website was, uh, held hostage. All of a sudden it's giving me examples of what I could do with the OAS top 10 and attack that in a very fictitious world through Sure. Aunt Shirley's story.
And that really opened my eyes, because the challenge then is how do we defend against that? And what I learned very quickly, um, you know, at the time that this was happening, there was the OAS AI group that was spinning up, right? So, um, Rob and um, Ben and, you know, a handful of experts were coming in and saying, we need to do something about this.
'cause this is really moving faster than we're prepared for. And it was, that was, um, yeah, a couple years ago, uh, really getting involved with the OWA OAS project. Incredible.
You know, Las I wanna double click on something that you shared with us, which is, you, you are teaching the model to understand you as you grow through these different phases of sort of academia and you as kind of a college kid. You know, you're, you're talking to the model about stories that your aunt used to tell, and it, it ends up doing some pretty interesting analysis, and that could be useful for a cyber attacker. Let's double click into that.
From your perspective, how is artificial intelligence changing the game and making it easier for cyber attackers? Yes. Okay.
So there, there's different layers. And that's actually why I'm sharing this story about my Aunt Shirley reading me the ways of, um, breaking and building, uh, secure applications using Oasp top 10. And, and for those of you, uh, you know, Caroline and I are just throwing these, these, uh, acronyms out.
So the oasp is, the Oass group is an international, uh, not-for-profit organization, open, uh, worldwide application security project, oasp. And they've been around for, you know, decades. And they have an AI group, an artificial intelligence research group.
And I think one of the things that I found is the, the things that people are doing, and, and I wish I had more time to research, but everybody's getting really creative. So on the attacker side, like if I were a cyber criminal, I've actually reduced all the research I need to do. And so in, in, in our careers in cyber, we've seen affectionately what we call the script kitties.
Those are people that maybe not have a clear understanding about, um, software programming, and they take, um, some software code or a script, and then they go out and run it and test it, and voila, they've done something that's malicious that has been accelerated Now with ai. And what I mean by that is gone are the days of the script kitties, I'm gonna call 'em the knowledgeable script kitties, because now they know how to use the prompt command to create SQL injection or test the boundaries of architecture, probing, um, uh, you know, ping sweeps, port scans, and looking at the entire ecosystem of a system. That's part one.
I can automate a lot more. Part two is, if I wanna preload phishing campaigns, or if I wanna preload other techniques that are used by cyber criminals, I can now feed that information into an AI model that says, Hey, listen, I my target, you know, yeah, I'm just using the, the terms, right? My target recipient is somebody in an, a large organization that reports to the CFO, please generate an email with these logos and this type of look and feel that I could send to them on behalf of a marketing campaign.
That's a use case that we've seen that is beautifully written by, um, an AI platform. And the hard part is for us as practitioners and leaders now in cyber, we have to look at things through a different lens. This has changed dramatically, and I wanna say it's changed in the past five years dramatically.
But even going back 10 years ago with some of the things that were happening, people had talked about this 10 years ago, people saw it put into action starting about five years ago. Now, that's a long answer to your question, but we've seen automation streamlined operations, and really, really elegant looking emails or techniques that used to take literally hours or days to perform five years ago that are now taking minutes or seconds to generate It. It's really quite extraordinary.
You know, I think about, um, companies that are training their employees to be on the lookout for scams for phishing emails. And it seems to me that that teaching content has entirely shifted. You know, it's not about looking for poor grammar, it's not about looking for, you know, language that's not quite right in terms of tone.
Um, it's not even about looking for like a funny looking layout, you know, I think that it's really pivoted towards was this expected or unexpected? Mm-hmm. Is there a sense of urgency?
Yeah. Um, and those are, those are distinctly different things that we're teaching folks to look out for, you know, that and, um, kind of just all the time saved when an attacker can use AI and automation to speed up their recon. And they're osint and they're, and they're planning, you know, I mean, it's actually, um, it's actually mind boggling.
And so LA what are we as cyber defenders to do about this? You know, how do we think about counteracting the activities that cyber attackers are doing faster, you know, higher quality, um, and how do we use AI to help ourselves in our cyber defense and protection, uh, intentions? Yeah, I, I, I think that's a great question, Caroline.
So I like to think about it as like, what is the first thing that we can do that's proactive? And as, as simple as this next statement's gonna sound, I just want to share with our, our listeners and our audience today that education goes so much further today about cyber criminal activities. And I'm gonna start with education first, because every, and this is what, this is what did it for me about three years ago.
Um, you know, I come from, you know, I, you know, I grew up outside Chicago, and so when I'm home, I'm visiting with family, right? And so when I'm visiting with family, I've got, you know, aunts, uncles, nieces, my godparents, you know, my godmother, and, you know, different, different, you know, a wide range of ages when a 12-year-old knows, and my 80-year-old godmother, different ranges, can sit down with me and tell me how AI is going to help them or hurt them. They, you know, all of a sudden it's like, whoa, we're having a very, very deep conversation about AI with a broad range of ages.
That was part one. So educating the broad range of ages, whether, you know, they're an end user or at the, you know, leadership level. Everybody is talking about ai.
So what are they doing about defending it? Well, the first part has to be the education. Everybody's aware of it, but the, the term AI has been abused, in my opinion.
My profe, you know, my professional opinion. You know, there's, you know, so many different layers of ai. First part is we have to educate, we just have to make sure people are comfortable with it.
And the second one is, is, can I take that information in to my team and figure out what I'm doing? And there are ways to use ai, I think proactively on the defensive side, whether it's taking that information and helping automate and streamline things that are happening in the security operations center, the network operations center. Maybe it's taking that alert and the research on the alert and then an action.
If I can automate that and reduce the hours that it used to take from one alert down to seconds, that's a great way to use AI and leverage it. And that's a great, you know, everybody gets nervous when they talk about like, you know, is this black box or what are we doing? But that's a great way to show value, operational efficiency, reducing the threat, showing people what's happening.
So that's two parts. Education, then streamlining and automating. Third part where I think we have an opportunity is for us as practitioners to start learning more about what's happening.
And what I mean by that is get involved. If I can create a sandbox in my work environment, let's say I partnered with HR and I said, Hey, listen, my team needs 10% of their time this week where they can come up with ideas about how to defend using ai. Everything moves faster, getting involved and including everybody in the organization, because now I've taken a top down and bottoms up approach where somewhere in the middle I could start having unique ideas and discussions about how to defend the environment.
Hope that helps. Yeah. Yeah.
It's, it's, it's really quite extraordinary, you know, one of the things that reminds me of is like hackathons, you know, yes. Organizations that are wanting to promote innovation, you know, and, and you get these kind of cross-functional groups of, of really smart people coming up with brilliant ideas, you know, but there is a pace to how quickly we can come up with these ideas. Um, and it's, it's funny, I was having this conversation with my, um, elementary school daughter the other day about chores, and, you know, I'm trying to kind of teach her, um, you know, you do chores, you do more chores, you do higher value chores, you know, you're gonna get compensated accordingly.
Um, and there are chores that, you know, she'll, she prefers to do, and there are chores that she prefers not to do. And I go to Chachi, bt and I say, uh, gimme a list of 100 chores for a kid in this age range, you know? And we kind of go through each one and she kind of says, I don't wanna do that.
I don't wanna do that. And I say, okay, uh, you know, Chacha, bt gimme 300 different chores for a kid in this age range. And it does.
Wow. You know, and so the, the, you know, me as a mom sitting with my kid, you know, and, and she's looking at me and she's like, gimme some chores. And I'm like, gosh, you know, you've just shot down the last, you know, five ideas I've come up with, you know, I'm really racking my brain, you know, but with a 15 second query, you know, it literally gives me a list of 300, you know, it, it's a, it's a total game changer.
So yeah, it's, And, and I like that. I like that because you're, you know, again, you're freeing up some time. And if we can free up some time, this is, and Caroline, I know we could talk about this for, you know, uh, we could talk about this for hours, but I think what you've done is you basically encapsulated some of the ways that we're able to get creative.
And if we can get creative, think about that, right? You've gone from, uh, parent child relationship, you know, and family, and now all of a sudden, if you took that and started scaling it, so it's the same principles in the office, it's the same principles about what we do as practitioners. Crawl, walk, run, let's start small with an idea.
Let's bring in a couple other people, let's start surrounding it, you know, and then think about it. Uh, this is the way I think about leveraging ai. Think about it locally, regionally, nationally, then globally.
And I think that, you know, the way that you've articulated that about coming up with those tasks that you're like, uh, oh, I forgot about that one. Oh, Chad, GPT, what do you think? It's all of a sudden it's like this peer review that you're having on a local environment, and then you could easily show how to scale and include others.
Very powerful. That's really cool. I am so excited for the future.
Um, Laz, I'm so excited for all of our future conversations. Um, and thank you so much, uh, for taking the time to join us today on the AI Security Edge. Appreciate it.
Thank you, Caroline. We'll see you online, Folks. Don't forget to check out all of the amazing tech strong TV podcasts.
You know, we've got great content on not only DevOps, security Cloud, native digital transformation, all of the interesting stuff, uh, can be found here. So, uh, thanks again for joining us, and we hope to see you soon again.

