AI
AI
AI
CISO AI risk management is emerging as the defining test of the AI era, pushing security leaders beyond blocking attacks and into the middle of enterprise decisions about how much risk a business is willing to accept. That tension is playing out this week as thousands of practitioners converge on Las Vegas, where AI has propelled the cybersecurity world into a new phase, driven by startlingly advanced autonomous attacks and an urgent need to adopt technology to defend against them.
Much of that pressure is now landing squarely on the CISO, who is increasingly expected to act as connective tissue across legal, compliance, engineering and the business itself, according to Krista Case (pictured, left), principal analyst and practice lead for cyber resilience and security at theCUBE Research.
“I’ve also been thinking about this AI governance through the lens of the different roles that the CISO has to collaborate with within the enterprise — things like legal, compliance, engineering, IT,” Case said. “They almost have to be sort of the connective tissue helping to facilitate these conversations. So they’re really becoming a business enabler.”
Case was joined by Jon Oltsik (right), analyst in residence at theCUBE Research, for a keynote analysis of Black Hat USA, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how the CISO role is evolving as AI moves from experimentation into production, alongside the invite-only summits where senior cybersecurity executives participate in candid, confidential conversation that will help to shape the next generation of cybersecurity strategy. (* Disclosure below.)
That evolution remains far from universal. Only a narrow slice of security leaders have translated AI hype into a coherent strategy, Oltsik said.
“About 20% of CISOs get it,” he said. “They understand the implications, they understand what their organization’s trying to do with AI. … They’re looking at security architecturally. … The other 80% are in a state of ignorance, sometimes ignorance is bliss, or at least assumed bliss.”
That gap in AI risk management is compounded by a disconnect between the tools flooding the show floor and the practitioners meant to evaluate them, according to Oltsik. Instead, CISOs must build threat models tied to specific business initiatives, then hand executives a clear menu of choices — accept, mitigate or transfer the risk — rather than stand in the way of adoption, he said.
“You can’t get in the way, and no one should try to get in the way — you’ll get run over,” Oltsik said. “You’ll lose your job if you try to get in the way. So that’s really the way it is.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Black Hat USA:
(* Disclosure: TheCUBE is a paid media partner for Black Hat USA. Sponsors of theCUBE’s event coverage do not have editorial control over content on theCUBE or SiliconANGLE.)
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.