Bridging the Gap: CSA’s AI Security Initiatives at RSAC
Techstrong Group’s Alan Shimel sits down with longtime friend and cybersecurity veteran Rich Mogull to discuss his exciting new chapter as Chief Analyst at the Cloud Security Alliance (CSA). The two industry legends dive deep into the explosive rise of agentic AI, exploring how CSA is bridging the gap between high-level security frameworks and hands-on practitioners through their new AI Security Maturity Model and the launch of the dedicated CSAI non-profit arm. From expanded enterprise memberships to wild stories of AI-generated incident response code on the fly, this conversation is an absolute must-watch for anyone navigating the rapidly evolving frontiers of cloud and AI security.
Transcript
Hi, everyone. We're back here live. Where are we?
We're at RSAC. That's where we are. We're in Broadcast Alley.
It's been 20 years. If you haven't figured it out by now- 20- 25 years ... been 25 years.
If you don't know this guy, you probably don't know a lot about security. He's my friend Rich Mogull. Let me embarrass him a little bit.
I first met Rich, he was a Gartner analyst- Yep ... covering the DLP space. Yeah.
And shortly thereafter, though, he woke up and left Gartner, and he started his own analyst firm called Securosis, and he was doing his thing there, and he ran into a guy who had just written a book about the CISO. What was the book? " Our friend, the Candy Man, Mike Rothman.
And Mike joined Rich at Securosis, and they really... This is a time where Gartner was the shizzle, right? For security- I thought you were taking that word in a different direction.
No, I didn't. I didn't. Gartner was the shizzle for security analysts, and maybe there was Forrester, and I think some of our friends were just getting started at 451 Group- Yep ...
and stuff like that, but that was it. There was Scott Crawford here, this one there, but there wasn't... Rich and Mike really redefined what an independent analyst meant to be in the security space with a totally different model of doing research and sponsored research and all of these things.
I always admired them when I was on the vendor side of the house, and then when I started what became TekStrong. Rich, in his spare time at Securosis, though, was fascinated with cloud security and developed a cloud security solution, and they spun up a company. If I get any of this wrong, just jump in.
No, you're on. I-- Yeah. Spun up a company called DisruptOps- Yeah ...
which was putting guardrails on for people using cloud. And the suitors came knocking, and Rich and Mike sold DisruptOps, as part, were acquired by our friends, Jody Brazil, who just happened to be sitting here when you walked up. Randomly, as I walked up.
My co-founder- Well, you know what? Yeah ... and CEO.
Yeah. " So that was, I think- ... a little God message there.
That was a good one. Yeah. But anyway, got acquired by Firemon, and Rich was their VP of cloud security there for a number of years.
And then, I guess, was it less than a year ago? Eight months ago. October.
Oh, okay. Yeah. So about six months.
Yeah. Officially became the analyst for the Cloud Security Alliance. Yep.
Rich Mogull, this is your life. Clearly, we've known each other- Yeah ... for decades.
We've known each other for a while. Back when, what was it, Still Secure, and- Yeah, doing all of that stuff ... we did some advisory work and, yep.
All of it. So Rich, how's the new gig? It's great.
" Yeah. I remember day one. " I remember that.
I remember day one and two. I was here. Yeah.
Hoff, Jim Reavis. Yep. Who was the guy also with Hoff?
It's, I think, oh- I can't even remember. Yeah. But, so I got involved early in doing research.
I built their training program. I wrote some of the research documents over there, and then Jim and I were sitting there, it was last year, right before RSA, and he had this list of stuff. " And of course, it's my side thing, because I was working full-time at Firemon for Jody, who is sitting here.
Right. And I was getting ready to leave that role because Jody and I both agreed it was getting to be time, and we're still friends, that to hand off what I was doing to somebody else. " And sure enough, we pulled it off.
So it took a while, and joined in October as chief analyst and- Well, this is kind of a dream job for you ... it's great. It really is, though.
Right. It marries your passion to what's going on in the industry. It gives you an important perch.
Well, and I like the non-profit- Yeah ... angle. Well, not only non-profit, non-vendor.
Yeah. Right? No offense to Jody.
I love Jody, too. But it takes a little while to get that stink off of you when you leave the vendor space and come to more of a non-profit or a non-vendor kind of thing. That's some of why I left.
I was proud of the work I was doing at Firemon and the new stuff that, at some point, perhaps Jody will be able to talk about when he's ready for it, but very cool. But also, it's like that's not my wheelhouse. No.
My wheelhouse is the analyst, the work with organizations, doing advisory work, helping solve problems, and I like that I'm able to give away all my research for free. That was the model we did at Securosis. Right.
Mike and I are like, "We're going to give all our research away for free, have it be vendor-independent, and still make money doing it" Make money ... which nobody thought we could do. We did for a while, and it got time to be for us to move on.
The startup distracted us, and now I get to basically do that again. I love it. All right.
Enough about you and me, because we could spend all day talking about you and me. People would say we're baby narcissists. Because we are.
But we've got enough narcissists in this world, don't we, Rich? We're not going into politics. You did, I didn't.
I just said it. But anywayYou guys, every year for the last 11 years, we put on what was the DevOps Connect DevSecOps event. Yeah.
Yesterday, we kind of changed it up a little this year. It was AI Native Dev and DevOps and securing AI and everything else. We had some really nice talks there.
But for all these years, in the room next to us is always the Cloud Security Alliance. Yeah. They get a bigger crowd.
I'd pop in between both rooms when I wasn't working. A lot of people do. They pick to see who's speaking on any given minute.
Yeah. But you're up there speaking now. So I popped in to say hello to you.
You opened at 8:40 in the morning, which I got to tell you- ... as a brave man, because I know better, because people just don't get here on Monday at 8:40 in the morning. Alan, it's not like I picked the schedule .
I had a feeling that wasn't your choice. But you made some important announcements. Yeah.
Let's talk about that. Yeah. So my talk was, you know me, I always like to bring content.
And even though I don't feel bad about promoting CSA because of the work that we do, but at the same point, if somebody's in the audience, physically in a room, I want to give content. So I talked about basically the, so one of the problems that I encountered over my years of work is we have all these great frameworks and models and standards, and on the other side, we've got somebody clicking in consoles or writing command lines to get stuff done. And I did a lot of advisory projects where I was pulled in, sometimes by very large organizations, where we had to actually build out the, "You know what?
" And I tend to be like, people like to dog on security. No, I think we do a really good job with the resources we have. It's hard, and the job of a security professional is very difficult, and the people doing the actual active defense work there, that's really hard.
And we've gotten demonstrably better. Oh, yeah. People can say what they want.
The mission's gotten harder. Much harder. I agree.
The stakes have gone up- Yeah. Well, yes ... from when we first started.
Yep. " Up here, they're also dealing with compliance issues. And so my talk was, how can you bridge from that top level all the way down in a way that's practical?
Because I think we're not... So, standards live in spreadsheets and commands live in consoles, and how can we tie it together? So that was my talk.
It's a thing I came up with years ago. I call it governance hierarchy. We actually built it into CSA training like four or five years ago.
And at the top level, our frameworks to just help us figure out our focus. It's like the lens of what we need to do. And there's really good ones like NIST CSF.
It's very broad. It's not meant to tell you everything you need to do, but it's designed to give you that big picture of what you need to do. The problem is, when I first started doing cloud work, we didn't really have good ones for cloud.
Because cloud is a different enough, new and disruptive enough technology, you couldn't just layer in the 20 years of what we were doing in data centers and in our regular networks. And so I wrote a cloud security maturity model with CSA and with IANS, if people know who that organization is, and we co-released it between the three organizations. Now with AI, same thing.
So my talk was about building that bridge and how you can go from those high-level models. I like the maturity models because they tell me this is what the buckets of your security program need to be for cloud or for AI or for general security. Then the next level is we need control objectives, which is the, how do I define my desired security outcome?
So plain language of, what do I need to be measuring in terms of my outcomes? So I kind of walked through that. For that, at CSA, we have the cloud controls matrix, the AI controls matrix.
They're a good starting point, not the end point, starting point for those. And then how do you translate that down into the clicks? And so, big things were, in terms of the content is, I had released a draft of the AI security maturity model.
Got 600 comments from 60 different people from around the world. Like, all right, clearly- Struck a nerve there somewhere ... people are really interested.
Mm-hmm. Of course, I had to use AI to go through all the feedback because it was too much even for me to go through. But categorized it, got some really good improvements on that.
So getting ready to release that piece. And so that was the talk part. The announcement part was we're expanding our membership opportunities because Jim brought me on largely, because I've got, we use the word analyst.
I'm pretty hands-on practitioner level worker. Yes. I'm a blue collar analyst, or I don't know.
Always have been. That's kind of insulting to say to actual hardworking people. But I try to take that perspective.
And CSA's got all this great research and stuff and people and membership and global participation. What the organization hasn't had a lot of was, well, how do we support people to actually implement and get this stuff working to improve their security outcomes? So that's a big part of what my role is.
And then the big announcement was expanding our membership opportunities. So we have a structured program now that I've built, it's to adding membership for organizations to be able to support them along that journey. So it's not just vendors, it's user practitioner organizations?
This membership is all oriented towards enterprises. Right. And look, let's be realistic.
We're non-profit. Someone's got to keep the lights on. We still need to keep the lights on ourselves.
Right. So we're like, how can we do that where we're helping improve security, improving the research, opening up opportunities for people to improve their security outcomes, and do it in a way that's vendor agnostic and helps support our mission. I love it.
And look, as an outsiderI love to see the involvement of non-vendor memberships. Because whether it's the Cloud Security Alliance or the Linux Foundation and CNCF and all those folks, or Eclipse or the rest of them, let's face it, a lot of them have become rich, a place for co-opetition between vendors so that they- Yeah When I was practicing law 100 years ago, there was this organization where workers' comp insurance carriers were able to share all their data collectively without violating antitrust because they gave it to a not-for-profit entity. Yeah.
Which gathered the data from all the insurance carriers- And then fed it back ... and then fed it back. Yeah.
And though it was a not-for-profit and it was an alliance, by all, to me, that was always kind of dirty. Yeah. And it was hard.
At Securosis we do licensed research, not sponsored. In other words- Right ... in CSA, we do a lot of work with the vendors- I know you do ...
but they don't drive. And honest, it's incredibly, look, I spent time on the vendor side. You've been a vendor.
Absolutely. I am not completely anti-vendor. You give it to the right people, there's- Neither am I.
They keep my lights on here, too, let's face it There's very smart and we were talking with Jody. Jody and I share the goal of wanting to actually improve things. Right.
It's like, yes, of course we want to make money in the process. We have to. We live in a capitalist society.
Absolutely. But I think credibility comes with a bigger practitioner membership. Yeah.
And that's something a lot of these not-for-profit foundations have not given. They give lip service to it. And we have a lot of enterprise members already, but we weren't serving them as well.
So they would, like our base membership, a lot of it was, you would get training, you would get access to CSA executives and stuff to talk about things. I was their unofficial analyst. I would get on calls.
Yeah. Almost nobody ever called, though, because they just didn't know that that was- That you had it ... widely available.
And you get more basic newsletter. And it's a solid little package, particularly for the training. There's- Yeah.
No, no, the training's good. Look, you and Mike did the training? Yeah, yeah.
We built it, or one of them. There's three. I built one.
Right. And on the research side, we've done some pretty good big projects. But I agree with you, if it's only the vendors, that's a problem.
It's when you get this mix- That you get the real deal ... and then because, yeah, you're serving the community of both the vendors and the organizations using their tools and technologies. You're not just serving one side.
Look, I know you don't want to talk politics, but there's a political aspect to this. Oh, no, I'm always happy to. I know.
I just don't want to get you fired. I can't be fired, Rich. I'm- All right.
Game on. Yeah, no, but it never stopped me before. No.
But no, but seriously, a representative government works best when it's representative of the people. Yeah. The people who need cloud security are not just the vendors, it's the people who need to be defended and are in the cloud.
Well, and we have so many members that, they don't pay us anything. They're- And that's always been part of it ... all the working groups, anybody can participate in chapters and in working groups.
Since day one, by the way, they've had that, right? Oh, yeah. That's the core of CSA.
I remember early on, like every two weeks was a working group phone call. Anyone could dial in. This is before we had Zoom.
Anyone could dial in and listen in and participate in the, I guess we called them conference calls then. Well, they write most of the research- Yeah ... is the working groups.
It's not someone like me on the back end. I've done that a couple of times, and that's not common. Because we produce industry consensus research that anybody and everybody can get involved with, and it's hard to manage.
I feel for our research team, because some of these working groups are really large, and the logistics of holding meetings and then getting people to actually write. But I know, so the AI maturity model, I set it, put it out, we got 600 plus comments from 60 different people. That's going to be better than if I wrote it myself and published it- Absolutely ...
like the last one ... every day of the week. Every day of the week.
That already, they found stuff that I missed. It is much better research than what I wrote on my own. Now, I like being able to draft something first and get that feedback, personally, but that also, there's other kinds of research where one person can't do that.
It's just too, like our cloud controls matrix, AI controls matrix, those need a lot of people working on it. And these are all volunteers. And that's another aspect of the whole not-for-profit thing, that yes, there are people who get paid who work there full time, but a lot of these not-for-profits live and die- Yeah ...
with the strength of their volunteers. It's the same thing, again, like in open source, the maintainers, a thankless job that now is starting to recognize they're the linchpin of this whole thing. We've got to take care of these people.
All right, so we spoke about the membership program. Yeah. Where can people get information on that?
org. It's not fully on the page yet because we just announced it. org, or RMogle on anything but Twitter, politics, and- It's X.
No, that's, man, whatever. Yeah. It's Twitter.
So, but you- By any other name where the rose smell is sweet. Find me on LinkedIn, find me on Mastodon, find me on Blue Sky. Any of the above.
And at the CSA website. Now, you got some other stuff going on. I do.
Did we cover it? We covered the membership, the research. We've got, yeah, some, the I know we're going to have Jim on this week.
I don't want to spoil too much- Right ... because it's Jim's baby, but we did announce a new nonprofit arm, so it's like- Yes. But we'll go more into it.
It's a nonprofit arm. Of CSAI. Right.
It's all about AI. Yeah. And so it's a way, honestly, it's a little bit hard.
Our name's Cloud Security Alliance, and right now, the vast majority of work I'm doing is on AI. And- You and everyone else. Because it has to be.
And we have our AI safety initiative, and our trusted AI safety expert training, and the AIC, and all this stuff. So this is a way to, it's still CSA, but it's a way for us to better align, fund, and focus those efforts. So it's not like we're splitting or anything else, and Jim can go into the details.
And it's funny because it's like, well, it's CSAI. Is that Cloud-- No, it's just CSAI. Just CSAI.
It is what it is. Cloud Security Alliance. But look, if the Linux Foundation can have, I think it's 40 different daughter foundations, you could have CSAI.
And that's exactly what this is. And it's super exciting because it gives us, a better way of... Okay, I was with a friend last year at DEF CON, a good friend of mine.
And we were talking, I was telling him because I had lined up this job, and I hadn't started it yet. " That's great. " No, it's just CSA.
I went through all the research we had already published. " But you know what? I wonder how many similar stories we're going to hear because, look, just sitting here, Rich, talking, every single person, everything they're doing, not everything, but a large part of what they're doing is all revolving around this.
It is driving like nothing I've-- And I was here- Oh ... for the dotcom. Yeah.
I've been here through this all. Nothing is at this level. So I want to give an example.
Go ahead. This morning, I was running a workshop, and it was a cloud incident response workshop. Mm-hmm.
And I had a framework and stuff we set out, because I used to teach that over at Black Cat, and automation platform for live attacks and everything. So I have to spin it all up the morning of the class because it's really expensive to run. I'm not going to run it overnight.
Yeah. And spun it up, and parts of it didn't work right, weren't going right, even though I had tested everything before I left. Well, there always is.
Used Claude to build a new desktop. And this was a moment. So first of all, I know I could've debugged that, but I'm looking at the clock.
You don't have time to play. And the AI had all the context of all my code. And so I gave it, told it what was going on, told it what to look for, and it went in and found it far faster than I could.
And I would've found it, and it turns out it was a weird race condition in cloud formation, which isn't supposed to happen, but does sometimes. I was spinning up 65 accounts. Nine of them borked.
Didn't work right. So that was the interesting part. All right.
Put together a strategy to fix it. I had to launch all these simulated attacks. " It didn't even have the attack code.
It was able to just pull it from that project because I normally run that someplace- Right ... else in a container. " I do it from my laptop, so it doesn't look like it came with an AWS.
" Because my main desktop at home, I was remote into, doesn't have those containers. " And Claude goes to go do that, realizes that the docker image I based everything on was out of date. Interesting.
Instead of just taking the next one, finds one it knew was compatible with the software libraries I had built into my attack code, downloads that, builds new containers, deploys them, aligns them with the credentials it needed to run the attack, and everything ran. And by the time I walked from the Marriott to this building, it was done. It was all up and running.
It's amazing, isn't it? It's scary amazing. Well, so look at the implications, though.
We could talk all day on this, and- We can, and I have. What does this mean for the profession? What does this mean for the jobs?
I'll tell you what, I don't think we're going to know for a few years. So look, developers are the tip of the spear when it comes to this displacement. Yeah.
But marketing is not far behind. No. Writing is not far behind.
I hate to tell you this, analyst and analysis- Oh ... are not far behind. The tech industry, in general, is the tip of the spear.
But the waves here are going to tsunami out into the general economy, only to be followed two to three years later by physical AI robots- Yeah ... doing other kinds of work, right? Blue collar, physical work.
It's a very interesting world we're coming to. It amazed me at "Dune," the movie and the book. " Because they killed the thinking machines.
They- The Butlerian Jihad. Yep. If you're a real Duner.
Yep. And you know that, right? Serena Butler and the war against the thinking machines.
I did not know any of the names other than the war against the thinking machines. I'll- You have a better memory than I do. No, I reread them all the time.
Oh. I love the... So I've not only read the Frank Herbert Dune books, but I've read the sequels and prequels- Okay ...
by his son and Kevin Anderson. And at the end of the whole Dune universe, the thinking machines were there the whole time, pulling the strings. Spoilers, dude.
I'm just, look- I know. I gave up on book three or four because- Well, I don't think we'll ever see a movie ... they got a little weird.
Well, it did. Well, the Frank Herbert one got weird there. Yeah.
But the prequels are fascinating because it talks about the war against the machines. Yeah. And then the sequels pick up from the prequels.
Yeah. So it is, well- We've probably used our time and nerded out a little bit here. Yeah, we did there.
I'm sorry for the Dune deep dive, but whatever. Rich, it's always a pleasure, man. Oh, man.
All righty. Thank you. Hey, we're live.
We're with Techstrong. I am Techstrong. But we're at RSAC.
We'll be back in a moment.