Generative Artificial Intelligence and Cybersecurity – Faisal Bhutto, Calian IT and Cyber Solutions
Faisal Bhutto, senior vice president for cloud and cybersecurity at Calian IT and Cyber Solutions, explains how generative artificial intelligence (AI) platforms such as ChatGPT are about to turn the cybersecurity world upside down.
Transcript
This is texturong TV. Hey guys. Thanks for the throw.
We're here with bisel Buddha who's vice president of cloud and cybersecurity for Kelly and it and cyber Security Solutions. Yes, that was a mouthful and I think I got it. I'm we're talking about chat GPT and cybersecurity and what is actually happening out there versus what maybe we're all reading about so we'll see how it goes Faisal.
Welcome the show. Well, thank you. My pleasure.
Everywhere you turn around these days. We're expecting Armageddon and the cybersecurity space because machines are going to start launching massive numbers of fishing attacks using these chat GPT type of generative AI platforms a do you think that that's going to happen and be have you seen any signs of it happen? So I I think any good seizure Security Professionals should all visit soon.
There's Armageddon when it comes to the world of cyber AI or not, but this definitely adds a new new Dynamic to the already tough job that my fellow colleagues have in the industry. You know, it's funny when Chad CPD came out. Everybody was excited about all the amazing things it does and I'll make us more efficient but there is a report that came out where checkpoint Publisher report on January 6th, if I'm not mistaken and it was interesting report where they actually monitored the chatter in the dark web to see how the bad guys are already looking to make their lives easier with chat GPT.
So it's it's that Blade the cuts both ways, right? And yeah, there is Chatter. I mean, there's people that if you think about it right there in there's been a market to create new malware ransomware kids and what have you and and it's a service that you can buy in the dark web you detonate and in fact a customer attack a customer.
Well think about how that industry is going to change for them as well. And there is already been examples where you can see people who don't know how to write good code are using chat TP to do right code to encrypt files for rent somewhere. You can see examples where these groups are looking to have chat GPT create.
The most amazing impersonation emails or phishing emails that you know that you've ever ridden because think about it if English is not their first language and they're trying to convince HR department to change payroll data, but an employee chat GP is a pretty handy tool they're doing it. So it's it is happening out there. I I do believe it's gonna have an impact as it becomes more commercialized and readily available where you know, just like the good guys bad guys.
We're gonna use it. Even thoughts of how we might detect this because historically, you know, once I got that email, you know from that Nigerian prince, I could pretty much figure out the misspellings. But you know now how am I supposed to figure out that these messages are perhaps not what they pretend to be.
That's funny. Yeah. No, you won't get an email from your cousin anymore from Nigeria.
It will be someone it will be you pretending to be you know, who's not you emailing your HR with the most amazingly well-written email that you'll ever see. Look AI driven problems have to be solved with AI driven Solutions. The industry has to evolve and it is to be able to incorporate Automation and artificial intelligence in detection threat and response.
So, you know in that example of an email that comes through it might look amazingly perfect with no spelling mistakes the the email protection platforms or threat detection platforms have to look at indicators of compromise. Where did this email originate from? What does the header say?
Is it really coming from the domain or is it kind of sort of like a domain which looks like it but it isn't and you know traditionally we dependent on humans to identify that that's gonna have to change where you have to have to rely on machines to be able to detect that flag that Regardless of how well written the email is and that's just one example, you're gonna have to do that on on other threats that are generated around ransomware and what have you so I I do believe that the way to solve it is going to be where the entire ecosystem and the industry comes together and incorporates AI for detection threat and response whether it's in same Ed or xdr email protection and you name it. It just it won't just be human dependent we will fail for sure to try to protect ourselves. And this goes beyond phishing attacks and Theory you should be able to use these platforms to show it an example of a type of vulnerability and then show me all the instances of this type of vulnerability out.
There might be more efficient way of scanning and then likewise I may as an attacker I should think and be able to say, you know, show me the most effective piece of malware that does this and I will copy that of course, there might be guardrails that prevent that but there's more than one of these Platforms in town, right? Yeah, no doubt about I think one of the real examples was somebody wrote a code to survey all the AWS open, you know their S3 buckets to see which one is using the default password and has unencrypted data and then look for files with these 12 extension types and downloaded, you know, Excel files dot files or what have you so it's it can be really sophisticated it goes beyond fishing emails or impersonation emails. I mean, it's the code and the the ease of because you know, ultimately you're trying to get to an end result and chat GPT or something like that is helping that bad guy get to that end result a whole lot faster with a lot less effort, right?
So that's why I believe that our detection and response engines have to be also have a lot of intelligence built to them and automation because it's gonna happen at a very fast pace and your time to respond and protect. It's just getting smaller and smaller. You can't just wait on it for two days while things happen within seconds.
Right with the and it's very fast moving as well. Right? You gotta like a cat and mouse game.
So that's where the CISO and and the folks in charge of security have to put their heads together and look at their tool sets and processes and say how human dependent are we how much automation can we built in in terms of response and recovery, of course detection as well. Or are we therefore now involved in something that feels like an AI arms race in cybersecurity and that's kind of where we are. Maybe we're behind the curve.
I think so. I think it will be that because you know, there is an a look there's an AI arms race anyway, right I mean companies are trying to Google and Microsoft her battling it out. But I think in the word of cyber, you know, if you look at Palo Alto Cisco, you know crowd strike all these major manufacturers they have to be able to like they need to be injecting more of AI and machine learning into their Solutions or else is a big threat to their own reputation because at the end of the day, you know, that's the top tier solution are being used by customers and if they can protect them from what the bad guys are generating it could it could really hurt their own market value and their Market perception, right?
Do you think as we go along here that? A lot of cybersecurity folks have been somewhat skeptical of AI and maybe it's just because of the limitations of the use of the technology thus far but do we need to overcome that skepticism and what do you think is the current state of the art for cybersecurity and AI? I don't think anybody should have any kind of doubts that this could change our world upside down after so much coverage and what what we have seen just in the short amount of you know, since November until today the adoption the the race so I I believe I think just the adoption and and the ease of what you can do with AIS is pretty much everybody is disposal.
So I don't I think those perceptions if not already have change and for those who think it's it's gonna die and it's a fad they may not have jobs, you know a few months from now because you know, I I frankly believe you've got to take this very seriously and I believe like even for us right as a managed MDR provider, you know, we're constantly looking at bringing in Ai and Automation and anything that we do so we can be a whole lot more efficient. Right? So I think organizations have to start thinking of it.
Now look at your current tool sets your processes your people look at Automation in the world of cyber. You know when you do those tabletop exercises. Figured it out.
But what if you had an AI LED attack, how would you respond and recover from it using Aid even have those Technologies? Those are hard questions, but you need to ask yourself and then set budgets accordingly go to the boards accordingly because it's gonna get real in my opinion. Do you think this will push more people towards consuming cybersecurity as a service and I'm asking the question because if I'm on premise am I ever going to be able to collect enough data to train an AI model on my by myself or am I just gonna have to rely on somebody who has the resources to go build that and then consume it more as something I might access be an API or whatever it is.
I mean the question you should ask yourself is do you have the horsepower to run something called IBM Watson? Do you have the ability to go run a big, you know deep machine learning engine to be able to come up with certain AI algorithms? The answer is going to be if you're not in this industry and a manufacturer working for that such individuals.
The answer is no so absolutely you have to go rely on if you're if you're you know seesaw of hospital or a school district or in Olan gas or Energy company. The reality is cybersecurity is not the bread and butter for this company. So you've got to be able to go rely on Partners like us as well as manufacturers out there to be able to bring you those Solutions quickly that can be effective and that's the only answer because you see even as as solution providers, we've got a lot of Automation and AI in our security operations centers that we can respond to threats and detect and remediate from them faster we ourselves as the experts also rely on our ecosystem Partners like Paulo Cisco and crowdstrike, for example, Microsoft to help us become more efficient because they've got the budget they have the quote unquote Horace.
However to be able to go do it a whole lot better than guys like us can even do right so we lean on it. They put it all together. We make sure that the right solution fits the right problem so we can then take that as a package to the End customer.
That's where integrators Like Us. Come in. So yeah, the end customers absolutely they they're Dependence Reliance Trust on manufacturers as well as partners like us it has to be there trying to do it in-house if this is not your if your p&l is not dependent on this in the world of cyber is a bad idea.
It just it just doesn't work. Well, the definition of what we consider an entry level position in cybersecurity change over time, we've already seen people are using generative AI platforms to write security controls and automate that process. We were also seen people talking about how a lot of those entry level tasks are just going to be automated using sword platforms or whatever it is.
So is the point of entry into this field Rising as we're kind of sitting here into people need to think that through because suddenly I'm not going to be looking for somebody out of college with six months worth of experience. I'm gonna be looking for people to have much higher levels of knowledge and experience when they come out of college. Yeah.
I think my opinion that is I think it will happen over time. I don't think it's gonna happen overnight because the Cyber Talent shortage is so massive right now where you want people that can understand these cyber principles have some of the certifications so you can get them on the path of running the systems because the ultimate goal is that people run the system and systems to the job, you know, most efficient organization. So I think I think the hiding profile for example for people like us would change or we would want the people to still come in.
They may not know much about AI or those tools but our goal would be to get them trained up. So they're not doing the fundamental repetitive mundane tasks that we can go achieve through and through an automation automation platform, but I do think Talent Market is still very very tight in the word of cyber. But employers are going to want to hire people and get them trained up not necessarily be super selective that oh since you don't understand it, I won't hire you.
I still think it is a massive need and it will continue and then, you know, even Beyond cyber it, you know, we'll have to see how the industry changes what happens to customer service agents on airline tickets on you know help desk. So I think it's gonna be a sea change and I think cyber is gonna tag along with it, but for a potential person who's listening to this podcast who wants to get into the world of cyber definitely make this part of your learning curriculum of how how do you like don't just learn about cyber controls or governance learn about automation learn about sore. What does a sore platform do in a security Operation Center chances of you getting a job with big dollars is gonna be much higher versus, you know, just getting your Security Plus or your science a plus All right, folks.
Well, you heard it here. It may be automated. It may even have artificial intelligence.
But that doesn't mean you don't need to know how it works and you should proceed accordingly Faisal. Thanks for being on the show. It's my pleasure.
Thank you so much for having me. All right and back to you guys in the studio.