Lenovo’s Nima Baiati on AI’s Role in Cybersecurity
Nima Baiati, executive director and general manager for commercial cybersecurity solutions for Lenovo, explains how artificial intelligence (AI) will transform the way security is achieved and maintained.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Nima Ti who is, um, general manager for cybersecurity at Lenovo, and we're talking about what the role of AI is gonna be to make things more secure in general, and what the impact that's gonna have on cybersecurity professionals because, well, the world is changing and hopefully it'll benefit the defenders more than the bad guys.
Hey, Nima, welcome to the show. Hi, Michael. Great to be with you.
Give us a sense what people should expect. I think that everybody sees the hype and we know that AI will be applied to cybersecurity, but it's not clear to me that folks understand, um, what are the implications. Uh, there are some folks who are probably saying, you know, is this a threat to my job?
And there are other folks who are kind of understand that maybe it's gonna get rid of a lot of the toil that nobody enjoys. But what's your read on how this is all coming together? Yeah, it's, it's, it is a great question and, and, and one that's definitely been top of mind for a lot of people and a lot of organizations over the last 12 months.
I think it's important to recognize a couple of things about artificial intelligence. One that whilst AI might be the, the, the, a new buzzword, so to speak, over the last 12 and 18 months, AI's been around for about 50 years. We've been using it in various iterations for quite some time.
What's changed significantly is that we've gone from what I would call kind of your, your, your basic more statistical type regression models of AI to an area where AI now is generative, meaning that it can generate its own outcomes based off of its data sets and its data models. And as we progress further over the next several years, this type of technology is only going to continue to accelerate in terms of its capabilities. We've already seen significant acceleration, for example, between chat GPT-3 to four.
Now, in terms of implications and ramifications, I think with every introduction of new technology, you know, when we saw, for example, the industrial revolution, we saw some significant changes happening in the workplace. We saw differences in terms of who was working where and what kinds of jobs that they were doing. We saw this with the introduction of the internet, or let me rephrase that, with the broader usage of the internet, you know, 20, 25 years ago.
And I believe we'll see this as well with artificial intelligence. We'll start to see a shift in terms of what we'll call, um, lower level or lower skilled white collar or knowledge based jobs becoming more automated. And an example of this, for example, or an example of the usage of automation that AI can provide from the security landscape is within a security operations center, or for the security analysts today, one of the challenges that security analysts face, and one of the, one of the, the top challenges that cybersecurity in general faces is that there's a massive skills shortage at the global level.
Artificial intelligence has the ability to help automate a lot of these processes that you would need individuals for or that are more tedious, sifting through hundreds and thousands of event indicators to determine if they warrant investigation is something that AI is able to do to be able to bubble up to the top of the list of saying, this event, you don't need to look at this one, but this one here warrants further investigation based on what we're seeing from the behavior, the contextual story that's AI is building. AI also has the ability from a security standpoint to be able to piece together a story where the human eye might not be able to derive the context out of right. Taking disparate data points that to, again, the human eye or the human analyst might look innocuous, but from a machine learning standpoint has formed a context of there's something happening here, or this is a new version or a new iteration of malware.
Um, being able to move beyond just signature based detection. And this is something that we've already, for example, Lenovo been using as part of our think show portfolio for the past several years using contextual behavioral based AI on the endpoint to be able to detect, for example, things like zero days. So from a security standpoint, there are a host of applications.
Now, the flip side to that is as well, from an attacker perspective, right? It's not just the good guys, but the bad guys are also looking at this. It lowers further that technical threshold in many cases for attackers, right?
It used to be quarter century ago, you had to have some really solid understanding of how computer systems worked, how code worked. While that's still required though, that threshold has gotten lower and lower with ai, because you can use, just like from a defender standpoint or a good guy standpoint, we can use AI for good. Attackers are also able to use it.
And we see this even today with the, with things like deep fakes, for example, right? And that becomes a, a, a big ethical question and a philosophical question really, in terms of going back to one of your, your, your opening comment in terms of the overall impact of ai. Are we entering into a world where it becomes, where trust in general becomes incredibly difficult to, to, to, to, to put forward, right?
Is the picture that we're, we will see in the future on the news or the video that we'll see in the future? Is it real or was it generated by AI in order to sway public opinion, for example? There's a lot to unpack there, but let's start with we're lowering the barrier to entry from a skills perspective.
And you talked about what that means for the bad guys, but similarly for the good guys, if I have this shortage of personnel that's going on, am I not democratizing cybersecurity in a way where I can bring more people into this because well, they don't have to be a rocket scientist? Absolutely. Absolutely.
It, it, you know, one of the challenges in skills in cybersecurity is that it, it, it did, and it still does to some, to a good extent depending on what field and what, what, what role an individual is doing requires a hefty level of technical expertise. But AI also makes that learning curve a little bit less steep for, for people who are getting into the field. Uh, because we, we do have so many tools at our disposal today that can help bring forward, again, a lot of those insights.
We do have a lot of tools at our disposal today to be able to automate many of these processes to be able to see things that we can't see. And so I believe that over time, the role of the cybersecurity professional is going to get a little bit more out of the weeds because we'll be able to give a lot of those tasks to AI and get a little bit more high level, a little bit more strategic, a little bit more, uh, aware of the full battle space as opposed to really, really deep in the weeds. There'll still be a place for that in terms of investigation, incident remediation.
But in terms of people who are looking to get into the, the cybersecurity industry as well as for organizations who are, who are looking to, uh, increase their pipeline of talent, I believe that AI will be a positive thing in that regard. This is an old kind of joke that talks about how being in the military is all about long periods of boredom punctuated by sheer moments of terror. Um, cybersecurity has a similar vibe, right?
A lot of it is just boring toil search for this. And then every now and again, you hit on something that is a true threat and everybody gets motivated, but it burns people out. Will AI kind of reduce the burnout rate?
The, the, the turnover that we see, You know, that that is, that is really the hope. I mean, burnout, if you look at the statistics, is very high. You know, the average tenure of a, uh, of a chief information security officer now is well under two years, uh, security professionals, you know, their average tenure in roles is, is continuing to decrease.
Burnout is a significant concern. And to your point, right, you know, long periods of boredom, uh, punctuated by moments of sheer terror, you know, I think security is not only that, but it's also one can one can also make the, the, the, um, kind of the allegory to, even in the intelligence space, right? In the intelligence space.
And that people who work in the intelligence community, nobody hears from them. They don't get any really great credit except when something goes wrong. And that's really the, the, the dynamic within security, right?
Nobody really, you know, you don't really get any credit, you don't really get any kudos unless something goes wrong. And then, you know, the kind of the world falls down around you and direction that I see AI going is because we're gonna be able to, and we're already starting to automate many of the tedious tasks. Again, it will enable a lot of the, especially the, the, the mid-level, senior level professionals to really up their view organizationally into a more strategic plan.
And it's one of the things I think that's also very important from the standpoint, if you look at the makeup of CISOs over the last decade, we're starting to see a pretty significant shift of the pure technologist moving more into the person who can marry technology with business strategy. And that's also a positive direction that security's taken that will be enabled by ai. 'cause an AI will give managers in security, leaders in security, the tool, the data, the reporting, the outputs to be able to better communicate and articulate what's going on from a risk standpoint inside their organizations At the risk of making a gross simplification.
But a lot of times when we don't have some capability in hardware, we create software to provide that capability. And cybersecurity is no exception. There's a lot of stuff we do in software today.
Can more and more of that move down into the hardware level and take the algorithms with it and maybe get a little closer to responding in real time to threats at the end point that don't require this kind of infinite loop of processing? Yeah, that's a, that's a, that's a really good question, and it's a way in which that we've been looking at security at Lenovo, um, especially around our think shield portfolio. So if you look at the, the, the, the model at which we've, we've built our security vision, it's really around supply chain below OS and then OS to cloud.
And so it's our belief that we can move a lot of these security capabilities, you know, as we would say, closer to the box or, or, or more into hardware and leverage the hardware, right? So we're looking at, for example, today we're doing a lot of innovative work around looking at bringing AI capabilities below the os, right? Understanding how we can better protect firmware, detect firmware vulnerabilities, detect firmware attacks using AI training models on what types of firmware attacks exist today to be able to detect unknown or unseen firmware attacks.
And so I think, again, as we progress, especially from companies like ours, like Lenovo, you'll start to see more and more of these capabilities manifest themselves into the hardware Today. We, we leverage a, a, a host of hardware capabilities within our devices to be able to provide security, right? So for example, we have capabilities in our bios today that exist in the market to be able to self fuel.
So when the bios is attacked, the bios is able to detect that attack and be able to remediate that attack. We have firmer resiliency capabilities in our, in our platforms to be able to do the same types of detection and remediation against firmware attacks in the hardware itself, built into the hardware itself. So as we progressed, we're, this is a, in an area where we're continuing to invest a significant amount of, of, of resources and effort, Do you think security will eventually become a criteria that we use to buy hardware?
Because historically we bought something for it, and then we said, this is the cool, and now we should figure out how to secure it after the fact. But can we get to a moment in time in the future where we're gonna actually evaluate things based on the security that they have embedded in them, and that'll be a factor in our buying decision? I, I, I believe we're already, we're already walking down that path, right?
So if we look at, for example, the NIST requirements, a lot of organizations today used the NIST requirements, the National Institute of Science and Technology, which sets high level guidelines in terms of what type of, let's say firmer resiliency or what type of hardware capabilities a device needs to have or should have in order to be at a certain standard. If we look at a lot of the discussions that are happening over the, today and even, you know, the last year, whether it's in North America, whether it's in Europe, whether it's Asia, there's a lot of discussions happening around moving security more to the left, right? And as we shift the security to the left, we'll have to rely more on making sure that, not just from a software standpoint, right?
So things like software, bill of materials is becoming very important, right? So what went into my software? How is my software rated, right?
So we'll start to, I believe we'll start to see, we'll get to a world where we'll have rating systems or some form of an, uh, of an assessment or certification standards around software, around hardware, around cloud applications. I believe that we're, we're, we're already walking that way. And if you, if you, again, if you look at a lot of the discussions happening in places of, of, of government globally, those discussions are underway.
Have we inadvertently stumbled into something that feels like a cybersecurity AI arms race, the bad guys are using it, the good guys are using it, if they use it, we gotta upgrade our hardware and software. Is that kind of where we are at the moment? Uh, I, I would say that that's, that, that, that is an accurate, uh, it's an accurate way of putting it, right?
I mean, security in general, cybersecurity in general has always been an arms race, right? You're always trying to, uh, get ahead of the, get ahead of the bad guys. AI adds a, an arsenal of tools or the potential for an arsenal of tools into the attacker standpoint, but also an arsenal of tools against the defender's standpoint.
So it is always, you know, the thing about security, whether it's about cybersecurity or, you know, uh, a human intelligence, it's a cat and mouse game, right? So the, the, the requirements as well are somewhat different. When we look at attack organizations or hacking organizations, the vast majority of these hacking organizations operate like, like, like companies.
They have bureaucracies, they have command and control. They're operating on, on, on return, on investment, right? I mean, they're, they, they have structured themselves in a way where it is truly organized crime.
Uh, and when, when you look at crime in the digital sphere versus crime, let's say in the, the physical sphere, so to speak, if someone were to go, and I, and I, I like to give this example because I think it helps frame it a little bit. If someone were to say, okay, I'm gonna go rob a bank, I'm gonna put on a mask, jump in a car, grab a gun, and, and, and go into a bank, your odds of success in that are pretty low. And your downside, if you get caught, are pretty high in the digital sphere.
Even if your odds of success are low, you can, you can, you can kind of take a spray and pray approach, right? I, you can go after 500 targets and all you need to, to do is get one of them. Whereas if you were to go and try and rob physically 500 banks, you, your, your odds and success are pretty, pretty much gonna be zero.
Now, from a defender's standpoint, if you're one of those 500 organizations that's being attacked, you really need to try and be right a hundred percent of the time where the attacker doesn't need to be right a hundred percent of the time. And so there is a level of asymmetry in, in, in, in, in, in cyber warfare or in the cyber, uh, realm when it comes to the attacker and the defender. You've been obviously doing this for a while as a parting thought.
What's that one thing you see customers doing that just makes you shake your head a little bit and go, folks, we can be better than this. I think in some areas it's, it's, some organizations are still looking at cybersecurity as a tick box exercise, almost like I'm buying an insurance policy as opposed to looking at it as a strategic area of their business. And that impacts everything else, that impacts their approach to technology.
It impacts their approach to people and to processes into innovation. The, the, the organizations that I speak to that really get it are looking at security as a partner in, in, in their, their, their corporate strategy. A partner in their business unit level strategy as an enabler to what they're trying to do as a business, right?
Businesses are in the business to make money, right? For for profit organizations. And so the organizations that look at security from that lens of incorporating cybersecurity into the strategic level of the functioning of the group are operating at a different level in a different pace, by and large, as opposed to, you know, to your point of shaking your head of an organization saying, Hey, we need to do A and B because it's a requirement, so let's tick the box and, you know, move on and hope for the best, generally speaking.
And, you know, that doesn't work well. All right, folks, you heard it here. The game is changing.
One thing is true, though, AI or not, if you think about security as an afterthought, it's gonna end badly. Hey buddy, thanks for being on the show. Thank you, Michael.
Pleasure. All right, back to you guys in the studio.