Must-Ask Questions for AI Security Vendors with Swimlane’s Mike Lyborg
To make informed decisions, there are 8 must-ask questions for AI security vendors. Mike Lyborg tells us what they are.
Transcript
This is Textron tv. Hi everyone. Welcome back here to Techstrong tv.
I'm happy to introduce you to our next guest on Textron TV today. His name is Mike Lebo. Mike is the CSO and a company called Swimlane.
Let's welcome him. Welcome him. Hey, Mike.
Welcome to Text on tv. It's great to have you on here. Thank you, sir.
Thank you, Alan. Okay. Um, so Mike, I said you were the CISO at Swim Lane, and you know, they're, as I were talking to you off camera, they're CISOs in their CISOs.
There's first time CISOs, well, all type security admins who become ciso. There's all different flavors, you know, looking at you, I can't tell what flavor you are. Um, tell, tell us a little bit about your adventure on the way to becoming CISO at Swim Lane here.
Yeah. No, I, I've been with Swim Lane for seven years. Uh, kind of worked my way up from, uh, a consultant, uh, so cybersecurity consultancy, um, and, uh, enablement, right from our customer experience programs.
Uh, prior to that, I, uh, I built a couple of security programs and SOCs, so very tactical, like tactical, tactical, operationally focused on, on how do we manage risk, right? And, uh, way before then, um, spent about 12 plus years at the United States Marine Corps. Uh, and some of those are USO comm, uh, under, uh, umbrella called the Marine Special Operations Command, uh, where it was really interesting because it was a, a bridge between kinetic and technical solutions to, to deal with, um, uh, our different mission profiles.
Got it. Um, that's an interesting background. Very, very quick.
Yeah. And yeah, I mean, I can even add before that, right? Like I did it.
Uh, so remember the good old days in the nineties of, um, just network security, right? Like the early, early days of, uh, Cisco. That's how I got started too.
Uhhuh. Yeah. That's how a lot of us, you know, I tell people that, especially today.
'cause you get, like, a lot of kids come in, they take cyber security in school today, right? Yeah. We didn't, they didn't have it then.
You know, first of all, we didn't call it cybersecurity, it was InfoSec or security, but most of the people I know, they came into security by way of being network people, right? They were playing with routers and switches and stuff like that, and, and security was kind of part of that, or they didn't know enough not to do it, and they, yeah, I got drafted into it. So, good story.
Um, swim Lane. I think some of our audience probably somewhat familiar, at least with Swim Lane, but for those who aren't, Mike, how would you describe Swim Link to them? Yeah, I mean, the, the one sentence is we're an AI enabled automation orchestration platform, right?
com. Uh, but holistically, if we go back years, and you think about what I used to do and as a security operations center manager, uh, or do forensics, right? Is we did a lot of repetitive work.
Um, so day in, day out, um, we would go and collect evidence or analyze, uh, data sets, uh, to kind of find anomalies of those needles in the haystack. Um, so we got smarter and we started building batch grid, PowerShell scripts, python scripts, to do all of this in, in volume and, and kinda standardize. Um, when I started at Swim Lane, I just kinda mind blown because we put that into a platform where we could take all these kind of high code to low code transformations, um, and run these on CR jobs, run them on actions.
Uh, if the detection signal comes in, then go and run these a hundred different tasks, right? So humans don't have to do it, and it kind of standardizes, uh, and enables the security analyst teams, uh, and the risk managers to, to get a normalized data set of what's actually going on without having to go and query and do all these look gaps. So, unifying all the information, uh, that is at a very high level, what we do at Swimlane as a product, uh, platform team, and also internally, Mm-Hmm, sure.
So as I suspected, Mike Swimlane wasn't always an AI security vendor because seven, eight years ago, there wasn't no AI security vendors. Let's be real. But sir, you know, today, not just today, over the last year or two years, it's very hard to have any discussion around technology, IT security without AI and ai, you know, how AI influences it.
Um, you've come up with your own little checklist, right? Eight must ask, eight must ask questions that you should ask your AI security vendor. This is something people out here want to hear.
Um, before we start, is there anywhere like a blog or somewhere on swimlane where, because they may not remember all eight, somewhere where they can get this, you think? And then let's jump into what these eight musk ask questions are. Yeah, no, absolutely.
Yeah. So it's, it's front center on our, on our, on our home page. Uh, okay.
com, uh, and you look up our hero ai, there's several blogs, videos, uh, and even interactive demos, right? We can kinda walk through, uh, the user experience to see what we do with it. Um, as far as all the different questions, uh, I think the questions obviously change every day.
Uh, right. And to your point, when we look back on where AI was at maybe even three years ago, four years ago, um, it wasn't always returning the same kind of, um, or the expected response, right? Uh, so we, we might know the answer and you go and ask it.
So if you're not seeing what you are expecting to, or, or you already know what's true, uh, that kind of gave a lot of people, um, a bad taste, right? So I think one of the first questions I always ask, uh, and, and, uh, I suggest everybody should ask is like, what, what model, um, are you currently using? Um, and how are you training it?
And what was it built on and how is it public and private? Like, we can dig deeper on any of these, but that's often one of the first things that I, uh, that I ask our vendors in our ecosystem. Absolutely.
So, all right, let's jump into it. What are these eight must ask questions? Uh, well, data sources is often really important, right?
Like, how are we training it? What are we doing with it? How are you ensuring data privacy?
So I just mentioned something earlier, right? Yeah. If it's public.
Um, so one of the big things that we often see when people go on stage and they talk about AI is like, well, what, what, how are you controlling, uh, and reducing the risk, um, of a possibly, uh, hallucinations or returning information that could have been erroneously submitted by a human that shouldn't have updated or trained the model to, to, right. So what we did internally at Swim Lane is we, we built a, um, kinda like it's not a public, um, you know, model where anybody can go in and, and ask whatever they want. It's specifically built and focused on, um, on cybersecurity, uh, technologies, answers and problems.
Uh, so, so I think that's, that's really a crucial, um, uh, on the LLM selection. Sure. Yeah.
I, I agree. Give us some more. Uh, yeah, so we talked a little bit about data sources, the models, um, algorithms.
So there's a lot to dig deeper there, right? But at the end of the day, it has to be, uh, you know, safe, responsible, use. Um, and I think also like looking at knowing and testing and providing guardrails, uh, is extremely important.
And that's something I often ask our vendors. And I think a lot of times, you know, let's say that you build a policy as a CSO or as e risk management team, right? You, you then start looking at, well, what are we doing to protect our sensitive information?
'cause humans are humans, they're always gonna do take the easy path, right? So I always recommend that, well, don't give everybody access to your sensitive information because then they can't submit it into, and a public or open, uh, model, right? Uh, where it could be compromised possibly later.
Uh, so always take care of the basics first. Uh, if you have a good, uh, a good solid foundation, then you've immediately also reduced a lot of the risk. Sure do.
That's a good one. How about another, uh, measures, uh, adversarial attacks, right? Um, I don't think we have all the answers yet.
Um, but internally, uh, and as a consumer of other models, uh, test it. See where you can break, throw problems at there, and then figure out, um, you know, what are the vulnerabilities? Uh, uh, I think that that's really paramount.
And as we continue to learn more about different areas where there could be exploits or maybe we see something on, on the, uh, in the news flash that some other model just got compromised, and here's how they were able to, to get information now, uh, test it against your own vendors' ecosystems and see what the response is. And if you find something, say something, right. Report it back to those vendors.
That's a good point for sure. You know, that goes back to again, the security people. When I first got involved in security, one of the reasons they got into security was they like breaking things and then fixing them and make 'em better.
Yeah. Right. Make sure they're not as easily breakable.
So, you know, that harks back to what security people are about. And I think that's, and that just doesn't go for AI security tools, right? I think that goes for all the tools that you use, and it's at the core of being a security person.
But good stuff. What, what about halfway through? Let's hear some more.
Yeah, I think also the level of support, right? So what's the frequency of their training? Uh, what, what is their training data?
And if you, if you do have a customer, um, or user, um, report something like what does that process look like? Have we found something, we've now said something, uh, how long does it take for you to, to fix this? Is this something you do once a year or is it continuous?
Right? Um, so that, that should be part of your question stack as well. Um, and I think the focus, um, so if we, if we go back to the, like, I guess the start, just because the tool in your stack has AI enabled doesn't make it necessarily better.
Keep in mind that some early adopters failed pretty hard, uh, when they started shipping ai. And so they didn't ask the simple question. So what, what, what, how is this helping us?
How is it helping our customers? What outcomes does it deliver? And how can you measure and show, uh, show me and quantify and qualify the data that is being, uh, returned?
Um, and so rather than boiling the ocean and try to do everything right, like our model, like if you ask about the weather's gonna be tomorrow, it's not there for that. Uh, so, so make sure that, that you, uh, you kind of pick and select the, the tools and that you ask those questions to your vendors in the ecosystem. Absolutely.
I, I think people, again, you know, people think of ai, they think of chat GPT, and it has this huge LLM of the entire internet as it existed in 2021 or whatever. But that's not what today's AI tools are about. They actually operate on small language monitors or much smaller LLL lms, right?
That are more focused on, on the job at hand. I think that's a good thing to focus on. What else do you got for us, Mike?
Uh, I think just compliance, right? Compliance and different regulations, like new regulations are being spa almost daily or updated. Um, and I think it's important that we all follow, uh, along with that, right?
So that we can be good stewards of the information that we a return to our consumers, um, but also focus on how do we mitigate, so the whole testing guardrails and everything else, if you start asking those complex questions, um, that could possibly return sensitive information, uh, make sure that it doesn't, uh, and that should be part of your, your whole build test validation phase, um, or your own adoption, whether that's an internally built, uh, or something that you, you know, service or something that you consume as well. So be aware of all the frameworks out there, map what you can, uh, and continuously improve, uh, and extend, um, your risk management program to include ai, right? So a good example is people have personal phones, right?
So let's say that we are not a, uh, nimble organization or, or that the companies that we're talking to or about like, may not be so nimble. So they're like, yeah, we're just gonna block everything. Uh, you won't be able to use any, any of the public, uh, LLMs right?
Or systems out there. And then they go, uh, block that, and then now they start, everybody just starts using personal devices and now they just extend or expand the risk, uh, because now you don't have any visibility into what's being, um, what is being used for possibly, right? So, uh, follow best and common sense practice is what I like to say.
Or better practice. 'cause I don't think there's a best practice anywhere, but, uh, there's definitely things you shouldn't do. Um, so, so tho that's really I think one of the most important approaches would, um, uh, when it comes to the different standards and regulations.
Sorry, it was a long-winded answer, but, uh, no, it's okay. Look, some things can't be said in five words, so it's all good. We're getting to the end of our list though.
Why don't you give us what else we got left here? Uh, uh, yeah, I think embrace it, right? Um, that, that's like, that's a really big focus because it's here whether you like it or not, right?
So enable and train, talk about the different scenarios. Uh, I mean, we can, we can laugh about phishing training and education 'cause people still get phished, right? Um, but doing something is better than doing nothing.
Um, so, so talk about what's acceptable, make sure people acknowledge that and you as a business, uh, kinda assume and then transfer the risk where we're applicable, where I think those are really important to building blocks when it comes to ai. Um, and, and still just take, yeah, take care of the basics first. Um, mm-Hmm.
I, I don't, I agree with you a hundred percent, man. Yeah, you can't, you can't spin it. I'm sorry, go ahead.
I was No, no, no. I, no, go ahead, sir. I was gonna say, you, you can't spin, you can't go zero to a hundred in a day or two, right?
You gotta, this is a, it's evolutionary, not just plug and play. So I, that would be my big thing to, to folks adopting these things too, is, you know, you gotta let it digest, like get your head around it before you try to go a hundred miles an hour. Yeah.
Anyway. And it, and it's not linear either, right? No.
The adopt the adoption, uh, the expansion, the, the advancement in general, right? It, it is, it is awesome for us, I think to be part of, of this era. And, and we can say that every 10, 10 years or so, uh, there's some new technology, boom, right?
AI doesn't necessarily, it's not new. Uh, I mean, it is new in, in the sense of adoption, but I think, you know, every couple of years there's, there's a big change, whether it's the internet, right? Like people started using the internet and people are like, oh, this is awesome.
And then it kind of, uh, dwells like tones down a bit and now it's, it's business as usual, but always building those controls to mitigate risk throughout, um, and get deep into it, um, and test everything. Uh, those, I think my biggest, uh, internal, uh, risk management factors, right? That, that, that we focus on heavily.
But if you say, yeah, no, we're never gonna adopt ai. We don't allow it. How are you kidding yourself?
Yeah, I think so. And, and people will find workarounds. So now you'll build mitigating controls for the workarounds, and now you're just spinning your whales doing, um, that's, I, during the course of my career, I've heard that same thing said with open source, we'll never use open source in this company, right?
We, we only use commercial software where we have a throat to choke and an SLA and blah, blah, blah. 99% of all companies today use open source. And I bet you the 1% who said they don't, probably don't realize that it's built the applications they're using.
Anyway, so the same thing with wireless. I remember once being at an army base out in Colorado for Carson, big Army base, they have a beautiful office. And, and I was talking to the Doum, which is sort of the CSO of an army base, right?
They're the information assurance officer for that army base. And I asked him what he was doing with wireless security, you know, and he says, we don't do anything with wireless security because we don't allow wireless, you know? And then as he's saying that, I'm seeing people like reach under their desk, unplugging their laps, you know, and waiting for 'em to patch and they plug it back in.
You. You're not gonna stop progress, right? You, you can't, you, you gotta embrace it.
So, no, absolutely agree with you. Agree with you. Hey Mike, we're about outta time.
I wanna thank you for coming on here and, and giving us this, this, uh, must ask questions again, people can get this off the front page of Swim Lane. com? Yep.
Yep. Alan, it is. Check that out, Mike.
Don't be a stranger. Come back and keep us posted here on AI and AI security. Awesome.
Thank you, Alan. Thank you for having us today. My pleasure.
Mike Lyor, CSO at Swimlane talking about eight must ask must ask questions for AI security vendors. You're watching Text Drunk tv. We're gonna take a break.
We'll be back.