ROCon 25: Richard Seiersen on ‘Risk Yoga,’ AI, and the Future of Cybersecurity
Richard Seiersen discusses his background and role in risk management at ROCon 25. He presents his keynote ‘Risk Yoga,’ which emphasizes transforming strategy into measurable actions. The conversation covers the uncertainties in cybersecurity, the critical role of AI, and the future of quantum cryptography. Effective risk management strategies are highlighted, promoting informed decision-making in uncertain environments.
Transcript
Hey everyone. We're back here live in Houston for Qualys Raan Conference day two. We've been just talking to a bunch of different people already this morning.
We got started early. Hope you're enjoying it. Our next guest, Richardson, You nailed it.
Well, it's not my first time interviewing you, but Okay. If, if you follow along at home, I actually spoke to Richard last year in San Diego for, uh, quality Security Conference, QSC Richard, if I'm not mistaken. You had just joined around then, wasn't it?
Yeah, I've been here maybe 20 months. I feel like I'm a baby. You know, it's in months.
You, yeah. The time. Yeah.
He's not making, I, and I do remember a little of your story, but no one at home is gonna remember it. Right. Why don't we, let's start there.
Give us your j you know, a little bit of your journey to being a quality in about 20 months. Sure. Great.
Well, actually, this is my second stint. I am in a boomerang about 20 years apart. So actually when I started Ed, ed and I were both Midland engineers.
I remember he'd show up in cargo, uh, shorts and t-shirts and uhhuh. Yeah. And then I went on to do this serial CSO thing, GE Twilio Lending Cloud.
I've been a Chief risk officer in the insurance space. Mm-hmm. Um, and I've written a few books, but summed and I stayed friends.
And when he started on this journey, this new vision on the Risk Operations Center and more specifically ETM or enterprise True Risk Management as a platform, he called me up and said, Hey, would you like to join the team? And I was like, this is great. Can't wait.
And here I am now. That's fantastic. That it is a great story.
Now, your official title is not Chief Risk Officer. It is not Chief Risk Technology Officer. And we owe Ed the thanks for that great title.
He Came up with that. He came up with the title, and I think the emphasis really is 'cause 'cause of my background on risk, um, first and foremost, helping to bring, I guess, the world, particularly CISOs, along on this risk focused journey. But at the same time, I have a role in helping define technology as well.
So being a voice for a reason, I suppose, to the world on the risk side, but also helping to guide some of the product as it relates to risk as well. So I do both those things. I love it.
Yeah, it's great. It, you know what been around a while, you, you learn that you, you want something that kind of plays to your strength. Right?
Right. And this is a, just, just like a great role that plays to your strengths. And, and it's good when, you know, things come together like that because at the same time, they're, you know, Qualys is the risk operations company now.
Right. This conference is the Risk Operations Conference. So it all, it all fits together nicely.
You know, you like to see that in life. I'm, I'm pretty excited. I'm, I'm like a dog with two tails.
I can be more excited. So, Absolutely. Richard, you are present, you presented here.
Yes. And, um, why don't, you know, people watching this live at home probably aren't here by definition. Right.
Unless, you know, a quantum, they could be in both places, but as soon as we would know they were, then they wouldn't be. Um, I've been spending a lot of time with some quantum people lately. Yes.
Anyway, talk to us about what you spoke about. Sure. Um, the title of my talk was Risk Yoga.
So I was the day two keynote, so risk yo Yoga, turning Strategy into Measurable Action. And so, yeah, I didn't wear any yoga pants, by the way. Okay.
I taunted people and told them I might do it. But yeah, it was an opportunity to relax and, uh, I, I suppose play with the audience. I actually, there was a yoga theme throughout.
I ended up asking a lot of questions and people would answer, and I would use that to, I, I suppose instruct them in, uh, new postures as it were to use a yoga theme and how to, how to think about risk perhaps in ways that might be new to a security practitioner or security leader. And, um, I guess it went, it went well. It seems like good feedback.
People are still here, so I didn't scare anyone off, but yeah. Okay. All right.
It was Enjoyable. Um, so yeah, I'm gonna come back to the, to the quantum thing. Even we can't know everything.
'cause like almost by definition, once you know it, you don't know it. Right, right. It changes it.
How do you, Mr. Yoga professor or instructor, how do you, cybersecurity especially today seems almost about uncertainty by definition. Yes.
So if it's about uncertainty, how can we have any certainty? Right. Right.
It's very, you know, is the cat in the box or not? Right? How, how, what's your advice Sure.
To grasshopper out there right. About how to deal with this? That's A great question.
So, you know, it's when we're uncertain about something, that's actually when we measure. And the more uncertainty there is, the more measurement there is. When you stand a lot to lose, when there's high stakes and you, there's a lot of uncertainty.
That's actually where measurement comes from. If you think about statistics, right? When statistics came about, because someone had small and messy data and they still had to make a bet.
In fact, one of our main statistics today comes from the Guinness Brewery. It's actually considered part of their intellectual property where they're using very small amounts of data to make forecasts about crop yields, things that go into beer and whatnot. And so small, messy data to make better forecast.
That's the same thing today. Even with ai, in many cases you think, oh, we have all the data. Well, we, we have sensing and artificially intelligent adversaries.
On one side, we have a business that's digitally and AI transforming on the other. And here we are in the middle. So there's, we're just surrounded by uncertainty.
And the stakes are large. I mean, just look what happened with Jaguar Land Rover. You think about Marks and Spencers we're talking hundreds of millions of billions of dollars of impact.
So the question is, if we were gonna say, well, it's, if we say it's immeasurable, if someone were to say that to me, what they're saying is all possibilities are equally plausible to me. They're gonna say, uh, we could be hacked a hundred percent of the time all the time. Or maybe it happens 0% of the time.
So, well, what do you do in that case? Well, you say, well, since I, I'm so uncertain as a security leader, you know what I'm gonna do? I'm gonna spread too little butter across way too much bread.
Right? It's a Tolkien quote. Um, but there's a sun Sue quote, uh, from this that's really great.
He says, he who is everywhere is weak everywhere. So the idea is that a general who's gonna deploy forces everywhere ends up being weak everywhere. So in the case of security, while we have a lot of uncertainty, we wanna measure so that we can take those resources.
Again, we stand in the middle here. We got, again, sentient, artificially intelligent, bad guys here. We got digital and AI transformation here, by the way, who typically has 10 to a hundred x the budget that we have.
And here we are in the middle. We have to measure to focus our resources. Sorry I went a little long, but that was kinda the gist of my talk.
You're a treasure man. I, I could listen to you all day talk about this. It is great.
So I think you've outlined the problem and the, and the environment that we're dealing with. Now, some may say, look, you gotta fight fire with fire. Right?
You got the AI stuff here. You got this transformation, which is AI powered here. I gotta have AI here too.
Yes. What do, is that the answer? Well, I mean, I don't know if you, when we say, is that the answer?
I mean, is that the answer to all of our security drama and dilemma? I would say I always look for the magic bullet, but I I, there's no Santa Claus either. Very good.
Yeah, no agree. So, um, yes, we have to use ai. Um, here's something that's distinctive about Qualys.
We're using ai. We also happen to have about 120 to a hundred, somewhere between 120 and 150 researchers, not just researchers, award winning security researchers. They just won two pony awards, uh, back at Defcon.
Yep. This, they've, they've done this two or three other times as well. So we have this elite team.
What you wanna be able to do is take that team, use them to actually do reinforcement learning with your AI models on somewhat of a continuous basis. And obviously bringing in all that massive amount of data from, in our case, enterprise true risk management. You want to have all of that working together.
So it's not just AI by itself, but you want the AI plus the human expert discernment to work together. So this is, this is one of the reasons why I'm here, is because I think this is part of the, I I guess it's the data or AI or measurement moat that Qualys has. Is that an opportunity to work with just what I'd call a, a cesspool of security iq.
And these guys bring that together with AI and data to make, make a big difference. So it takes the people and the AI together. So it, it's, you're not even talking human in the loop.
You're talking a true partnership. Like a si almost like a sidebar. They're putting on this, you know, I don't know.
Yeah. T see on that, that we will get killed over here. Yeah, we might.
I mean, so that's human enhancement. Yeah. Yeah.
Right. And, and that may be, you know, something we're gonna see coming down here, but I, I think right now we're still in that partnership phase. Well, look, AI does what AI does.
Yes. And we're going to use, it's a tool. Yeah.
Like every other tool, humanities use since, you know, homo erectus or something. But we also have to recognize that there are certain things that the human still has to do. Yeah.
That, you know, it's, it's gonna take a human. Right. And, and I think that's where we are today.
Now we're seeing the rise of agen AI become much more prevalent. Even the generative ai ai, you talk to some of these people who are really into ai, they'll tell you generative AI is yesterday's news. Right.
Right. How's that changed the equation? Well, I, So that might be marketing people.
I mean, gen so generative models by the way, not to get overly nerdy, but generative models are a thing. And so the idea where you could have some learning off some data, and based on that the model can then extrapolate, make inferences, and even generate new data, new scenarios, that's a generative process. So that doesn't go away ever.
No, no. I, I think that's table stakes for the age. 'cause without it, the agents can't operate, they're not autonomous, they're just APIs.
Yeah. So yeah, just a, some assumptions in the modeling there. But yeah, genic ai, the idea that it, you can have composable models that, um, and we use this word autonomous, right?
Um, I think that, you know, it's autonomous with constraints, right? You, you, you want it to make reasoned, uh, inferences and then take deterministic and safe actions. Yep.
Right? And so again, when I go back to this idea of that we have all these researchers, we can look at things like Mitre attack paths, right? We can look at the combination of attack paths and controls.
By the way, the combination of attack paths plus controls, plus exposure, that's a mathematically, uh, massive. Like we humans cannot reason over that complexity. Great.
We have AI for that, but AI's only gonna be as good as the assumptions that are put in underlying it. So again, I wanna go back to the idea that it's really, maybe you call it a human in the loop, perhaps you call it reinforcement learning. But for us, and again, this is where I think it's a Qualys distinctive, is that we have this elite set of humans, these researchers, award-winning researchers, bringing them together with massive amounts of data.
We have this giant data lake, right? Bringing that together with ag agentic AI becomes the sort of scenario where you can start saying, okay, this is how you can start looking at not only just the deterministic action you can take or have the models take patch this, block this, but also start saying, alright, given your environment, given these attack paths, given these adversaries, here's how we can start rank ordering. How you go about purchasing controls, how you go about making investments.
At what rate do you roll those out, given your financial constraints, what's the most optimized approach you can take so that you avoid spreading too little butter across too much bread, but you start focusing on the risks that matters. So that's, that's why I'm here. That's why I'm excited about what Quas is doing.
Absolutely. Hey, last question. I'm gonna go off the reservation a bit.
Sure. Okay. Sure.
I mentioned Quantum a few times. Sure. Quantum and security post, you know, post quantum cryptography, and there there's been a lot of buzz around, Hey, we need to be getting ready for quantum.
It may be three years out, five years out, maybe more. Right. Not much more.
Right. Um, what do you, in your role at Qualys, this is kind of something on your, on your desk, right? Yeah.
Yeah. What do you, what are you thinking? What are you seeing on that?
So it is kind of interesting with actually, with, with what's happened with crypto most recently, but I, as I looked at it, there's something like one, maybe 50%, if not one third of crypto will be completely exposed. I think there's more recent changes where they're saying, well, okay, we're have some protection here. You know, again, I'm not, not a crypto expert and don't claim No, you get it.
Not even on tv, even though it was a tv. Mm-hmm. Um, but I think as a risk leader, we do need to be thinking about that.
So what's, what is plausible in terms of, you know, in, in fact, even thinking about the future, I'll say this, and I talked about this on my talk, uh, I'm gonna kind of go off the reservations, but prediction markets. Are you familiar with prediction markets? Yeah, sure.
Big thing ties to crypto as well, but people making bets, like prediction markets significantly outperformed, uh, the pollsters in the last election. The presidential election. Yeah.
Great. Where they failed, by the way, was on, uh, forecasting could be the next Pope, by the way, I, people were betting on the Pope thing, right? Uhhuh.
So it's kind of interesting. Oh, they bet on that. Whatever it is, right?
But the idea of taking that same approach all, so given what we know about crypto, given what we know about the current state of the world, how can we, how can we start measuring and creating really that's already modeling. How can we think in a, you know, relatively mathematically unambiguous way that retains our uncertainty without obscuring what certainty we do have, make the best bets. That is what risk management should be doing.
Sure. And yes, I am thinking about that stuff. I'm thinking a lot more though right now about AI and what that means.
Yeah. Than crypto. Well, I, I think it, and I think AI becomes the force multiplier, or maybe it's the other, maybe when few day does come and we do have quantum combined with AI though, right.
I think those, they're too volatile, you know? Right. Uh, get crazy.
Sounds Like more employment. I don't know. More security, Job security.
Yeah. For the security teams. Well, if they don't replace us with AI robots or humanoid, whatever physical AI is.
Right. Right. Calling it Richard, thank you so much.
Thank you so much. Pleasure. Likewise.
This guy's great. Do check him out. Your books are still out there too.
And everything else, it's getting a little loud here, but I'm hoping you could hear us. We're live at, uh, quais Rock on. We'll be back in a moment.