Managing AI Adoption and Security Challenges with Anand Oswal at RSA Conference 2024
Anand Oswal, senior vice president and general manager of network security at Palo Alto Networks, delves into the challenges posed by the rapid adoption of artificial intelligence in the enterprise. Anand discusses the phenomenon of shadow adoption, where employees access AI applications without IT oversight, emphasizing the need for holistic security solutions to protect against a range of threats, including those specific to AI-powered applications accessed through unmanaged devices like browsers. Palo Alto Networks announced new products aimed at securing both employee access and custom AI applications, showcasing their commitment to addressing the evolving cybersecurity landscape.
Transcript
This is Textron tv. Hello, I'm Krista Macomber with techron tv, and we are live here at the RSA conference. I have the pleasure of sitting down with Anand Aswell, who is the, um, S-V-P-N-G-M of the network security business with Palo Alto Networks Anon.
Thank you so much for joining us today. Thanks for having me. Yeah.
How is the show going for you so far? It's been great. Yeah.
Already? Yeah, I know it's busy. Uh, already busy, right?
I know we're sitting here actually early Monday afternoon, but the conference is already, as you can see, full swing. Um, and so anon, I figured we would kind of jump right into it. So no surprise.
Artificial intelligence is a big theme, you know, here at the, at the conference as it is really kind of in the tech world at large. And I know, um, before we, you know, kind of hit the record button here, you and I were, we're talking about, there's definitely, um, a few dynamics to adoption that we're seeing. And one of the, um, one of the components that I figured we'd start with is the fact that as these artificial intelligence applications are being built and coming to market, um, employees are beginning to access them without the knowledge of it.
It is that old challenge of, you know, kind of this shadow adoption. Um, so can you talk a little bit about, you know, are you seeing that as well, um, maybe within your customer base at Paloalto? Absolutely.
Well, let me say, look, AI is transforming business. Yeah. It's adding significant, significant value Yeah.
To every single enterprise. The radar of adoption of a ai, the technology is faster than any technology in the history of mankind, right? If you think of AI applications that employees of organizations are using to increase their productivity, that thousands of applications available.
I read a research recently that said that, oh, 57% of all employees are using these Gen AI application and tools, whether it is aware of it or not. Exactly. That's happening.
Yep. It really is. It really is.
Um, and I think, you know, kind of another component that we're seeing is that organizations are not only using some of these, you know, kind of more general purpose AI applications. Yes. They're also creating custom air applications, um, to better kind of serve the needs of their, you know, of their business and of their customers.
And there's a whole slew of kind of new infrastructure considerations that comes along with that, things of that nature. Absolutely. So let's tackle the first one you talked about, Mm-Hmm.
Employees accessing these new tools available without it being aware of it. Mm-Hmm. Um, and there are platform of such tools, right?
From tools which are productivity enhancing tools, which, uh, will automate your workflow analysis, your data analysis, and so on and so forth. Yeah. To developers using these tools to write code, to complete code, to simplify code, to automate their workflows to sales and marketing people.
Yeah. Like, you know, they're using it to write their blogs, marketing emails, generating collateral, and so on and so forth. And we have thousands of such applications coming in every day, and this number keeps increasing.
What it really needs is to understand who's accessing what application Yes. And why. Yep.
Then you need to decide, should I allow this application? Should I deny the application? Yeah.
Or should I limit usage of this application? If you allow an application, you wanna ensure that it has secure usage and you have the right level of controls, uh, that you can have only the sensitive data not leak out, but that's a big concern for organizations. Yes.
Right? And last, but not the least many of these applications are sending responses back to you. How do you ensure that you don't have malicious attacks coming in, uh, to your enterprise?
So all of this makes it a very holistic solution. Yeah. So really you wanna have visibility, you wanna have full access control.
Yes. You wanna have complete data protection control and the general controls. Yes.
Yep. And then protect your organization from all these threats. That's really what makes it complete.
Certainly none. And we're, we're seeing that as well. I think, you know, a couple of the big considerations, just to echo your comments, certainly are, you know, making sure that the AI application is kind of secure, the accessing data, not accessing data that may be, you know, uh, from an overprivileged perspective.
Um, and as you mentioned, the flip side of the coin too is kind of, um, you know, maybe especially when we think about generative ai, the content that's being generated and kind of the integrity and security behind that. Um, so maybe we can take a moment here and talk a little bit about Palo Alto Networks. Um, can you share a little bit, I believe you have an announcement.
Yes. Um, so can we share a little bit about, um, what Palo Alto Networks is doing to address these issues? Yes.
Palo Alto Networks is having a holistic complete solution. Mm-Hmm. How do you secure AI by design?
Mm-Hmm. And that falls into the two categories we talked earlier about Mm-Hmm. Securing employees using these gene applications.
Yes. Ensuring that your network administrator, it has visibility, has control, has granular data protection policies in place and threat protection policy in place. Mm-Hmm.
Now, the other factors are every organization, every organization is building these AI powered applications. Mm-Hmm. Because they wanna transform their business.
They wanna have engage with their customers in different ways. And I say AI powered application is really the third wave of application transformation. You know, long ago applications were built on a three tier architecture.
Yeah. You got your front end, you're the application and you're a database. Then key in the cloud, cloud said, let me help organizations now modernize these applications using microservices.
AI powered application is the third way. And it's not just plugging in a model, an application and saying, you're done. You're bringing in entire new app stack.
Mm-Hmm. AI infrastructure. Yeah.
AI models, tools and plugins, data sets, and all these are communicating with each other and the outside world. Yeah. This increases the attack surface attacks from a supply chain perspective, from a configuration perspective Yeah.
And runtime perspective. Mm-Hmm. So we are basically having a holistic solution, AI security, posture management, and AI runtime security Mm-Hmm.
To ensure that applications that you build for your enterprises are secured by design. So it's kind of, it sounds to me like it's both sides, both sides of the spectra. Excuse me.
So it's, as you mentioned, um, having that security posture upfront. Yes. You know, as the application is being developed to make sure kind of that it's secure at the start, and then once it's actually moved to runtime, you know, having that visibility into the threats and, and things of that nature.
If you think of AI security, posture management, it's really about, uh, identifying and remediating Mm-Hmm. All the risks you're seeing on supply chain, all the misconfigurations, you're seeing all the awareness that you need to have around sensitive data that is not secure. Mm-Hmm.
And then AI runtime protection is around protecting your applications, your models and data from all these new threats that we are seeing in the ai ai work. You know, if you think of AI powered applications, they had the same threats as classic applications, but then they Yeah. Specific threats, threats around things like prompt injection, which in very simplistic terms is how does the attacker fool the model to go beyond the guardrails to give you the information that they would not give you in normal case Mm-Hmm.
Information about your training data or send information about your clients. Similarly, you have model DOS attacks or data leakage attacks. All of these need to be talk through holistically when you're protecting your new AI port application.
Sure, sure. Um, SOAN, can you share about specifically, um, what Palo Al Alto and Networks is an at in here at the show? Yeah, So three products.
First, AI access, security. Mm-Hmm. Ensuring that any user, whether you're in the office at home is from any device from managed devices or unmanaged devices are able to access these generic applications, which help them increase their productivity, but do it in a secure fashion.
Mm-Hmm. And second, as as organizations are building these applications, how do we ensure that they have the right security posture? Mm-Hmm.
So supply chain risks, configuration risks, Mm-Hmm. Data exposure risks and, and AI runtime security. Mm-Hmm.
For ensure all the runtime threats that we see, they're protected against those Mm-Hmm. That's what we're announcing tomorrow, really around how do we ensure that organization, um, secure all the AI usage by design. Sure.
Sure. That makes a lot of sense. And I think, uh, maybe one topic that we didn't touch on is the fact that, um, you know, customers are going to be, um, you know, accessing these, um, AI applications through perhaps their cell phone through a whole variety of means.
Maybe an non-secure browser. Um, that kind of circling back to this concept of, you know, shadow it maybe are outside of the control of it or maybe just not as secure as we would like. Yeah.
Um, you know, can you talk a little bit about how, um, the new announcements are going to address that? Sure. Um, you know, 90% of all successful ransomware Mm-Hmm.
Originates from unmanaged devices. Mm-Hmm. About 80% of all data breaches happen from applications that you're using in the browser.
Yep. For the most part today I'm working in my browser. Right.
So what secure enterprise browser gives you is ensuring that for your unmanaged devices, you're having complete protection, complete protection from a zero trust network, access perspectives, complete protection from a workspace perspective, and all the data controls that you need for your, uh, applications you access Mm-Hmm. And then even for your managed devices, you're adding a new layer of protection to protect those devices from all the advanced phishing attacks happening, uh, on the browser. The browser's the only entity that sees everything unencrypted, and it's really the right place where you can apply all these granular controls and prevent you from attacks that you've never seen before.
Yep. And that's very important because we do see that kind of phishing and social engineering, these are still the primary ways or very important prominent way that attackers are, you know, kind of penetrating our networks and our environments and gaining access a hundred percent. Yeah, I agree.
It also helps simplify it. Mm-Hmm. Today, a lot of times when you're having contractors onboarded, you have to ship them a laptop.
Mm-Hmm. Uh, and sometimes they're working only for a week or two weeks a month. Mm-Hmm.
And it's very cumbersome. Or you use tools like VDI or Desktop Desktop Service, which are, you know, slow and clunky. Yep.
Secure enterprise browser is a very nice, elegant solution to address those use cases to simplify it, but at the same time, get all the security controls you get with your SS e architecture. So we are completely integrated them with our SS e offering. Excellent.
Excellent. Anand, thank you so much. This has been, um, a very insightful conversation.
We really appreciate you sitting down with us here at RSA conference 2024. And we would also like to thank our, our audience for watching. Again, this has been text on tv, and please, um, tune in for, um, more of our great content coming up here at the show.