Premeditation of Evils – Risk Planning for the Future with GenAI | RSAC Virtual 2025
In cybersecurity, anticipating the worst isn’t paranoia—it’s strategy. This session introduces creative thinking frameworks designed to help leaders and security teams collaborate with Generative AI to stress-test assumptions, identify opportunities, explore edge-case risks, and uncover blind spots—often caused by cognitive biases—before they become breaches.
Drawing inspiration from Stoic philosophy’s premeditation of evils—the practice of imagining future harms to build resilience—this talk repositions GenAI from an operational efficiency tool to a creative partner in strategic planning. We’ll explore how GenAI can enhance strategic imagination through various techniques that expand your field of vision. Attendees will leave equipped with actionable tools for improving red teaming, scenario planning, and creative problem-solving.
Transcript
My name is Leslie Grande, and I am not a cybersecurity expert. So you all wonder what the heck are you doing here? Talking to me, listening to me.
Uh, I am, however, an expert on creative problem solving and creative thinking techniques, and I spent the last year and a half writing the book that Mark was telling you about doing, uh, a lot of research on what cognitive research has been done, and also really understanding how to help people access their creative capacity to solve problems. And I think a lot of us, uh, suffer from lacking, uh, confidence in our creative abilities. And so my mission is really to inspire people to see that everyone is creative.
Creativity is everyone's superpower. And the real question is how do you leverage it? How do you expand it, right?
And how does it help you solve problems in your daily life, whether it's personal or professional. A little just about my background besides being an author, I, uh, spent over 25 years as a product executive at companies like Apple and Amazon Best Buy, discovery Networks and T-Mobile, where I launched the first Android phone with Google. And, uh, through that process, I've, uh, really gravitated towards zero to one products where really there's a lot of ambiguity and a lot of difficulty in understanding the, the market and the customer need.
And so really sourcing the right opportunity and creating a product that really excels on product market fit. But that skill, that technique is also really important for any kind of problem that you face. And that's what I'm here to tell you today, are some techniques that you can use when you're really doing some risk planning to really expand your capacity to think big around what could prevail and, uh, what you might face.
Uh, my, uh, relationship with the University of Washington is that I, uh, co-created an executive education program called the Product Management Leadership Accelerator. And our next cohort starts in June. And, uh, it's really a, a, a pleasure at this stage in my career to, to inspire and hopefully, uh, inspire people to reach their full creative capacity.
I wanna kind of give you a, a little bit of why are we talking about the stoic premeditation of evils as it relates to risk planning. How many of you are familiar with a premeditation of evils? Oh, good.
This is the best answer I could hope for. 'cause hopefully you're gonna walk outta here learning something new. Now, the stoics belief that the best way to prepare for success is to imagine failure cases, to understand the things that are improbable and unlikely to occur and what might cause them.
And not so much to imagine the things you know and what could happen with the known, but to explore the unknown, the place that you're most uncomfortable, the place where you have least information to really consider your expertise. The thing you lean into when you lean into expert, think you avoid those things that are uncomfortable. You are more likely to stay in the zone where you can perform well, but you will also overlook those things that creative hackers and attackers are looking to do, which is find their way in, in a place you don't expect.
So this is a famous quote from Seneca, and if you keep this in mind, you remember, the things you don't pay attention to are the things that could be most catastrophic. And that's what the premeditation of evils is, is meant to support in your planning. So when you think about it, these are the kind of questions that you would ask.
And why do you ask these questions? Well, you wanna be immune to surprises. You wanna actually believe that anything could happen.
And unless you think about it and explore it, you won't be prepared for it. And the stoics really believe in robust preparedness. This is not about rumination.
This is not about catastrophizing. This is really about believing that you will not be surprised when something occurs and you are not prepared to attack it back. And so this is really important.
These are the things where when we talk about what does a premeditation of evils do, it explores the worst case scenarios in a way that gives us confidence that we're ready for them. So the value of a premeditation of evils experience is that it's a structured form of foresight. It's giving you a way to look forward without actually worrying about what you have or what you've done.
It creates this idea that the model today may not be adequate for things you hadn't considered. So when we think about considering intentionally contradictory ideas, that's a place where most of us get uncomfortable when we have to believe that something could be secure and insecure at the same time, it's very concerning. How is that possible?
How will I ever know we're protected? If I can believe that something that is secure can also be insecure? But unless you think that way, you will not be prepared should someone find a vulnerability in what you think is a secure system.
So your strategy has to intentionally include things that seem like they contradict your basic assumptions. And the best part of the premeditation of evils is that it really gives you the confidence that you can be cognitively flexible when something you didn't expect arises. Most people are so rigid and rigorous that it's hard to leave room for the unexpected.
But what's really healthy is when you acknowledge the unexpected could exist and you have strength and confidence in your capacity to handle it, right? The idea of stoic is, I've seen this before and I'm not helpless, or I've considered this possibility and I'm prepared. So that's why premeditation peoples work so well for cybersecurity.
'cause even the most hardened security can go sideways if you're limiting your focus to what is known. Some pessimism kind of can circle around this topic, and people can think that they're dwelling on the negative, they're catastrophizing, they're imagining the worst case scenario. But instead, this exercise is really about the action that occurs when something bad happens.
It's really meant to inform and trigger behaviors that are emotionally controlled and really robust in how much of you is available to attack the problem. If you're worried about what you don't know, if you're concerned about the constant ideas that you have of way things, the way things can go wrong, you are more than likely not going to act in a healthy manner when that happens. And so what you wanna do is stay aware of the possibility that something could go south at the same time that you're managing your expectations, that these things are, are, are plans that we need to make to, to really create obstacles from them having the impact that we don't want them to have.
So the negativity gets controlled by us facing our fears head on. There's a lot of, uh, concern that when you spend time wondering about what could go wrong, you waste time in the corners and the fringes. And the thing about that is with the premeditation of evils, you wanna start with the broadest lens possible.
And then you wanna ask, when you've captured all of those things, what could have the greatest impact? And it's the impact that will help you prioritize. And it may be that thing on the fringe that only once in a blue moon happens, but when it does, everything goes down right?
And that ca that is a catastrophe you want to avoid. So one of the things that's really important is that you focus on the assumptions around that catastrophe, and what are those assumptions that you can control and what can you manage against the idea that it's broad is only in the start. Because if you let yourself ramble around and, and look at all of these things and don't have a structure for framing up which ones you attack, which ones you prioritize, which ones you investigate and explore, second and third level consequences of, then it will be a useless exercise that will rapidly turn into rumination of the, of the evils that could befall you without taking action.
And what you have to remember is that premeditation of evils is about taking action. So what makes generative AI such a good partner for this type of risk planning? Well, the best thing about generative AI is it's not attached to any of your ideas.
And by the way, not attached to any of its own ideas either. The idea that generative AI can provoke some thoughts is actually the point. Even if they're outrageous or outlandish or unbelievable, the idea that they're bringing forth ideas, these tools are able to get you to think about these things, is likely to overcome the group and consensus thinking that happens within an organization.
You're gonna have a voice that isn't worried about getting promoted, that isn't worried about being wrong, it isn't worried about being unpopular, it isn't worried about its career. So it's going to give you the impression or the idea with the least amount of baggage giving you the opportunity to assess it without any emotion. Humans have a really hard time doing cross-cutting to find patterns.
It's really hard for the human brain to see patterns in things that are not obviously associated. This is where gener generative ai excels, right? Being able to connect the dots between how something in biodynamics works and how it might actually help manufacturing, right?
That's hard for people to make those connections as humans, but it's easy for generative AI to do it. We all know generative AI is nothing if not speedy, right? It's, it's always feeling like it's cutting, getting back to you with a wealth of information in a short amount of time.
And, and what's great about that is when you're going broad and your lens is broad, you want the largest amount of things to come back for you to prioritize and consider. But then you also want the depth. You wanna be able to, to mine the depths of one of those, those ideas, and look at second or third consequences and go deep to see whether there's a, there, there, or whether it just on the surface looks like it's a problem you should solve.
And so, again, generative AI won't be offended if you ask for explanations, if you challenge its thoughts, if you actually come up with a contrary opinion and ask it to debate why your thoughts are not as strong as the uh, proposal it made. It's a fabulous thought partner from that standpoint. And the best part of it is we all come with learned experiences, lived experiences, intuition, history, all of the emotions that we have, all the goals that we have.
Generative AI has none of that, right? It doesn't have the bias of what was done before, and it doesn't have the bias of what your boss said, and it doesn't have the bias of what's considered normal. In fact, in many cases, that's what's problematic about generative ai, is it doesn't always have context as to what's culturally normative or what's socially acceptable.
But in this scenario, this is a, this is an asset, this is a really valuable asset for creative thinking, is to be less attached to the idea in order to be more open to the prospect of what it brings with it. And I think that's the thing that really makes generative AI the best partner for a premeditation of evils exercise. So how do you look for threats that you don't expect?
What are the ways that you go about it? Well, part of the way that you do it is you look sideways. You don't look linear, you don't look at cause and effect.
You look at other things that are to the left and to the right. You look inside as much as outside you look forward, but you also look backwards to forwards, right? The idea that there is no linear approach to how you solve this problem is core to working with ai because it can be a crutch for you to let go of that standard way of thinking, cause and effect problem solution.
Because what may happen is the problem may not be the problem. It may be a symptom of a problem. And with generative ai, you can mine the depths to see whether that symptom actually has a root problem that's bigger than the thing you see or observe.
And, and, and with no offense for you challenging whether or not that's actually the most important thing. So there are three types of contradictory thinking that really support a premeditation of evil's exercise. So paradoxical thinking, we've all heard of things like bittersweet.
My kids go off to college and it's bittersweet. That means both things can be true. It, it can be sad and it can be happy.
I can be depressed and I can be proud, right? Things can exist. Both things can be true.
So balancing tensions is where you find some interesting moments because not everything is clean. Not everything is black or white. The idea that both things can be true can muddy the waters of your view, and it allows AI to say, oh, I have boundaries now, so I have to believe this is true, and I have to believe this is true.
And then I have to navigate within those boundaries. Again, that's a little bit difficult for the human brain to do. Opposite thinking is one of my favorite.
If you're a Seinfeld, uh, fan, you probably remember the fabulous episode where opposite George did everything the exact opposite way, and everything worked out beautifully as a result, right? The thing is, doing things the other way does result in different outcomes. So working from back to front might actually cause you to think about an obstacle that could actually prevent you from being successful.
So opposite thinking is really important. This is where you flip your assumption if, if I think white is black and now I think black is white, what does that mean? Why would I change how I think about it?
Well, partly because to some people who don't see the problem the way I do, they may be navigating it that way. And it helps me to recognize that everyone doesn't approach a problem the way I do. And so opposite thinking is a really helpful tool to actually flip my assumptions.
And again, premeditation of evil really focuses on faulty assumptions, assumptions that could lead to your failure. Inversion thinking is really awesome because it's what what does failure look like? How do I create a failure scenario?
I'll give you two quick stories on this. One is, uh, um, Charlie Munger, who is the COO of Berkshire Hathaway. He tells the story that this is what his life, uh, strategy has always been.
And he learned it when he was a weather forecaster in World War ii, trying to keep pilots from crashing. And he didn't know anything about flying and he didn't know anything about weather. But in World War ii, you got assigned a job and you just kind of had to go figure it out and do it.
So what he decided to do was go ask all the pilots the conditions that would cause him to crash. Just tell me those, and those are the only things I'm gonna look for because everything else means you're okay. So if I can go figure out what failure looks like to the pilots, I will actually then plan for success because I will avoid all of those circumstances.
When I started my career, I started the film industry before I moved into technology, and I moved to California and moved to Hollywood, and I didn't know anybody. And I was not an eppo baby, and I had no idea how to get a job done, but my parents thought it was gonna be the worst idea ever. And in order for them to be proven wrong, I just had to avoid failure.
I had to look at the circumstance where I would fail and do everything opposite of that to succeed take jobs I didn't want in order to get the next job. I did meet people that I didn't think on the face value would give me a connection, who ultimately were two connections away from somebody who got me a better job. The idea that I was open to things that would avoid failure really gave me a key to success.
And ultimately, I made it to the Director's Guild and, and worked on films like The Abyss and Terminator two and Tremors. And so I had a career, but I built a career on the back of not wanting to fail, not wanting to have a case where I couldn't get a job or I couldn't find someone who could hire me. So three practices to to consider when you're doing this, uh, kind of an exercise.
One of them is, you know, we, we've all been trained to do prompt engineering. And prompt engineering really forces us to be more specific and put in a lot of context and a lot of detail and be helpful to our AI partner by giving them as much information as we can. That's actually the opposite of what you should be doing in a premeditation of evils exercise.
You should really start as broad as you possibly can. And how do you do that? Well, you think of things that you wanna keep out of the prompt to make sure that you're not overly focusing the AI output on the actual part of the solution you've already implemented.
You want everything to be on the table. And one of the ways to do that is to use hyper NIMS versus hypo nims. And what does that mean?
Well, a hyper nim would be a word like attach, and the hypo nim would be staple clip glue paste. And now all of a sudden the prompt is telling AI, I only wanna glue paste. I only wanna look at those things when in fact you can add those in layers later.
But you've opened the door for thinking at the most, uh, broad altitude, what you could possibly do with, with a set of problems. You don't wanna add in all of the elements that are in your system or all of the things that you think are given too early because you will navigate to solutions you already know you wanna look for the ones you don't know, and you wanna be as broad as possible. You also wanna look at second and third level consequences.
You really do have the opportunity with gen AI to go again and again and again till you see where that road takes you. And the idea that the second and third level consequences could actually be more severe than the initial breach or the initial vulnerability is what's really important in this exercise. You wanna step through the, the, the initial pain to see all of the pain that can be caused by that mistake, because in that light, something looks a lot bigger than it does perhaps when somebody just broke into your system, right?
If somebody gets into the system, okay, that's a problem. We wanna stop that. But what can they do once they're in the system and how do we stop all the places that they could wreak havoc?
And then the last part, which is really important too, is you wanna look at third parties as well as internal actors, because while bad actors might have nefarious agendas, sometimes careless employees are just as dangerous. And to be able to look at all the parties who interact with the system and all of the places where they can touch it, you're going to be much more thorough in thinking about when something happens, what the risk of that axis is. So if I'm just careless, how much power do I have to create chaos?
If I'm nefarious, how deep into the system can I go and how much havoc can I create for the agenda that I have? And both of those would be completely different paths down a premeditation of evils exercise, but you'd wanna take all of those paths to make sure you've covered the ground. So I'm gonna give you three examples, one for each of these types of thinking.
So paradoxical thinking, as I said, it's balancing the tension between different ideas. So here you think about, I have a really restrictive security system, but how am I so vulnerable with internal employees? Well, one of the ways that you might imagine that is it's so restrictive that there's a subculture around the company of ways that people avoid it.
People navigate through different things. They share passwords and credentials. They have figured out ways to not be slowed by the extra security that you've imposed, right?
And so how can the most rigorous system be also the most risky because of what we created is so difficult for our employees to use, right? So balancing the idea that it's really great for perhaps for external hackers, but it may not be as great for internal employees who are doing things like sharing credentials, right? So that's a good example of, of where a user experience changes the security of the system that was designed for external hackers to prevent breaches opposite thinking.
So the the same problem, you might say, well, what if we actually made things less secure? What would that look like? How might we change the authentication process to facilitate a less secure system?
And what would that create for us? Because in that scenario, that's kind of what credential sharing is doing, right? It's actually making a less secure system out of a secure system you have.
So when you think about what would I do to design a system that would actually not protect my, my business from my own employees, you have to think about the opposite of what you wanna achieve. And that in, and in that, can you still maintain the goals that you have for compliance and it security? Lastly, in the inversion thinking example, you wanna think, what's the worst thing I could do?
This is my, how do I not get a job in Hollywood? Like, what's the thing I do? Well, I sit there and I send out paper resumes to people.
That is not how you get hired in Hollywood, right? That is not the way it works. It's a network thing.
It's a, it's a being at the right place at the right time thing. So what does a security solution right look like when it fails on all fronts? What are the elements, the, the traits, the attributes of that kind of a system?
And one by one, what do I have to do to negate those, right? Working backwards from the worst to the best helps me see all the places where I have holes to plug. So the premeditation of evils is a really powerful risk strategy with generative ai because it expands your field of vision, it gives credibility to things that you're easy, easily dismissive of, because in the context of the bigger picture, it could be a cascading series of things that actually cause the catastrophes that we might face.
And so, by looking broadly, we can also look at the patterns and associations across those things that actually could connect one small problem into something that becomes a larger problem. And so this idea that these edge cases that we dismiss because they don't look as severe on the face, may actually be more severe when we look at them in the context of a premeditation of evil's exercise, the fringe actually becomes the vulnerability that you most need to protect, because it may only happen once in a, in a blue moon, but when it happens, there's no recovery. If you haven't planned for that failure case, you won't be prepared if it happens.
So with that, uh, I'll talk to you just for two seconds about my book. It does come out on Tuesday. I'm super excited about it.
Uh, the, the thing that I think is really important for people in any field, whether it's finance or cybersecurity, is to recognize these techniques exist in a way to help you structure your thinking, especially when you feel stumped or blocked by the things that you know today. And by giving yourself permission to explore the edges and also use these frameworks to ask questions that don't, um, belie your own biases or don't present a conclusion within the prompt, you're more likely to uncover the things you hadn't thought about. But moving from prompt engineering to this type of structured framework is important.
Not that prompt engineering is bad, but when you're really looking to go beyond your own cognitive boundaries, these techniques can really help you ask questions in a different manner to really unlock the potential that you have inside your, not only your experience, but inside your own creative capacity. So if you wanna, uh, look at the QR code, you can go up to my website. You'll learn more about the book, you'll learn more.
Also, the book is really, uh, a kind of a playbook because I, I provide exercises in the book. So to practice some of these techniques that you might not be familiar with, there's some, some exercises there. And every chapter has a section on how to partner with generative AI on that technique.
So whether it's these three techniques or seven other ones that are in the book, they're all useful when partnering with ai. But how you use them with AI is really the key, because different benefits accrue when you have AI as your partner and you're going through the process of problem solving with no anticipation that you know the outcome, but with a great idea that you have, you wanna solve a problem that you know is the right problem to solve. And even AI will challenge you that maybe that's not the right problem to solve.
And so one of the reasons I wrote this book is to give people the confidence to use AI as a collaborator and a co-creator and a solution prompter, and a Provo Provo provacator around ideas that you wouldn't necessarily come up with yourself.