Why an AI Leader is Necessary for Creating a Strong Security Strategy – Techstrong AI Podcast EP46
Amanda Razani speaks with the executive VP of product for Skyhigh Security, Thyaga Vasudevan, about how organizations can ensure they are equipped to handle the cybersecurity and implementation challenges presented by AI.
Transcript
Hello, and welcome to the Techstrong AI Podcast. I'm Amanda Ani, and with me today I'm excited to have Thaa Vasu Devin. He is the executive VP of Product for Sky High Security.
How are you doing today? I'm doing very well, Amanda. Thanks for having me on this podcast.
Happy to have you on the show. Can you share a little bit about Sky High Security and what services do you provide? Absolutely.
Um, sky High Security is a cybersecurity vendor, and we are specifically in the security service edge market, which is part of the broader SASS e market, secure access service edge. And at the heart of it, uh, sky High Security helps organizations protect their users, uh, as they access, uh, applications. Applications could be cloud applications, applications could be on-prem applications, doesn't matter, but to be able to provide the zero trust, uh, security for an access standpoint for their users.
And once they have access to these applications, we help organizations to be able to protect the crown dwells, which in today's world is really the data. So being able to protect access and then being able to protect data is skyhigh security's, uh, biggest strength. And we do this, uh, from, in a unique perspective because we are the only vendor that offer this ability to do this both on-prem and in the cloud, and also do this in a hybrid fashion.
Wonderful. Thank you for sharing that. So, our topic of discussion today is, uh, why an AI leader is necessary in creating a strong and secure AI strategy.
So from your experience, can you share what are some of the challenges that leaders are facing right now? And and how do you suggest that they solve this, uh, with, um, a strong AI strategy? Yeah, that's a very relevant question, uh, for today's times.
Um, as you know, we all know that AI applications, uh, are indeed on the rise, uh, in pretty much every organization that we speak to. That is, that is already an initiative for leveraging the power of AI into their day-to-day operations. So what this means though, is that this comes with, uh, heightened security concerns.
Uh, as an example, if these applications, um, you know, the way AI applications work is that they all, they require access into vast amounts of sensitive data within the organization. And then they have what they call a, a learning on top of this data before these applications can be, can be leveraged. So at the end of the day, uh, how do you make sure that your sensitive data, uh, is not being leveraged or being trained into these AI applications?
So that's one part of the puzzle. The second part of the puzzle is, um, do the right set of people have the right access for these AI applications? So, as an example, if it's an application that's being built internally to mine, a lot of the customer data, and then being able to provide rich valuable insights, there may be certain insights that only the executives should be able to see.
And there may be certain insights where a marketing person or a customer success person can see. So to be able to ensure that the right person with the right role has the right access to the right AI application becomes a key part, uh, of the security, uh, ask as well. And lastly, every region, every industry is, uh, you know, evolving, uh, as, uh, you know, the use of ai.
And so a lot of regulations are coming up, uh, on the use of AI and, and the use of AI applications in the industries. So to be able to understand the compliance and regulatory challenges, uh, becomes, uh, an interesting challenge as well. So why do I mention all of that?
Because these are all the big challenges that an AI leader within an organization needs to think about. A, he or she needs to think about what is the business need of that organization and how can ai, uh, how can they bring in the power of AI into the organization so that they can bridge the gap between, uh, the power of technology and power of what, what the organization really needs. So we have to make some IT decisions, as in when we build these AI applications, what LLM models are we going to use underneath the covers?
Are we going to use a pass service host an AWS or Azure or GCP or OCI, or are we going to run this in-house? Uh, which means that's gonna be capital intensive, uh, but it's much cheaper to run it on an operational basis. So then they'll have to make these decisions on security.
What kind of security controls do they need to ensure that, uh, data doesn't, uh, get exfiltrated the right person has the right access and ensure that we manage through the regulatory and compliance risk? So really the, the significance of the AI leader then becomes defining the AI strategy and roadmap, which includes of course, security and then ensuring that the organization is well positioned to take advantage of the power of AI for their business needs. So once you have a good AI leader in place, do you have any advice or tips to ensure that there is good communication between that AI leader across the organization and be and between all important departments?
A hundred percent. And I think that is one of the key responsibilities of an AI leader, is to drive what we call strategic alignment, which includes cross-functional collaboration as well. So what I mean by strategic alignment is if the AI leader does not define a clear strategy for the organization, it can very quickly lead to disjointed efforts across the organization.
You'll have different business groups leveraging, as an example, different LLM models for meeting their own needs or leveraging different SaaS applications to meet their own needs. So the, so one of the key goals of the AI leader is to ensure that all AI investments within the organization, they're aligned with the company's strategic priorities. And the, the important thing to do here is because most of the time these AI initiatives, they span multiple departments.
So the AI leader then acts as the unifying force, you know, ensuring collaboration across technical teams, business units, and also of course, the executive leadership so that they can achieve these cohesive results. And then how do they track the end results? Um, you know, as, as we look to integrate ai, a lot of company leaders, I've been reading some articles, they, they don't see that end value result that they expected.
Uh, so what advice do you have for how do they achieve that end goal and track, uh, the value from it? Yeah, I think this is a very good question because this has come up in so many of our customer discussions about as they're double, you know, adopting AI within their organization. How do you find the right return on investment?
I think it all starts by setting the right measurable goals, uh, by the AI leader. So for each ai, I mean, where we have seen this work well is where for the AI projects, the AI leader, uh, you know, defines the success metrics for each of that project. And it depends upon what that initiative is.
So as an example, um, one of the com uh, one of our customers, they were leveraging the power of AI to mine through, uh, customer documentation. And the reason why they wanted to implement that was so that their end customers have a two things. It, they can find the right information faster, and number two, they don't have to spend a whole bunch of, uh, time in navigating through their documentation site to figure out the information.
So again, kind of related to the first point is they wanted them to find the information faster. So then if the, in, if that is the overarching business goal that defined the AI leader will say, if I'm going to be leveraging the power of ai, first of all, how does the experience then get better? And now as the end user comes and searches for information, then how do we make sure the information that they're looking for is indeed the right information and the customer's satisfaction is still very high.
So those are the two key measurable goals that they will track. And if they see that the changes that they have done on the AI project are already leading to better measurable outcomes, that is indeed the success from that initiative standpoint. Wonderful.
And then another question is AI is advancing so quickly and rapidly. Um, how do business leaders keep up and, and keep the most current, um, aspects of AI as it advances so quickly by the time they get one thing done, it it might be already obsolete? Yeah, yeah.
This is, uh, you know, it's indeed true. Um, this, the space is evolving very, very fast. So there are multiple, uh, way things that are evolving.
I think the first piece of the, the technology itself is evolving, right? There's no questions about that. Uh, every day, um, you hear about new AI SaaS applications, uh, coming up, which should solve a specific problem for the business.
Every day you hear about new LLM models coming up or existing LLM models getting updated. 0. You know, this just keeps on enhancing as things go along.
So that's the technology being being up to date on technology. The other aspect of it is that the security aspects of it are also evolved. Uh, what, what I mean by that is, you know, you, you need to ensure that you are on top of what, what are the security considerations I need to have for AI applications?
What you used to be doing for other SaaS applications may not be necessarily true that I need to do for AI applications. As an example, previously you were probably happy just saying, I'm going to allow or block a certain application, or I'm going to not allow sensitive data from getting uploaded into that application. But in today's world, for you need to look at one level below, what is the LLM underneath the covers, what is the risk of the LLM model being used?
And so as the AI leader, you need to think about and keep evolving your understanding of security as well. The, the next awareness that they, they always have to be is on regulations, uh, governance and regulations and compliance, right? What, what, because every day you hear about different countries or different regions coming up with new AI regulations.
So if you are a multinational, if you are operating in, in different geographies, then and, and you are dealing with a whole bunch of AI application with sensitive data, uh, then you need to be on top of what are my, uh, you know, how do I make sure that I'm, I'm compliant with the regulations of those regions? Because anytime you're non-compliant, then all the then, and then the, you know, the impact of not being compliant would be fines and that PR and all that, which is all going to be a negative impact. And will, it'll wash away all the great work that he or she might be doing with the use of AI within the company.
Absolutely. So if there was one key takeaway you could leave our audience with today, what would that be? Yeah, I mean, the one key takeaway would be embrace the power of ai.
It is once in a lifetime technology and it is going to make your life yours as an organization's life much, much easier. Making them super more productive. But as you do that, think about definitely the security implications of that.
Security needs to be bolted in right from the very beginning, making sure that sensitive data is well protected, making sure that you have zero trust access to these applications. And of course, last but not the least, always be on top of governance and compliance as you build these AI applications and then deploy them within the organization. Wonderful.
Well, thank you so much for coming on our show and sharing your insights with us today. Thank you, Amanda, for having me. And thank you to our audience.
Stay tuned. There's more.