enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Director of Cyber Security Operations at Putnam Investments

AI and Cybersecurity A Practitioner's Perspective

Felix Kyei Asare, Director of Cyber Security Operations at Putnam Investments

Artificial intelligence (AI) has transcended from being a mere buzzword to becoming the talk of the global tech village. For some, it sparks concerns over job displacement, and for others, it fuels apprehension about its control over our world - ideas perhaps fueled by fictional narratives. From a corporate standpoint, fears about potential breaches of confidentiality, loss of intellectual property, and insufficient controls around data use have caused some enterprises to resist integrating AI technologies, like generative AI, into their workplaces. Today, however, I'm here to not only dispel these misconceptions but shed light on the untapped potential of AI in fortifying cyber security infrastructures.

For those unfamiliar with the term, 'generative AI' refers to large language models capable of analyzing data in various ways and generating responses that mimic human interaction.

Reflecting on my early career as a cyber security engineer, the burden of combing through numerous dashboards, interpreting complex scenarios, and deducing potential threats was significant. The challenge of managing an ever-increasing array of dashboards and metrics only amplified as I moved into leadership.

As a leader in the cybersecurity space, the three most important elements for me daily are enhanced visibility, robust governance, and efficient incident response. The question is how can AI enable me to ensure visibility, robust governance, and efficient incident response across all my workstations, servers, physical data centers and cloud environment, etc.? What would it feel like if I had a tool that would tell me my daily high alerts, employee engagement, how my teams are spending time, what contracts are coming due, who is going to be on vacation, what vulnerabilities I'm more susceptible top and what my daily risk ratings are alongside that of the third parties are manage if they've been involved in a cyber breach that's hit the news? All on a single screen, with glaring red alerts rated according to their order of magnitude. The solution? An AI-powered tool that offers comprehensive visibility of high alerts, employee engagement, contract deadlines, team availability, vulnerability profiles, and daily risk ratings, all prioritized according to their respective significance.

Enhanced Visibility

AI’s capability to recognize patterns, when combined with Security Orchestration, Automation, and Response (SOAR) solutions, leads to transformative outcomes. AI can automate the process of tracking assets, monitoring network activities, and identifying potential vulnerabilities. This leads to early threat detection and proactive response. The integration of all security tools under one umbrella offers a singular, clear view of the cyber landscape.

“Choosing The Right Tool Is Similar To Fitting A Puzzle Piece In Its Perfect Slot. The Size Of Your Internal Team, Risk Appetite, Budget, And Organizational Needs Determine This Choice”

Robust Governance

AI can be a significant catalyst in IT governance. AI can optimize resource allocation, ensure regulatory compliance, and balance IT investments, leading to more efficient and effective IT operations. Utilizing AI-infused tools such as Viva Insights, IT departments can proactively monitor for deviations from set policies and regulations, ensuring robust governance.

Increased Incident Response Efficiency

AI-powered incident responses have proven their mettle in mitigating threats effectively. An AI tool can oversee your platforms, correlate incidents, overlay intelligence, and recommend remedial actions. With AI, you can expect streamlined communication and improved incident response timelines.

The pathway to integrating AI into your cybersecurity strategy is straightforward. Begin by acquiring and preparing your data, then train your model using industry-specific data, such as Bloomberg's GPT model for financial data. Testing and continuous improvement through data enrichment ensure your model remains effective and up to date.

A User-friendly design is crucial for adoption. For example, it took Facebook 4.5 years and Instagram 2.5 years to reach 100 million users. However, ChatGPT hit 100 million users in just 60 days by nailing the user experience. It's crucial to acknowledge that concerns about data protection are valid. If data security is a significant concern, consider building an in-house AI shop. To create an in-house AI shop, don't simply block users at work from using Generative AI; take the following steps to protect your data:

If guarding your data is the concern, then build your own Ai shop with maximum steps to protect your Data:

• Build a Sandbox 

• Open Access to only Internal IPs

• Turn Off Content Logging

• Create Endpoints that go through your content filters 

• Ensure TLS / SSL Decryption is Enabled

• Have a robust IAM system in place

• Have DLP in place 

In conclusion, AI can substantially enhance visibility, governance, and incident response in cybersecurity. By identifying patterns quickly, reducing incident response timelines, and optimizing resource allocation, AI proves to be a game-changer. As a CISO or a CIO, embracing AI as an integral part of your cybersecurity strategy is a forward-thinking move, and I highly encourage it. With AI tools, you can even add a bit of fun to your security measures by generating the voice of your favorite celebrity to read out your daily alerts.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.