Access this podcast to hear experts from Brinqa and CI-Discern highlight how organizations can move beyond identifying vulnerabilities to understanding risk, taking informed action and supporting NERC compliance. Explore how Brinqa and CI-Discern, sold through SCOOP Cyber, turn fragmented exposure data into trusted, AI-guided remediation while securing critical infrastructure and providing defensible reporting for executives, boards and regulators.
[Anthony Jimenez]
Welcome back to Carahcast, the podcast from Carahsoft, a trusted government IT solutions provider. Subscribe to get the latest technology updates in the public sector. I'm Anthony Jimenez, your host from the Carahsoft production team.
On behalf of ScoopCyber, we'd like to welcome you to today's podcast, focused on the new demands of exposure management, building for trusted AI guided action. Jay Klauser, Senior Vice President of Sales Engineering and Alliances, and Greg Sisson, Co-Founder and Chief Operating Officer, will discuss the shift, why VM alone breaks down, what exposure management means now, and the outcomes.
[Steven Cooperman]
Good afternoon, everybody. Before we start, just some thoughts. AI is changing every aspect of our life in a rapid pace I don't think any of us expected.
But with that, it poses an increased threat in our cyber landscape. Adversaries are using advanced AI, and really anybody can, to increase the risk exposure landscape to the point that they can chain together vulnerabilities. And organizations are not only tasked with managing the vulnerabilities they have, they now have a new set of vulnerabilities every day.
So how do we all handle that? Really, the only way to handle that was with a consolidated exposure risk management platform. Tools, processes, governance all around that to protect ourselves from this ever increasing threat that could shut down critical infrastructures, that could shut down our banking systems, that could shut everything down and cause tremendous damage to our way of life, our economy, our warfighters, and everything else.
So today we're here to talk about that, and I've brought together some real industry experts. Joining me today are two executives that come at this from different perspectives, really interesting backgrounds, and I think you'll find their expertise and what they have to say and experience really valuable. So rather than me introduce them, I'd like each of them to introduce themselves.
So Jay, I'll start with you, a little bit about yourself, and Branka in case the audience doesn't know much about.
[Jay Klauser]
Yeah, thanks, Steve. Really appreciate both Scoop Cyber and Carahsoft having us here today. You know, Jay Clauser, I'm SVP of Sales Engineering and Tech Alliances at Brinka.
As far as my background, I come from multiple different disciplines of cyber, starting out in mobile security, then network security, as well as identity and cloud security. And so I think the cool thing about being at Brinka is really bring all of that together and I can leverage that knowledge from those different disciplines at Brinka because at Brinka we are an enterprise-grade exposure management platform. The things you talked about at the lead-in are the problems we're solving for our customers around ingesting, normalizing, correlating, and then applying both business and environmental and threat context to those exposures, really to provide a roadmap of really what should and is introducing the most risk to your environment, and then how do you go out and operationalize and solve that?
[Steven Cooperman]
Perfect. And Greg, you know, incredibly impressive background, but I'll hand it off to you to tell everybody about that.
[Greg Sisson]
Great. Appreciate it. Yeah.
Thanks, Ian, for inviting me. So I'm Greg Sisson. I'm the co-founder and chief operating officer of CI to CERN.
I've led and advised organizations across the government and energy, including leadership roles at the Department of Energy, Department of Defense, and my last role was in Ernst & Young in their energy cybersecurity practice before launching CI to CERN in March of 2024. At CI to CERN, we help organizations with transforming their cybersecurity programs and making sure that they take the resources that they have and use those in a way that reduces the greatest amount of risk. And we do that in multiple ways, but one of the ways that we separate ourselves from others, I believe, is the deep expertise that we bring from the energy industry and the senior leadership that we bring.
We have a number of people that have served as CISOs in the industry, and so they can go right into an organization to either serve as an interim CISO, they can advise the CIO, and they can really bring a lot of credibility when it comes to transforming cybersecurity programs in critical infrastructure.
[Steven Cooperman]
Right. So to kick it off, Jay, you know, we started out talking about this whole landscape has changed, specifically in the offensive side, AI can now fund the new exploits. It's doing this 24 hours a day with billions of entities coming at us.
Why doesn't traditional vulnerability management programs really work anymore? Why do they really need to be enhanced to address the new threats?
[Jay Klauser]
Yeah, I think it's a good point. I mean, certainly vulnerability management programs are very important for, I think, organizations to have that in place as a starting point. But I think you touched on it.
I think what we're seeing here is there needs to be some investment enhancement about how do we approach this new challenge, right? I think, you know, when you look at it, you mentioned a few things. You know, the landscape, it's changed dramatically, you know, but previously, I think that these programs were built for, you know, for lack of a better term, a slower adversary.
You know, threat actors were talented, they had tools, they had things to identify weaknesses, but they weren't able to do it at the scale and with the expediency that AI is clearly able to, you know, to execute at, right, at machine speed. And so, I think it's a compounding issue, right? I mean, first and foremost, we talked about it, there's, you know, already probably more vulnerabilities and exposures than these teams and organizations are able to deal with with the traditional kind of, you know, threat actor capabilities.
When you add AI to that, now we're taking what would be assumed as a vulnerability exploit to be proliferated and out in the wild over maybe days or weeks is now happening in hours, right? So, I think that's the first compounding change in the landscape is with AI assisting these attackers, they are just so much more efficient than they used to be. So, that idea that we have some time in order to get our house in order and go address these vulnerabilities, that's been dramatically shortened.
I think the other thing that's happening is, and we just saw it with, I think, the most recent Microsoft Patch Tuesday, it's like every patch Tuesday, it's a record number of CVEs that they're including in these patches. Well, the reality is these, not only are these AI models able to identify existing vulnerabilities much more quickly, they're also identifying new vulnerabilities in code that weren't, you know, known before. And so, we're compounding it again with the adversary's faster, we now have more vulnerabilities that are adding to our queue that we were already kind of behind.
And then I think, you know, one of the biggest things is these AI models are really, really good at chaining vulnerabilities together and creating an attack chain. And yeah, I think that's a really recent, honestly, just at least within the past week was the example from OpenAI and Hugging Face. When you look at that incident, all three of these compounding factors were a part of that, right?
OpenAI had an advanced model, that advanced model chained multiple different vulnerabilities together to break out of its contained network, so to speak. And at the same time in doing that, it discovered a zero day. So it discovered a brand new vulnerability.
So the point being, I think the landscape has just changed in traditional vulnerability management programs, I think assumed that they had more, they have time to be able to react and mitigate. And I think that's the biggest change specific, and I'd love to get Greg's thoughts on this at some point, specific to critical infrastructure and utilities. There's also a large number of kind of traditional OT devices that probably are less accessible and easy to manage.
And so all of that compounds and it's really kind of put the vulnerability management program under a microscope. Yeah. Interesting and very scary at the same time.
[Steven Cooperman]
So Greg, you're working with major utilities, energy companies, ports across critical infrastructure. Let's shift over and talk a little bit on the defensive side and what people are thinking, what they need to do. I'd be interested, you know, is this at the board level yet where they appreciate how the risk or budgets being allocated, just sort of your viewpoint on all that?
[Greg Sisson]
Yeah. I think it depends. I think we're seeing a little bit of all of that across the board, and it really depends on what kind of utility it is, if it's an investor owned utility, they obviously have a little bit more money if it's a public utility, not as much.
But they're all looking at, you know, how do they use AI to shift a little bit on the defense and improve the defense, right? To try to counter the asymmetry, if you will, of the velocity of which AI has enabled an adversary to be able to do what they were already doing, putting the defenders on their heels. And now that's just, it's just exponentially multiplied.
So I think what they're doing is they're trying to really look at is, I think it's, I think a good term is how do they improve decision velocity, right? Because now that the amount of decisions that have to be made, given the amount of vulnerabilities that are coming in, the amount of tickets, how do they use AI in a way that improves decision velocity? And what I mean by that is, how do we get the right things, the right assets, the right understanding of the risk environment, getting that in front of the right people, and then having that follow the governance process and things like that to improve speed.
So I think really figuring out how to use AI as an enabler for their defenders.
[Steven Cooperman]
So, you know, from an organizational perspective, is there a culture shift? I mean, how does, you know, a program might have been in place for 10 years, same people running it, they think they're successful. Is there a shift in having to train them, change their mindset?
You know, how does the organization embrace this culturally and organizationally?
[Greg Sisson]
Yeah, I think what I would caution organizations is that they don't overreact, right? Because I think there is a tendency with AI and boards is the, you know, what's in the media and about the speed and the velocity and all of these things that the adversary has. I think that organizations still need to pause and really understand, do they have the basics in place?
Do they have the governance and the processes? Do they have an exercise program? Do they have, you know, the ability to do backups and those kinds of things?
Because if they still don't have those basics, then none of that's, none of this is going to matter. They can overreact on AI, they can bring AI tools into their organization, but that could just be a faster way to fail. So I think it is still, take the time to pause and really understand, do you have the basics?
Because the basics are going to be even more important.
[Steven Cooperman]
So this is really at the CIO level, make these fundamental decisions to build the foundation, right? And that's certainly where CI and CERN can help. So what does it mean when it breaks down to the organization?
I mean, do you have any examples or how do they react or what does it mean when they're traditional vulnerability management program breaks down?
[Greg Sisson]
I think when traditional vulnerability management breaks down, I think it goes back to, you know, everybody's going to ask, you know, why? And again, it's going to be about, are you going to be able to defend the actions that you took? Are you going to be able to defend, you know, around, did we have the right data?
Did we have the right assets? Did we have them prioritized in the right way to be able to put the right teams in place to respond? I mean, it's, so again, it really just goes back to those basic processes in governance.
And that's where, you know, something like Brinca that brings in governance and those kinds of things into the platform, as opposed to just understanding critical vulnerabilities, it goes beyond that to help really the speed at which you can now manage this high number of vulnerabilities in your organization.
[Jay Klauser]
Yeah. I think you touched on some really key points there, Greg. Two, a couple of words you used.
One, data foundation is absolute. You have to start with a strong data foundation, right? For any, whether it's, you know, leveraging AI or not, you cannot make defendable decisions is the other term you use there.
You know, in the end, you're going to have to defend the decisions of why did we focus on, you know, this exposure, vulnerability, protecting this, you know, asset over another. And it starts with strong data to then defend, to decide on the actions and those actions need to be defensible. And I think that's one thing I'm seeing with, you know, the adoption of AI is, you know, it's, there's some, I think for good reason, you know, everybody wants to leverage it.
And I think we're going to need to leverage it to defend against the threat actors out there because they're leveraging it. But it's a little bit of a different animal when you're trying to defend with AI. It's not about just throwing AI at a problem and hoping it solves it, right?
It's about leveraging that strong data foundation to, in leveraging AI to provide the roadmap and the actions to take that are defensible, that you can go as a CISO to your board and say, hey, you know what? This is what the data told us. Here's why.
And here's what it does. Otherwise, you know, and, you know, it's kind of like the old bad data in, bad data out type of.
[Steven Cooperman]
So when you're working and you work with a lot of different organizations, you know, what would you say their average or where are they in this maturity curve? Do you think people are, you know, is it a long way to go or is it a big disparity between what you see or where do you think most people are starting this journey?
[Greg Sisson]
Yeah, it really depends. I think that with, over the last several years, I think, I think vulnerability management, there's at least a program in place. There's very, very, very few organizations that aren't at least looking at vulnerability management, putting good governance in place.
They have some kind of a tool typically that will help them to do vulnerability management. So there is something in place. It's whether or not they have taken it to the next level to really understand and prioritize their assets in a way to where now you can take all that information that's coming into your vulnerability management program and apply it in a way that really looks at it from a risk perspective.
Are you, you know, are you just patching, you know, patching all your criticals and reporting metrics for, yes, I've patched 90% of criticals, 30% of moderate and none of low, right? It's really about, I have a low vulnerability on a critical asset that could be exploitable because of the way it's configured in this environment. So I've addressed that low vulnerability because it's, it's a critical risk issue, right?
And it's a, it's a risk to the business operations. That's, that's when you know, you've graduated from just a strict vulnerability management program and addressing, you know, critical, moderate, low vulnerabilities to really understanding where those vulnerabilities are, what assets they could affect, are they exploitable? And you can really start to talk about that in a way that it makes sense to the business in terms of the impact on business.
And so that's where I think.
[Steven Cooperman]
Yeah, perfect. So Jay, we keep, you know, talking about traditional vulnerability management and now really the nomenclature has turned into exposure management. Yep.
Which seems like a broader view of it just for the audience. Kind of, what is that shift and why is it needed? And, you know, if you want to touch on what Brink is doing about that, that'd be great.
[Jay Klauser]
Yeah. I mean, I think, you know, what Greg just said is a great lead into that. And, you know, Brink has been for a long time, have been tackling that initial problem you just mentioned of, you know, we need to apply context, both business, environmental to, you know, for that great example at the end, right?
A low vulnerability could be in our, in particular environment as, you know, important or introduce as much risk as a critical vulnerability sitting on an internal system that's in a segmented network. You know, let's go, let's go address that low vulnerability that's externally exposed and exploitable, right? Like that's the, that's the basis of a, I think a, a mature risk-based vulnerability management program.
But now we're starting to see kind of, as you mentioned is, you know, what is exposure management? I mean, exposure management really is, you know, leveling that up to saying, not only do we need to think about, you know, the vulnerabilities, but how do other, you know, areas of risk and exposure in our environment correlate? And I think this is where the exposure management comes in is how do I start to take into account misconfigurations on a particular, you know, system?
You know, maybe, you know, MFA got turned off on a system inadvertently, you know, that's not necessarily CVE-based vulnerability, but it introduces risk. And now if I can correlate that misconfiguration with a low-level vulnerability sitting on a, on a critical asset, that, that correlation together starts to drive even more refined, you know, exposure and risk assessment, right? Or, you know, I have exposed identity secrets, I've exposed secrets on a, a, a GitHub repo, you know, and, and that actually is part of a, a business critical, you know, application.
So exposure management really takes into account, not just kind of vulnerabilities that we kind of, you know, love and know from, you know, CVE scoring, but it starts to layer in broader exposures across my environment. And this is where I think we're seeing AI be such an accelerator to, because that's not easy to do. It's not easy to, you know, start to correlate these things and understand, you know, how does everything chain and act together, right?
It's not a, you know, vulnerability management kind of took a singular view of a vulnerability, then obviously have some great prioritization around, you know, if we can layer in that context. Now, exposure management is really looking at the broader sense of, you know, how are we going to be and what could lead to an exposure? How do these things link together?
Looking at exploitability, blast radius of a potential exposure, you know, identity risk on an exposure. And then also kind of looking at it and saying, you know, the view of, and again, this is where that strong data foundation, if you're going to leverage AI to do this, like we're doing in Brinca is, you know, how do I start to look at where and what actions can I take to have the most impact on reducing risk in my environment, right? Good example would be if I have an asset, you know, that is, you know, exploitable, it's externally exposed, but it has, is on the same network as three or four, you know, crown jewels, even though it might be a dev or a low level asset, that blast radius is much larger.
So I can start to, it's really about looking at an extended view of exposure in your environment, far beyond kind of looking at it at an individual CVE level and assessing it from that standpoint.
[Greg Sisson]
I really like that because I, and you know, before I really started this discussion with Brinca and, and Scoop several months ago, I really hadn't thought about the differences between exposure management and vulnerability management a lot. You just, just hadn't really come up as a, as a, as a term. But what I really like about exposure management and the way that you're forced to look at it is looking at it from consequences, right?
It's really trying to understand consequences, not it's, it's getting away kind of like what we, you know, looked at heat maps years ago. It's, you know, the, the, the, the critical moderate low, you'll get out of that mindset and really look at what are the consequences of something like this and the being able to use AI to really understand what the real environment, what the whole environment looks like, because when you're doing vulnerability management, you're, you're running on a lot of assumptions, right? You're assuming that that firewall is still configured the way it was the last time you looked at it.
You're assuming that those sysadmins logged out. You're assuming that that person that was given elevated rights, that stuff timed out and was gone back. But using exposure management and using AI, you're getting real time updates on what those real conditions are.
And you're really able to understand consequences based on the conditions right now.
[Jay Klauser]
Yeah. I think that's a good point. You're right.
It's not, you know, it's very dynamic. That's exactly it. As you know, in brain guys, we're ingesting these feeds from the different tools, the, you know, the different solutions that are both scanning in, you know, and defending against this.
You're exactly right, Greg. It's a good point I didn't bring up is this stuff changes continuously. And so that, that risk associated with a certain exposure vulnerability may change day to day.
[Greg Sisson]
Now, minute to minute.
[Jay Klauser]
Exactly. Yeah. And as a team, and when I'm asking my remediation teams to go out and spend their precious resources to go fix something, I have to be able to defend that decision.
I have to be able to clearly communicate why we are prioritizing this exposure over another one. And as you said, we have to defend that decision to, you know, the board, you know, or to the leadership in that organization.
[Steven Cooperman]
So I'm going to get back to you in a second to talk about a real world example, but something we didn't cover, Greg is, you know, what we're hearing a lot is OT, IOT systems, the vulnerabilities are in HVAC systems and the cameras. How do you think this AI, you know, and exploiting firmware? I mean, everything is from the physical building.
And you look at a data center, somebody gets in, you're in big trouble and they can't get in from other exploits, right? So what are you hearing and what are you thinking about in the whole? And obviously Brinker can adjust really, a threat is a threat.
So we talk about exposure management. We have the physical plant as well, and especially in critical infrastructure.
[Greg Sisson]
Yeah, I think it's really understanding your assets and not limiting your scope when you start to look at assets. I mean, data is an asset, anything that has an IP address is an asset that has to be looked at when it comes to exposure management and vulnerability management. So I think, and that's why a lot of organizations, you know, they typically have put cyber under a CSO, under a security officer, because they understand that physical and cyber, they understand that all of that stuff now is, has an IP address, can get out to the web, is accessible via the internet.
So having somebody that oversees all of that space and then not limiting your vulnerability management program to just your traditional business networks, understanding how you do that with including cameras, I mean, soda machines, everything that has an IP address that could serve as an attack vector into your environment and understanding how to use that and understanding that attack surface and applying vulnerability management. The operational technology is a completely different story.
I think that's, you know, that's traditionally been segmented off, but even that has undergone extensive digitization now. And so really understanding, going away from the hard lines of what we can and can't do in the OT environment to coming up with ways that we can do better, quicker, faster vulnerability management in those spaces. But again, it all comes back to the, you know, understanding how those devices can be exploited.
What is their exploitability? How have they been fenced off? What controls are in place?
Are those controls effective? And so it really is, there's, it really can't be a stovepipe anymore. Right.
[Steven Cooperman]
It's your complete exposure in every regard. Yeah. So Jay, to give the audience, you know, a real world example, you know, talk about a case example, what Brinca did and sort of how this actually works in a practical sense.
[Jay Klauser]
Yeah. I mean, I think, you know, when you look at Brinca, as I mentioned, I mean, we are really experts at, you know, bringing in and really, you know, correlating this exposure and vulnerability data, you know, across a complex organizations and, you know, utility and critical infrastructure organizations are probably the definition of that. I would say, you know, very large, complex, highly regulated data sets.
Good example is we were working with a gas and electric organization. You know, they had some interesting, you know, requirements, both around regulations. Certainly they had a gas division and electric division, of course, who kind of were in siloed, both siloed from a technology perspective, as well as from an operations perspective.
And so as an organization, it was really challenging to get a singular view of, you know, the risk and exposure of their environment at any given time. I think to complicate things, they also had several regulations. In this case, they had NERC guideline and NERC regulations that, you know, they needed to ensure for audit purposes that anybody that was able to see the NERC, you know, managed devices had that certification.
And so it was a challenge, and they had a big challenge in, you know, being able to be efficient and effective in their programs because they didn't have a way to bring that data together and act on it and measure it. And so in BRINCA, we leveraged that. We brought everything in just to kind of, you know, bring, shorten up the program, but they brought it all in.
And because of those controls, you know, they were able to unify the data for the broader exposure management team and vulnerability management team. So they could report, they could have confidence in the data. But with the data controls, they were able to align with and comply with the regulations in place where, you know, they still had it segmented from an RBAC perspective.
The gas team, right, could only see the vulnerabilities and exposures related to their assets. The electricity team or electric team could only see theirs. And then to make that more challenging and more, you know, interesting is they were able to bring in the certification human side of it to say, hey, we need to know if Greg or Steve are NERC certified.
If they are, then it opened up a greater set of data for them to see. So, you know, it served a few purposes. It allowed them, one, to be much more efficient with, you know, not chasing down who the owners of a particular asset might be because they automated that capability as well.
But more importantly for them, they had a single source of truth for exposures and vulnerabilities in their environment. But they were able to keep the experience and the data clean for those different groups so that they could both measure and act on that data with speed. And I think you mentioned, you know, back to kind of exposure management, a part we didn't really talk about that was part of this, you know, outcome as well is, you know, it's great that we can correlate and we can assess the risk, but I think the ability to act is actually where, you know, a lot of organizations get stuck.
And so in this organization, it was also that ability to act. So having those owners of the assets, of the exposures mapped out on tap, available when needed, really allowed them to act quickly rather than spending time trying to manually add and update spreadsheets around who owned what asset, right? With Brinca, it's about leveraging the data sets to automate all of these actions and all of these, you know, ownership attribution and the prioritization.
If that's all automated, you can really focus on, you know, getting value and moving your program forward. And that was the outcome of that customer is, you know, instead of spending and having the resources spend all this time manually, you know, doing correlation and prioritization and ownership attribution, they actually started, they implemented with those resources, a threat hunting capability and an application, you know, security management capability. So for them, it wasn't about, you know, cutting resources from the team.
It was about freeing up that team to go work on more important and valuable things to the organization and allow Brinca to automate the process for them. And I think, you know, that's ultimately, I think the outcome that we've achieved with most every one of our customers who really, you know, implement the platform.
[Steven Cooperman]
Yeah. So the time to risk mitigation is quick. Greg, you know, I think the audience is probably gonna be made up of everything from CISOs, CEOs, technical folks.
But we got a call after this from a CISO of a major utility or a CEO or the head of a government agency and says, Greg and Jay, how do I get, you know, really intriguing what you said. Like you said earlier, Greg, I never thought of it from an exposure management. I got this team.
I fund them every year. I thought everything's okay. You guys really enlightened me.
I'm a little nervous. Where do I start? Who do I hand this off to?
Do I hire an AI, VP of AI? You know, I don't want to offend my existing vulnerability that they're not doing. You know, that's always a danger.
So help me figure out where do I need additional funding? Can I cut costs from elsewhere? You know, give me an idea what this means to me so we can start talking about the board level and getting a plan.
[Greg Sisson]
Absolutely. And before I answer that, if you don't mind, I want to go back to something that Jay said, because the fact that you guys were able to go into a utility and do what you've been able to do says a lot about what Brinca has done from a security control standpoint, because that's a tough environment. And to be able to bring in something like Brinca says a lot about what you guys have done around security controls and those kinds of things to build that kind of trust.
Because that's the biggest thing, as you know, having worked with utilities, is that especially ones that are NERC SIP regulated, because there's tremendous fines associated with that. If they don't do that right, if they mess up how they access data, how they store data, who they allow access to that data. So I hope the audience will realize what Brinca had to have done from a security standpoint to be able to get to where they've gotten in that utility.
[Jay Klauser]
So yeah, I appreciate that perspective. We know what we can do from a technology perspective, but that insight of the why, right, what's the business reason that that was so important to them, clearly, as you mentioned, it's regulated, it's fines, it's a challenging problem. And yeah, I appreciate that.
Yeah, incredible technology.
[Greg Sisson]
And then, so back to your question, Steve, I think the biggest thing is just pause. Organization, I think some organizations are tending to overreact with AI. They're getting a lot of questions.
Board members will read certain articles. They'll read things in the media. And if they don't really understand it, then they're going to demand action.
And I think it's incumbent upon CIOs and CISOs to really understand what the impact is on their organization, what is the right level of AI to introduce into their organization, making sure that when AI is introduced into their organization, it's done in a responsible and secure way so that it does enable business functions that it's really good at enabling, but also do it in a way that enables the security of the organization. And don't overreact in terms of trying to scale back people.
I think that's a lot of, we're seeing that a lot is people think they're going to be able to eliminate certain layers in their security operations center. We're going to be able to get rid of all of our tier one, possibly all of our tier two analysts. When the stuff that we're talking about, especially with Brinca, Brinca works really well when it's laid up on top of a solid groundwork of good governance and good policies and exercises and understanding where all your data is, understanding where your critical assets are.
And all of that stuff is just basic blocking and tackling of cybersecurity. And so that's why I think organizations just need to kind of take a pause, really understand where things like Brinca and other AI enabled tools are going to be able to enable them, but don't overreact and just be prepared to answer the questions from the board as they come in, but just really caution against overreaction.
[Jay Klauser]
Yeah. And I would just say, and I mean, to Greg, your point, I think clearly there's a need and a desire to leverage AI. But what I'm seeing from the organizations we're working with, there's also clearly a need to put guardrails in place for AI.
I haven't seen, I think everybody, like you said, there's this pressure to leverage it. But I think in your terms, I think there is this pause to say, okay, we need to leverage it, but we need guardrails in place. I think, and it's back to that, you need to be able to, if you're going to implement a solution that leverages AI, you need to be comfortable with it.
And you need to, if you're going to rely on it, you need to be able to defend the decisions and the actions it's taking. And I think at least at Brinco, we're looking at and taking that very seriously where we are, and I think there's a demand for putting the guardrails in place and understanding and having the controls in place from the organization to say, what do I want to let AI work autonomously on? And what do I want to, where do I want to set the limits?
And so it really is important to, I think it's paramount that we leverage it because the ability to provide and evaluate data at scale is so much, it's tremendous. And so it's a great advantage, but it all starts with the data. If you don't have good data to start with, then the AI is not going to produce good results.
You know, it was like a simple example of, we all have been using chat GPT for years, right? If I go tell, you know, chat GPT, you know, go write me a paper on X, and that's my only prompt. It's probably not going to give me a very good paper.
But if I say, hey, go write me a paper on a certain subject, here's the tone I want it to be. Here's, you know, some areas I want you to call out. You give it the data and the instructions, and that's the data foundation.
You're going to have much better results.
[Greg Sisson]
And you can't do that without having, kind of goes back to our earlier discussion, the earlier point. You can't do that without having good tier two, tier three analysts in the security operations center that understand the risk appetite. They understand the data.
You don't, you can't write prompts if you really don't understand the organization and the risk appetite and the assets.
[Steven Cooperman]
Yep, exactly. So I think, you know, what I'm getting out of this conversation is, you know, the threat is real. It's accelerating.
But, you know, don't freak out right now. Take a step back. Make sure your organization is ready from an organizational structure, from a governance.
Take a look at your data because you don't have the right foundational stuff, no matter what you apply to it.
[Anthony Jimenez]
Thanks for listening. And thank you to our guests, Jay Klauser and Greg Sisson. Don't forget to like, comment, and subscribe to Carahcast.
And be sure to listen to our other discussions. If you'd like more information on how Scoop Cyber can assist your organization, please visit www.carasoft.com or email us. Thank you again and have a nice day.