Transcript
We're living in a hybrid world, and we've had a couple of travel complications today, let's say. So, we will have two of our panelists joining us behind me on the screen. Good afternoon, gentlemen. Maybe I'll quickly just introduce everybody. First, we have Ralph Schneider, whose impressive career in IT and cybersecurity spans more than two decades, marked by his long tenure at Allianz, where he served as the group CIO for 13 years. Then we have Stefana Ischia, who's a certified cybersecurity expert and business strategist with extensive experience in global corporations and technology sectors. Eileen Jennings-Brown, joining us in person here today, is an award-winning technology leader with over 25 years of experience driving digital transformation across sectors. And last, but certainly not least, we have SoSafe's chief product officer, Gonzalo Gayolash. All right, so, one final reminder before the break that we will also be using Slido for this session. It should be the same link that you've been using since we have our gentlemen joining us on the screen behind me. But I will start with some questions that we already have teed up. So, first, I will start with you, Eileen. So, what challenges do AI-assisted cyberattacks pose to traditional security measures? Pretty general. Thank you for that question. I am not going to tell anyone in this room anything you do not already know. My first initial answer to this is the speed with which AI can assist in a cyberattack, and then the scale, the breadth of how far that can go. I'm sure everybody already knows this kind of stuff. But that, I'm going to give everyone else an opportunity to answer as well, because there's a lot in there. Gonzalo, anything you'd like to add? Yeah, the first two words that came to mind were absolutely speed and scale. I think it puts our systems in... We did not design controls, learning capabilities to operate at this fast pace and with this reach that we see today. So, that is absolutely the right framing for the challenges. I could not have anything else to add. Eileen, maybe back to you again quickly before I motion to the gentleman joining us remotely. But can you share any specific examples of AI-assisted or social engineering cyberattacks? Thank you again for that question. So, that was going to be the second part of my answer, which is the speed and the scale, but then it's the cost of a cyberattack now is going to be so much more because of the AI assistance. And then social engineering is a big risk. So, yes, I have an experience to share. Without giving too much away, I have experienced an AI-assisted cyberattack where the CEO's voice was cloned and it was used as part of a phishing attack and it started on WhatsApp. But the CEO's voice was cloned and then the attackers were using AI to help them generate answers to whatever questions were being asked as part of this ongoing dialogue. The objective was to steal 300,000 euros. Now, for whatever reason, the person who was the victim of the attack stopped just before they hit the send button on that transaction. So, they had logged into the account. They were very senior members of staff, but they logged into the account, into the bank account. They'd set up the transaction. They'd engaged with lawyers. They'd engaged with the CEO. And all of this conversation had been happening online and with telephone calls. And it was unbelievably convincing. And so, we were able to get involved and we were able to stop this from going any further. But it was unbelievably close. And all of that was assisted with AI. It was scary. Wow. It was really scary, yeah. Really makes it real and shows how fast this stuff is moving. Thank you for sharing that. I will go up to our gentleman joining us remotely. So, Ralf, how is Allianz leveraging AI to anticipate and prepare for the future of cyberattacks? As we see, these are evolving very quickly. Before I answer the question, I'm coming back to the first question. I would say that AI empowers the creativity of human beings exponentially. So, we are getting a totally new creativity booster in attacks. And Allianz was, since years, with our risk model, machine learning was always in our DNA. But with the generative AI, nowadays, all these machine learnings, AI techniques are going around and everybody is affected. Not only the special units, but everybody is affected. And this is different. And what we invested very fast in cyber security, exactly on the other side. But when the offense is using it, I can tell you also the defense can use AI and empower the creativity now of our defense people. Okay, thank you. And, can you hear me? We've lost all mic, I think. Oh, and we're back. You can hear me? Thumbs up? Okay. Apologies for that. So, Stefano, maybe I'll go next to you. How do you prevent potential misuse of AI technologies within your security operations? That's a good topic. Very, very good topic. So, our approach to preventing AI misuse in cyber security operations goes beyond traditional controls. We have developed a comprehensive framework we call AI Security Mesh that operates on five interconnected levels. I explained the first point. It's the intelligent behavior modeling. We can control instead of simple rule-based monitoring we implement. You get an AI-driven behavioral fingerprinting of our security AI systems. You have a dynamic baseline adaptation based on the contextual intelligence. I've got a predictive anomaly detection that identifies potential misuse before it occurs and cross-correlation of AI system behaviors across different security domains. The second point is cognitive security architecture. We developed a unique approach where each AI system operates within a cognitive sandbox with its own behavioral profile. AI decisions are validated through a peer-reviewed system of other AI models. We implement AI consciousness markers that track decisions and make them important with automated ethical compliance verification occurs at each decision point. Third, this is a zero-trust approach or AI framework moving beyond traditional zero-trust where the AI system must continuously validate their own decisions through multiple independent verification layers. We implement first decisions where AI permissions automatically reduce over time. AI systems undergo regular automated ethical audits. We maintain an AI decision accountability chain using blockchain or technology. The third point is a human collaborative oversight rather than simple human supervision because we've developed an innovative four-eyes principle where a critical decision requires both human and AI consensus implementation of AI protocols that makes decision processes transparent. In the fifth position, we need to push an adaptive defense mechanism our system constantly evolves through self-learning security boundaries, AI models, rotation to prevent automated stress testing of AI system and dynamic resource allocation based on risk assessments. Excellent, thank you. And maybe before I bring it back down to the stage, I'll continue with the gentleman on the screen. Ralf, could you tell us how you believe AI and automation can help address the current cybersecurity skills shortage in particular, so how we can use AI to be educating people? Exactly. What I said before, in the digital world and also now all the transactions with AI, we get a lot of data flows. So the transaction and the data flow is huge. How you can there in cybersecurity detect anomalies? Anomalies you can only detect when you are building, like Stefan said, a baseline, but then you need intelligence to identify and prioritize anomalies that you can do such an investigation. And exactly then to your point, how you educate the whole cyber defense, and it's all I call it the human firewall of this conference, to educate the people to raise the bar of signals. It's all the bar of signals. Sometimes a normal employee can identify an attack, sometimes a very advanced detector identifies and it's bringing together to understand what's going on. And you will not detect any more signals which are critical because they are coming more and more sophisticated without tools. So we have to learn to use also AI tools to identify risks. Like fakes or like others. So this combination, human being using the right tools, I call it a little bit to survive in this digital world. Yeah, right, to survive. Yeah, Stefan, anything that you'd like to add to that one? No, no, no. No, thank you. The best thanks. Sure, then I'll bring it back down to the stage. Goncalo, I think this is something that you're doing a lot of work on, how we kind of integrate AI for education purposes. Yeah, for us, when we think about user defensive AI, like we were talking about, you think in big contexts, right? So one of the examples given here was using AI to make sense of incredible amounts of data. This could be what is happening around your organization. Is there a campaign happening against the same industry, the same size of company? And AI facilitates the discovery of these patterns that even well-trained analysts might not make sense. And then when you take that context, you can take it back to the organizational layer. And we do a lot of work in signaling and getting data around what's happening at the organization, what behaviors are being shown, and then making sure that risk profiles are updated in real time through AI. And this could be generative AI, machine learning. The technique in and of itself is not very important, but taking it down to the context and the umbrella of the organization. And then, of course, the individual. We're going to be talking in a few hours of an area that we're all trying to pioneer, which is either sidekicks or co-pilots of somebody, entities, avatars that can be together with you, be a coach, be an assistant, be a participant, be an agent on your behalf. And that is a huge area of progress where if we put our collective efforts together, we can supercharge the individual in their actual response. So we think of it in these three contexts. There are specific use cases in data collection, in risk profiling, and then assisting the individual, being their sidekick, that are incredibly powerful use cases. And I would argue it's where we should put most of our efforts, because it advances the cause of the human, making the human better. Absolutely. Can I just add to that as well? Because I like how you're talking about the adoption of the tools in order to create superhumans. I am from an organization where AI was the business. And so it's actually a slightly different lens on this, where we invent AI to discover drugs. And we use the AI for this whole drug discovery. And what's really important when it comes to the skills and the capability for AI in an AI company for cybersecurity is it needs to be by design. So those engineers that are doing the machine learning, that are creating artificial intelligence, have to do it by design. And so for us, it's about teaching them how to do the recording by design, as opposed to using a tool that enables them to undertake a task. And it's a slightly different lens on that, how we close that skills gap. So it's a real big education piece around how do you do secure engineering. Very interesting. Thank you. And Eileen, the next question I have is also for you. So how should organizations balance financial investments in AI technologies with the long list of other cybersecurity priorities that also cost money? It's brilliant. This marries up really, really well because actually as an AI organization, so there's two sides to it. It's your business is AI, and then you're trying to balance the core business with the cost of cyber and protecting your business. You actually need to protect all your assets. You need to protect your people. And so how do you get that balance of the finances for each? AI is the business, and so there's always this competing demand. And it actually goes back to the point about this is where you invest in the skills and the capability because you are making it secure by design. And that's how you're targeting your finances. But where you're looking at the cost of cyber in your business, the best place to start is small. Do that. You know, we talked earlier about doing a risk assessment. Do a risk assessment. Understand where the greatest risk is. Target the money into that area, but also think about how can you make things secure by design and invest in those that are going to future proof that business. I'm going to have a slightly different answer to the others today. Makes sense. Then I'll jump back up to our gentleman joining us online. Ralph, how do you address concerns or misconceptions about AI within your organization to not get in the way of that security culture and innovation? I'd like to link it with this topic, security by design. I totally buy in and we did it for IT. Security by design is a concept since 15, 20 years. But the real challenge is the design. Sometimes the developers are not convinced or the pressure is so high that they have built the functionality and at the end they check the design. And with AI, the colleague said quite well, it's the business. And now you have to build security as a quality measure in the product, in the business. You have to think the business together with security because sooner or later comes. But there is an additional aspect on top and this is what we are always saying in Allianz, you have to take care. It's like a little bit like a human being. Normally the human being is designed to be I'm totally convinced is designed to be good. But sometimes it becomes evil by the interaction with the world of other people. And you see the same with autonomous AI agents or business model. You have to take care that not only the product or the service is secure but also the influence with the other services which they interact makes them not unsecure. This is a totally new dimension and I would say in this dimension it's not only in a network not only to make the notes secure but also the communication secure. Great, thank you. And then Stefano while we're up there I'll come back to you as well. So we talked about the skills gap in general but what do you believe more specifically are the skills that are going to be so necessary for AI or artificial intelligence? It's a bit of a question for the staff but I guess everybody when it comes to artificial intelligence. You know in today's rapidly involving AI-driven landscape it's very difficult to understand all the things there is many many points there is AI human interaction developing frameworks for AI assisted incident response that maximizes both human intuition and machine efficiency creating adaptive interfaces that evolve through clamshells that might there is a free evolution forecasting beyond traditional free-tensing professionals need to develop you know and all the people must have this predictive modeling skills to anticipate all criminals and might evolve and capability to identify potential blind spots in current AI security systems you know understanding of emerging AI architectures to predict future attack surfaces et cetera et cetera cross-domain intelligence synthesis model and adaptive response orchestration ethical AI security engineer et cetera et cetera and so to prevent this as I told you earlier this is a specific to have intelligent behavior modeling cognitive security architecture zero-trust framework human-AI collaborative oversight and adaptive defense mechanism you know I like to add the most important Stefan I would say is as a skill critical thinking because you cannot anymore trust what you see what you hear and what you interact so critical thinking I would say is the most important skill for the future in this AI power yeah yeah clearly and that's why all the customers all the company all the partner with them working on you know speak about the zero-trust they want to be in a zero-trust position in one or two or three years but I'm thinking about the smaller company you know because it costs so much you know to have a zero-trust policy what is the future for the middle companies that's the question you know because not all the company have the budget of aliens for an example and so because I see the price if I don't want to mention to mention the solutions you know but we have four or five pure player in cyber security you know who can handle the zero-trust in the future but who can pay for all of these topics you know many too low company and not many many company can do that so what is the vision for the smallest company it's interesting if anybody ever announced for this excellent thank you for the opportunity to talk about the inherent skills gap with the proliferation of AI but Gonzalo maybe I think there's also a ways that we can use AI in terms of closing the cyber gap because with our hardware we are still fundamentally lazy beings we want to spend less energy possible so back to the skills gap system design and human design that minimizes the friction so you can pave the path and make sure people do the right behavior so you remove the friction but for us when we think about awareness we think about an opportunity to for people to do the right thing at the right moment so I can prevent behavior and hopefully change in the future. AI is a fundamental design tool to be able to do this. We will talk more about how we do it. We will talk more about how the AI can help people to do the right thing. We are going to talk about this in just a minute. If we can do that, and it's going to take us a while, then it becomes a completely new game. We turn the tables against attackers. Do you find that at odds with talking about zero trust, and yet humans are fundamentally at odds with the first principle of what a human is? Yes, the humans will always be at odds with the first principle of what a human is. I think that's true. It will take thousands of years for our brain to not follow the path of least resistance. Anything that goes against the first principle of nature is inherently flawed. Thank you. One final round of applause for our panelists. Thank you.