Caffeinated Risk

Designing AI Enabled Security Products with Rachelle Loyear

McCreight & Leece Season 6 Episode 5

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 7:17

Our inaugural podcast guest and friend of the show Rachelle Loyear has recently released her third book, "Enterprise Security Risk Management (ESRM) in the Real World".  We are adding to the Caffeinated Risk summer reading list and marking the occasion with some additional content from the May 2023 episode . Despite being more than two years prior to the recent OpenAI Hugging Face incident,  Rachelle's frank discussion about both the potential and the risks associated with AI agency are a cautionary tale for all risk professionals implementing or assessing AI security solutions.

Doug Leece

Yeah, watching at 2 o'clock in the morning is a good idea. And 2 o'clock's different in every part of the world. What is lost when we have somebody remote? As you said, there's a place for local visibility. Some of that's pretty obvious, but if we were to look at the data piece, what's lost when you're looking at this data halfway around the world versus looking at it on a screen in the same city? Is there something to be said for that? Or it doesn't make a lot of difference.

Rachelle Loyear

I think if you are talking about data and cyber, I think that is that is the place where you are differentiated in the physical slash cyberspace because cyber the cyber environment is a global environment. My window into data is always the same, no matter where my window is. And I'm gonna say that about and and this is I'm gonna differentiate differentiate between data and information because data is ones and zeros, bits and bytes, yeses, no's scores. Information is what I've done with that data. And sometimes I think that having the I had to walk down the street to get to the location where I'm sitting in front of the data window can in fact inform the information that comes out. So if I am in New York City and I'm trying to just get a data picture about Kuala Lumpur, my data may be the same. I see, oh, I see this trend and this trend and this trend. But my information, if I was walking to my office in Kuala Lumpur every day, might be different. And that's why in this kind of plays in very well again with not to plug my risk-free safety product, but to risk really the system brings in the data. So there's a there's a number of the questions that are preset when you open the questionnaire because I'm trying to save time. And I want the people to not have to do a lot of research into crime stats, that they don't need to go look at this or that. However, the last step of this is person who sits there, I need you to go through this and tell me where the data is not aligned with your experience of walking from the parking lot to the building. And that is the last step of it, and that's where we bring the human factor back in. I can do a lot with data. And if I don't have a human, I can run the model and it's probably right. But if I have a human, that probably goes up. Right. That probably goes up to probably definite, as much as you can get definite and predictive stuff, because you know it's all it's all there. But that last step when I want to bring somebody who knows the site in to answer, to just tweak the questions. That's where we are today because I don't, AI is just not there yet. Data is not a replacement for experience, it is an assist to experience. Technology is an assist to the people. I used to, and I will admit, I used to think robots could do security. And over time, over the last decade, I'm like, wow, you can never get rid of the human aspect of this. You cannot take the subject matter expert out of the live. You cannot take that last dual key out. Not yet.

Tim McCreight

No, I I agree. And I think we can do everything we can to make the life of an analyst or uh a risk specialist easier by I'm gonna formulate the questions, I'm gonna standardize the response, I'm gonna provide a data lake to store the information, and then I'm gonna take the data, turn it into information, I'm gonna make some decisions on the information. But in our in our world, right, um, what I found with data that is being collected and information we interpret is the human provides a couple of things that uh AI can't yet is motivation, right? And and and the human reasoning behind conducting that theft, that crime, that fraud, that attack, that DDoS event, etc. And it it's hard to explain a financial, a political revenge motive to an engine to determine that how do I now rate your ability to be targeted, and is the target gonna be like are you as a target gonna be successfully breached or attacked, etc.?

Rachelle Loyear

Yeah.

Tim McCreight

What I'm finding is that it's if we can get to the you know, if we can make the collection of the data into information, the the consistency across whether you're in Kuala Lumpur or New York, but I have a same data set pattern that I can review. So as a specialist or an analyst or someone well-versed in risk, I can look at the different factors, and then I can look at the political climate in one versus another, the economic and financial one versus the other, life, you know, the the cost of living, the ability to live, etc. All of those things then now into add to my experience for motivation, opportunity, right? Can I exploit it?

Rachelle Loyear

Yeah.

Tim McCreight

That that's the additional thing that we also bring to the table that we're not yet there with artificial intelligence is the the potential motivation, right?

Rachelle Loyear

Yeah, and I think that that is as much as I have this vision, um, what we are doing today with these tools is very much along those lines. Um, the the risk team that is using the platform is doing so to bring consistency to the conversation, to bring speed to the conversation, to ease the life of the analysts, to take the boring part away when I am a person who has to do these things. Um, and to bring a little information that, oh, I don't know who to call about that, then I've got to call my friend, I gotta blah, blah. That's what we're doing with it today. We are, as an industry, I think, on the cusp of amazing things. And I'm excited that we're starting down the path. I'm very positive about where this beginning usage of making life easier is going to take us as to bring the board, trust the systems more and more. And we become better at knowing where humans fit into the picture. Uh, it's just gonna be an exciting new world. Didn't want to use the word brave because that was like a way back.

Tim McCreight

Yeah, wait a second.

Rachelle Loyear

Not throwing any hugs flee references yet.

Tim McCreight

We have used that one already.