Hello everyone, hello Berlin and hello EIC and all my friends. This has been a journey for me that for many years coming to EIC for such a long time that I get to be on this stage sharing my experience and knowledge with you and it's an honor to be here. So I'm going to take you through a bit of a journey. Today we're going to be talking about AI versus AI, the good versus evil, the superheroes versus the villains. So I'm going to take you through a bit of a journey first of all about what's causing the acceleration of AI, what's fueling it.
I'm also going to be talking about some of my personal experiences about how I view and see AI. I've been using different versions and models for many many years. Interestingly some of my first interactions were back in the 90s. I'll share some of those insights.
I'm also going to be sharing with you about how attackers, some of the areas where I'm seeing in the real world scenario about cyber attacks that are using AI to be weaponized and sometimes we hear a lot of FUD and a lot of fear but I'm going to be sharing with you my personal experiences where I've seen it being used in reality and also going to be sharing where I've seen it being used for good in the defender side. So are we ready to take you through the journey? I also got a bit of a quiz. Most of this presentation was created by me, the human.
A few slides were created by AI so I'm going to give you a quiz to see if you can select which ones were created. Come to me afterwards and I'll share a drink with you after that. So the first thing is what's causing this acceleration? One of the main areas is the complexity crisis. We're in a world of complexity. I remember years ago when I started my career back in 1993. I know you're going this guy's looking so young, how could he be that old? But it is quite true. I've been around for a long time. I've been in this industry now for more than 30 years. When I think about that, it's crazy.
But back in 1993 that was kind of where I started and security and identity was a key to the door where the computer terminal was, where the main frame, McDonnell Douglas Dom terminals, you can elect it, you have a username, sometimes a password and sometimes not. Things were way much simpler and then through the 90s got much more complex. We had basically virtual systems, we had edge devices, computers, different mainframes and then we got into the actually 2000s that got even more complex.
We started having distributed computing, data centers, then we moved to bring your own device, bring your own office, bring your own identity and today it's now bring your own agent. Imagine that the world where you know it's no longer going to be about what certifications you bring to the job, it's going to be about what agentic agents you will bring to the job. What other skills do you bring beyond yourself? I remember I get asked a lot of times, how can I do what I do? We need clones of me. The agentic AI is going to be my clone. I will be bringing multiple versions of me to the workplace.
So complexity is getting so much kind of difficult. We're seeing thousands of cyberattacks, every organization is getting tens of thousands of events and attacks per day. In the last year alone, even the actually vulnerabilities increased by over 100%. We can't keep up as humans. We have to find ways to be more efficient and this is where AI comes into it. This is where AI can help us and I'm going to share some of my insights into that today. But we are living in a complexity crisis and the only way we can solve this is with AI and we have to use it wisely and with responsibility.
But the threats are also increasing. Attackers are weaponizing AI. Imagine thinking about where basically phishing campaigns today are being crafted so well that it's getting very difficult even for security professionals to tell the difference between an authentic and actually a malicious email or a malicious message depending on what media it comes to you from. We're no longer living in the battle between hackers versus defenders and security professionals.
We're living in the world of AI algorithms versus AI algorithms and it's becoming much more automated and much more autonomous than ever before. So when we go through this, the threats are getting real and I'm going to share a little bit about some of the real threats that I've seen and hopefully it'll educate you on what attackers are using in this area today.
Now, we have to face the elephant in the room. The AI everything. AI-powered coffee machines, AI-powered vacuum cleaners, cars, watches, phones. I was at RSA last week and there wasn't the booth that didn't have AI on it. We have AI everything.
Now, what's missing a lot of times is context. It's really important to understand context. Just because it says AI on it, we have to understand about what problem is it actually solving. How is it making your life better? How is it making the organization more efficient, more effective? So we get into it's AI doesn't mean anything unless you really get down to the context and the efficiency it's providing to the organization or to the person.
We actually have a better sometimes where we're using AI, we're seeing the efficiency, but we're seeing actually ineffectiveness of employees decrease exacerbately, really significant. So when we think about it, when I look at AI, I started thinking about some of the areas about what do I see AI as? What's my interpretation? How can I share that with you? And I thought the best term I've heard recently about the really best understanding of AI was actually, sometimes you think of it, it's almost like a fuel, it's an accelerant. When you add AI to something, it makes it go faster and quicker.
And I was thinking about in my experience, what does that look like? And I started thinking about Super Mario Kart. I bet I'm the first person on stage to share Super Mario Brothers and Super Mario Kart. But when you think about it, AI isn't replacing us, it's making us super humans. So you have to think about it differently. It's a superpower. And you can use that superpower for good or for bad.
Now, when you think about Super Mario Kart, you might be thinking about, well, what am I talking about? How does it make you a superpower?
Well, AI is like the mushroom in Super Mario Kart. When you get that mushroom, it makes you go faster, makes you go quicker, makes you be stronger. Doesn't make you better. And I can prove that. Here's me playing Super Mario Kart. You can see I'm going around, I get the mushroom. I go really fast, I'm all over the place, I'm not really that good, and eventually I get wiped out. That's what AI is like. So it really means we have to start thinking about how can we make sure we are being efficient as possible, that we're being effective, that we actually have it being used for good.
Just because we have it doesn't necessarily mean we should use it. So it's really important to use it in the right context.
Now, again, as I mentioned, AI can be used for both good and evil. In the good areas, I've seen it being used in the last couple of years, I've seen AI being used more in defensive. In the attack scenarios, I've seen it seldomly used in certain areas. I've seen a lot of buzz and a lot of hype in academic scenarios and research. In the good areas, I've seen it accelerate. I've seen AI being used to basically automate documentation. Thousands of pages of documentation now becomes interactive.
I can take that documentation, query it, and get it to actually create an installation for me to deploy solutions and systems. I can get it to basically automate my configurations of my environment to go and choose where to deploy multi-factor authentication to, where to do entitlements, how to do governance.
Actually, I've been seeing it used in SOC analysts. It also means that I no longer have to be skilled in every single area. I now have my AI assistants that become, for example, my identity specialist is my AI assistant, my PAM specialist, my SOC specialist. Now I have different agents which augments my intelligence in order for me to actually work better and more efficiently. So in the AI for good, I've seen it used in a lot of areas that, again, helps us accelerate, move faster, analyze those thousands of logs and thousands of events that organizations get every day in different scenarios.
So it's really important to make sure we understand about how we can add that value. But in the evil side, I've seen it being used more and more in the past year. The first time I started seeing attackers using AI was around basically language translation. So I'm based in Estonia. In Estonia, we've got a very complicated language, which I'm still not very good at because I'm not Estonian. But it's a very complicated language, 14 cases, no future, no gender. So you can think about complication. But with the language, it's protected the country for many years.
Because for attackers, it was always very difficult for them to translate it. Sometimes doing systematic translation was very bad. So if you're an Estonian citizen, you could easily identify malicious emails and content. It was so easy. The only times it would be successful is if they paid somebody to properly translate it and be able to make it much more authentic. So looking for those local language people who are able to translate it. So it becomes very cost inefficient for the attackers. In the past year, that protection's gone.
With GPT and language translations, the phishing campaigns that I've seen that have been targeting Estonia is now so perfect in grammar, in detail, and accuracy, and urgency, that is so difficult. It is actually better than some people actually get educated in the actual language itself, like myself. So we're seeing basically language is no longer protection for countries. And artificial intelligence has made that possible. AI has also lowered the bar for attackers. It means that attackers don't need to be so sophisticated, so skilled.
They can actually simply go and get it as a service, where they actually make sure all the simple, basically attacker or cyber criminal needs today is a simple cheap computer and an internet connection, and they're off to basically being a cyber criminal. It has set the bar so low that it's actually very, very easy for attackers to basically get into the world of cyber crime. The other area I've seen that's been heavily used as well is actually in data exfiltration.
When attackers get access, and that's where we saw data exfiltration and extortion become the number one attack preference in the past year. Ransomware was up there very high, but extortion can accelerate because the attackers want it to be easier to just keep that quiet, to keep extortion much more quieter, but also it's easier to get paid out when it's quiet.
But what happened was, is that as those attackers are exfiltrating the data, where it used to take them months to analyze, used to take them a lot of time to find out where all that sensitive information is, where's the financial information, where's the intellectual property, where's the credentials, where's the IP addresses, where's that sensitive information, that terabytes they may have stolen. Now, today, they simply take that dump of data, put it through a GPG engine, and they can query it. Where's all the credentials?
And now, rather than taking months to do it, they're doing it in seconds. They're able to then go back to those victims and demand ransoms more according to the data they've stolen. And this is where we're in this race against time, the acceleration.
So, I've seen AI being used in the data exfiltration and analyzing data. Now, interestingly, the next time that I actually interacted AI was actually, I was doing some instant response of the second half of last year. Before that, most of the interactions I would have with the criminals was direct communication. You'd be talking to some third-party support person that that cyber criminal group has hired and paying as a service in order to do negotiations, to do discussions. Second half of last year, every interaction that I had with the cyber criminals was not with an AI chatbot.
Cyber criminals are losing their jobs as well. The middle tier, gone. They want to be more efficient. They want to be more effective. They want to be able to do things faster.
So, cutting out that actually cost, we saw lots of cyber criminals changing their career path at the end of last year because they were out of a job. Now, it was interesting. When I was going through that chatbot and I was interacting with it, a lot of things changed. When you used to be negotiated with a person because people have empathy, chatbots don't. They just want you to do and have expectations. But they also can be broken as well. They also have failures in security.
So, it's also important to learn how you can break the guardrails. But that was interesting actually seeing the chatbots taking over.
So, for me, we're in that kind of world where I'm starting to see more and more use of AI being used in campaigns. And I'm going to start seeing that more and more effective as we move forward. They are accelerating, they're augmenting, and they're getting better. But we have to make sure that we keep up, that we accelerate as well. And it's important that we do that. The next area is around what do we have to focus on? It's the algorithms. I remember years ago, there was actually research. And I always thought this was very unfair.
When DARPA did a research, DARPA basically had a project that was against basically algorithms and drones against real pilots. And basically, the drones completely were more successful than the pilots. And I always thought that was a bit of an unfair advantage. Because anytime you put an algorithm against a human, it learns, it accelerates, it gets better.
It learns, it accelerates, it gets better. It's got a training model. We can only process so much. We have the ability to do augmentation, to have the ability to change and learn as well. But the algorithm has a specific set of goals. It will self-learn, and it will improve.
So, it's unfair to basically put humans against algorithms. So, the only way we can actually get better is when it's algorithms against algorithms. That's where we win. And it comes down to who has the best computational power, who has the best algorithms, and who has the most accurate data.
So, this is where we need to focus on how to improve it, how to share it. How can we collaborate? How can we make sure that we're all actually accelerating at the same pace? Because that's what cyber criminals are really good at. And not only have we had to think about the importance of algorithms when it comes to AI, but we also have the massive growing thing that's actually behind the scenes is shadow AI. We used to have shadow IT, where people were going and acquiring IT solutions outside of the security and IT team's knowledge. Now we have to deal with shadow AI.
So, what is shadow AI? It's actually employees going and actually acquiring AI solutions without the company's knowledge. We've seen an acceleration in the past year where executive boards have been trying to actually solve this problem through basically policy. And the policy is don't use AI for these systems or these departments in these areas. We're seeing actually developers going and putting code in GBT engines to find vulnerabilities, to improve it, to create it. Then they're going and taking that code and checking it in. But actually, it all starts to merge the same.
It all has the same problems and the same inconsistencies. We see actually a lot of people going and adding chatbots and AI algorithms into meetings, into the code. Do you even know half the updates you've had in the last year have actually enabled an AI agent or an AI algorithm that you might not know or you might know about that's now taking your data? Imagine you're having a team's meeting about a legal case or an acquisition that you might be about to do. And somebody joins that meeting with actually a transition or a note taker.
That note taker takes the notes, dumps it into an external company's data repository. Now all your sensitive meetings are now actually going outside of your control. And we have to deal with that more and more. Shadow AI is a big problem, which means the next topic we need to move to securing AI. We need to make sure we put the right protections in place, identities, the access controls, who can change, who can update, who can train, what training models are you using, who can add the data to those training models.
Securing AI is one of the most important things we need to be thinking about before we start really using it for things that really matter. And we also have to think about the generative reversible networks that attackers are using. I've seen this being heavily used more and more. As every individual here, we pretty much have a very, very strong social media footprint. We actually have online our own digital clone. Our digital DNA is now available on social media. And attackers can go and take that digital DNA and create digital clones of every single one of us.
And use that in order to do basically phishing scams against your family, your friends, against your organization, against basically trying to get accountants to transfer money where we saw cases last year, basically calls been made where people were actually deep faked into the video. So we have to understand about how can we make sure we control, how can we tell the difference between fake and real. And online, because of games, it's getting more and more difficult. We have to make sure we understand the implications of this.
And attackers are simply taking basically this is a site where you can actually go and create fake people. And we see this used quite often, creating fake documents, fake identities, even fake job applications. We're seeing more and more attackers not just trying to attack the organization, but actually getting jobs in the organization and starting within. And we saw a lot of cases reported in the last year that actually focus on that area. The next area is when we start moving. Where we actually truly are today is in a world of automation. It's AI automation, AI assisted, AI augmentation.
We're using it to help us. But we're slowly moving to a world where we're going to take off those guardrails. We're going to remove the human from that basically process. And it's going to be truly autonomous to the point where the algorithms will basically be defended in our networks. And we'll be observers. We'll be watching the battle. It'll be basically like going to the Champions League final and us sitting watching our team, the defenders, play against the attackers. And we just hope that we win. We hope that we had the right team.
We hope we had the right data, the right strategy, the right algorithm, the right methodology. Because that's what's going to make the difference. But it really comes down to is the data. If you got bad data, you're going to lose. If you got good data, you're going to win. I'm going to leave you one final note. When you think about AI, you want to treat it like your best cybersecurity analyst. Because one day, they might actually become that best analyst. And finally, for your AI agents and your AI algorithms, treat them how you want to be treated. Because one day, they might return the favor.
We want to treat them kindly, wisely, with accountability, with responsibility. Because that's how we want to be treated. If you treat them badly, they will learn from that. And bad things might happen. So I hope this has been interesting. I hope it's been educational.
Please, if you have got questions, I'm here. I'm thankful.
Stay safe, take care, and all the best. Thanks, Joseph. Insightful and entertaining, as always. I really liked your analogy with Super Mario, saying that it's your superpower. And reading through the applications for speakers this year, the applications sort of fell into two camps. Those where people had obviously used AI to write the applications, and those where we wish people had used AI to write the applications.
Anyway, I just want to ask you a question that kind of relates to the identity side of things. What are the risks of relying too heavily on AI in identity verification? And could we be creating new attack surfaces or biases? Absolutely.
One of the things that when we're using AI and identity related, one thing is I've learned, when I was part of the EU AI Act, which I was part of the subject matter expert years ago, and we were talking about AI and identity related, the EU AI Act, which I was part of the subject matter expert years ago, and we were actually analyzing about using identity, especially when it was talking about law enforcement using it for looking for criminals or for basically in the airports looking for authenticated travelers and so forth.
When you're using identity, especially using AI algorithm, the thing is that in those cases, all the time, we have to be right. We have no room to be wrong. So when we start using AI and identity system, we always have to be right. So therefore, we always must make sure we have integrity. We have basically accountability, responsibility. There must always be some human that's overseeing or actually been able to observe and be able to check. And we also need to have diversification as well. The more we rely on one method, the more chance we have of that one failure does occur.
The failure is disastrous. And we've had that in Estonia.
I mean, we've had situations where we rely on a single identity source, and all of a sudden, there's a vulnerability, and that just doesn't impact one person or one system. It's everybody. So when we start using it more and more, think about the implication of integrity and make sure that you're always right, because if you're wrong, you impact the integrity of that entire history of the system, unless you diversify it. Great to have you on the keynote stage, everyone. Joseph Carlson. Thank you.