Welcome EIC 26 and also warm welcome to everyone watching us online. We are here on stage in Berlin at the EIC 26, but this talk, this panel will also serve as one episode of the CISO Perspective. The CISO Perspective is a new format which we brought up to share with you how leading security leaders think, how they decide and how they lead. And I have today, I have brought with me four leading security experts from different industries. So we have telco, we have defense aerospace, we have retail, different countries, different level of majorities.
So that's going to be an interesting discussion. So AI or identities in the epicenter, in the era of AI. And what is different now? Let me share with you some quotes which I heard this morning or throughout the day. And that's exactly what we would like to discuss.
So we, the humans, are now in minority. Identity and access management is a critical infrastructure. Identity is the, forget about new, is the perimeter. This and more I'd like to discuss with my guests over here. And before we start, obviously, I'd like you to introduce yourself. And I'd like you to answer two questions. Two questions, obviously, what is your current role? And secondly, what actually brought you into security? How did your career go?
Connie, ladies first. Hello. Thank you for having me. My name is Connie McIntosh. I'm head of security at Ericsson. What brought me to security was I had no idea. Security chose me, not the other way around. So I did an IT degree and then I applied for a job in government. Had no idea what it was. Knew it was in computing. And they were purposely secretive because it was in a classified network. And so I always say security chose me. So that's how I ended up in security. Roberto.
Hello, everyone, and thanks for inviting me. I'm Roberto De Paulis, head of digital security and security operations in Leonardo. We can say the opposite. I think that I chose security because it was a natural path. Since when I was a kid, 12 years old, with a Commodore VIC-20, I began programming in BASIC. And then I bought a modem, began the telematic. I began to manage one of the first bulletin board systems in Italy. And then I studied engineering. And so I turned a passion into a work. Andre. Turning passion into work. It's a good trick. So I'm Andre Kavalets.
I serve on a number of boards, in particular the Cyber Peace Institute in Geneva. I lead the UK's PhD program for multidisciplinary cybersecurity. Until very recently, I was the global head of cybersecurity for Vodafone business. And before that, spent 10 years as a global CTO for HP. And I go back to, you know, a bit like you, Connie. I started out 30-odd years ago coding and designing secure systems for the British Foreign and Commonwealth Office.
And for me, the concept of a determined adversary was always the single best challenge against which to design a system, a process, or an application. And that holds true today. Where you face an adversary, something really interesting happens. And that's how I got into security. Last but not least, Lukas. I'm Lukas Ruf. I'm the group chief security. I work in the British office of Migros. That's the largest retailer of Switzerland. And when I first was fascinated by security, I clearly remember this was back in 1984. When I watched the movie War Games. And then I wanted to become a hacker.
And soon I realized that it was too risky to be a hacker and switch sides. All right. Here you are.
Now, we want to talk about what we actually talked about the entire conference already. Identities in the era of AI.
So, what has now changed, right? So, we did a survey amongst the CISOs where many of you answered basically we do need a governance framework, a dedicated governance framework for these identities in the era of AI. Others actually say, well, it's not a new problem. It's just another service account with a fancier wrapper or something like that.
So, I'd like to get a short, let's say, statement from all of you about what you think about this problem. Lukas, now starting with you. Thank you very much.
So, that's the opposite. It's like a stack.
And, well, I think the whole problem accelerated dramatically. And this acceleration itself also raised the question, how do we really handle and control agency?
And, of course, as the title already said, identities at the epicenter. And so, we need to take care what are the identities of our agents if they have some degree of agency as well. And I'm convinced that we need to have a dedicated framework. It doesn't need to be anything totally freshly invented. But the processes, they need to be able to cope with the velocity of how agents are spawned and how they are then in the life cycle also removed again.
And, therefore, we need to have something which copes with the velocity and needs to be automated by itself. I completely agree. It's completely different. If network was our control plane years ago, it isn't anymore. We all agree that. Identity failed to manage identity. Far too narrow in scope. Far too static in its application. The new control plane, I think, is going to be AI agents. How we manage that is the challenge for all of us for the next three to five years. And if we fail at that, we'll fail at security. I think it's that stark. I cannot agree more.
Roberto, old problem? It's, by the way, yes, it's an old problem. Not very old problem, but it's a problem now much more complex to manage.
Because, by the way, even before AI, machine speaks with the API key, SSH keys, this is a certificate. And that word in many cases was not under control. Now the agent increased the complexity and the number of their non-human identities. So it's more complex now.
Yeah, I completely agree. I mean, we've all seen rogue agents. So what happens when you don't manage agents, they go rogue. They can do a lot of things and a lot of damage. So I think with what everyone has said, we need a governance framework around it. So now four leading CISOs agree that we have a new problem or a different problem at hand.
Now, we've done that survey. I talked about it already when we asked you. So how do you do it? 78% still think we need the human in the loop. So how does this all fit together? So it doesn't sound really different.
Again, it's a novel and different challenge we face. If we approach that problem in the same way we've approached and failed all of the other ones, we'll fail again. I think human in the loop will fail us. It's a life preserver on a boat that's already sunk. All the human in the loop is akin to making somebody walk in front of an AV and traveling at the speed the human can walk. The velocity will overtake us. We can't keep up. It's hard enough counting the humans in an organization. We've been overtaken.
I think this legal risk-based concept of keeping the human in the loop is just going to damage our ability to manage and transform. And those of us who hold on to that, the longer we hold on to keeping the human in the loop, you're placing undue stress on those humans. You're limiting your ability to transform, and you're not understanding the speed of change that the external environment is going to experience.
I'd say, boldly, human in the loop is the wrong and false first step to make. Well, I partly agree. If I may jump in, I do not want to take all the airtime. It's hard. But I think the human in the loop is just one implementation of a guardrail. And as long as we can somehow enforce the guardrails and we clearly understand what are the risks, then, of course, we can reduce the span with where the human in the loop provides the guardrail.
Yeah, I agree. Yeah, and look, I think whilst ever humans don't trust AI, we're always going to want to be in the loop because we don't trust it to make decisions.
I mean, I'm yet to see anyone in critical infrastructure put their hand up and say, sure, let the AI do it all and make the decisions. I mean, let alone the regulatory implications. I think regulators probably will have a say in that, too.
Yes, I completely agree, Connie, because I answer yes to this question of human in the loop because otherwise I lose control of what is happening. So, that's why, until I don't have something that can be automated but always with the control, the human control.
Well, but I disagree here. I mean, what you lack, Roberto, is trust in the system.
I mean, you are not confident what you have implemented, what you have specified that this will be enforced. And I think it's a cultural change.
I mean, I remember when we had e-banking introduced in the beginning of 2000. For any kind of luck, we had a high risk. And meanwhile, I couldn't be relaxed more.
But, Lukas, how can we have trust now? We have not the experience, we probably don't have the right tools yet of the right maturity.
So, what makes you trust? I think this morning, I don't know who was the keynote speaker, he introduced this concept of the Japanese guys for the cars. And I think it was Kazim or something like this. And for us, I assume we need to really approach this new era, this new space. We need to build trust, we need to experiment with it and get the confidence that it really works. Wouldn't you agree, Roberto? Not so much, because I'm, we can say, a follower of John Kinderwald. Never trust, always verify.
So, for me, it's difficult. But the verify is important. Because I think it moves trust to the governance layer. Do you have visibility? Can you discover what's going on across the environment?
But again, by putting people in a position of absolute trust and limiting the influence, I think you delay or you further confuse something you don't control. Whereas, you need that trust. I'm not saying no guardrails or no governance. But you need it in a different way. I think you need to be given AI-enabled decision support and insight. To take it away from armies of people trying to run as fast as armies of agents. Because that's a zero-sum game. Talking about trust, I have another data point for you.
So, again, touching on the survey we did. We asked the question, actually, which AI-supported service provides, currently in practice, the most value to you? And 67% answered that it is in the area of threat detection and SOC, triage, etc. Only 33% think it's the area of IGA.
So, how does this all fit together then? Connie, do you want to take this one? Yeah.
Look, I think what has happened with AI is we've looked at where can we get the biggest bang for buck. And that's why we've seen it put into really high data processing areas. Because that's one of the difficult challenges. And the fatigue in SOCs is very high due to the number of incidents. And so we've looked at what is the biggest problem that we can solve with AI. And that is probably why we're seeing that result, I think. And rightly so, because then you free up SOC agents to do really good analysis instead of just triaging.
I think that the market, the vendors on IGA are still not mature to provide the real value on this area. There are some promising start-ups that are working very good and are very innovative. And let's see what will happen. If they continue their path or they will be acquired by some other vendors that make traditional IGA and need these new capabilities. Couldn't it be also the case that when it comes to any form of cyber defense, this is rather a new area as such. And so it's a completely different kind of people that work in this area compared to the IGA world.
Which is basically an established tradition which we really live and we have this process. And we know we are the problem. And of course when it comes to the cleanup function of all the mess with all our rights and roles. Then of course we look for new capabilities. But there has been research 20 years ago or 25 years ago how to do role mining in an automated manner. And probably this challenge, this problem is considered rather solved from an academic perspective compared to cyber defense. And which is rather a new fancy topic. I mean this is supported also by our survey.
It says that only currently at least only 20% of you use AI for things where we all are more or the organization is basically sick and tired. Like access reviews for example etc. I would think that this is a natural next step for AI application. Agree or disagree? I think I disagree. You disagree? I don't think we'll put AI on the most mature and well understood processes. I think to Connie's point all of us will place our investment and our innovation and the highest burden on efficiency gains. On the things that are giving us the most pain.
And at the moment for most of us that's a tsunami of patching cycles about to hit. And also it's our operational teams. I set the team a challenge. I want no L1 analysts in the SOC. I want a year on your efficiency gain and you've got to start to automate those responses. That's one of the biggest operational challenges that we face. So I think that's where the effort, the investment and the money is going. To your point interestingly I've seen a shift from a vendor perspective towards that goal as well.
So not just in standalone technology and elements of control but to actually support the job of delivering operational security. And I think that's a really welcome shift in the last couple of years. Which has allowed I think the investment you see there to show up in that way. Anyone agreeing or same opinion? Well I think all the access review process which is tedious process for every one of us. This will be alleviated. And we will also probably have the chance to convince regulators that with all the mechanisms and guardrails in place.
We can accelerate this process and that we can reduce the manual access review steps to the very critical ones. Roberto you just mentioned that some vendors or many vendors are probably at this point not yet there. They are not yet mature enough. You run the Nata group for Zero Trust. So you probably heard every pitch on this planet regarding Zero Trust and AI supported stuff right? So question to you. When a vendor walks in with something like AI powered Zero Trust or other service, what are the questions you would ask the vendor? Every vendor claims to have AI capability, agents or whatever.
So then they have to prove what they are telling. And when you begin to ask okay but which kind of LLM are you using? Can we use our LLM? Can we install this on our premises? And then you can understand which protocols are used. Which permission needs to work. And which we can say FIRO routes need to be spread in the organization to work. You will understand if what they claim and tell is reality or not. But the question can be from someone. Okay but I don't have the chance to install this on my own premise to make this test. It's such kind of sus. So I have to trust. I have to trust.
So that is difficult. But I think if we are speaking about at least agents, an activity of red teaming on agents should be done. To understand how the agent reacts to we can say stimulus, signals, etc. Thank you. So in my webcast the CISO perspective at the end I normally do what I call a quick fire round. And I'm looking forward to that quick fire round now. Four CISO's firing answers to my single question. So I think that's going to be fun. First question. Starting with Connie. Identity at the epicenter. Fully agree, partially agree or overstated? Completely agree.
Identity as we know is the hackers favorite entry point because it's authenticated. Roberto. Yes. Absolutely agree. Andre. Yes. It's the single biggest opportunity we have to manage this mess. On the long term run I fully agree. I do not know what will be this flood of patches coming now soon. So at the moment partially agree. Partially. All right. So three times yes, one times partially. All right. Bigger headache. Human users behaving badly or AI behaving unpredictably? Now starting the other way around.
Well, I thought not to consume too much real time. But for me I think it's rather the situation of agents handling unpredictably. Because humans you can train. Today humans, tomorrow agents. Humans. And I think we speak too few about ethics on AI. Yeah. All right. In my opinion and experience I've seen they both behave badly at times. So I'm 50-50. 50-50. All right. Okay. So perhaps that requires now a little longer answer. But AI in your security team in three years from now, doing the routine work or making real decisions? Who wants to go first? I'll go first. Making real decisions.
Absolutely. We'll have advanced our use cases well enough and guardrails enough to be able to make those autonomous decisions. Absolutely. Yeah. I completely agree. We'll move so further beyond process automation and tactical operational things. We need to get into AI powered decision support. And if we're not there in three years we have lost that particular race. So it has to be the goal. I agree for many tasks autonomous. For many tasks. I also agree with Roberto. For many tasks, yes, but not for all. Okay. You're the partially fan, right? Exactly.
Well, I'm Swiss. It depends.
Now, you are all – so this is the last quickfire. You are all seasoned security experts and quite successful. Otherwise you wouldn't have been in that role. So what is your one sentence advice to a 25-year-old young professional who wants to end up in your seat? Most exciting job you'll ever have. No two days are the same. Do it. Be curious and continue to study and experiment. The curiosity point was the one I think I was going to make. The curiosity is at the foundation of everything. And I know the other point is we've spent so much time talking about agents and AI.
At the end of the day, what we try and do is make people safer. And protect people mostly from other people trying to do them physical, emotional or financial harm. Find your purpose in that. If you want to join this industry, find your purpose in that. And it will always be valuable and purposeful and exciting no matter what you do. I would give the recommendation if you're passionate about it, if it's your passion, then you're so agile and you're open-minded to any kind of change. And then you will find your path.
Conny, Roberto, Andre, Lukas, thank you very much for these insightful statements. I know it was short, but it was very interesting. So I think identity at the epicenter, I think we heard all, everyone agreed to that. It is not theoretical anymore. It has started in practice.
However, it's still at the very early stages. So we still have to do a lot more. The vendors have to do a lot more. The practitioners have to do a lot more. But it will happen. It is the future. So thank you for listening. This is a perspective. And you can obviously watch it on our website. You can also watch all the other episodes on our website. And with that, I wish you a continued successful conference. Thank you.