There is no cybersecurity without AI anymore. Today, I will discuss how AI has changed security, and not only security, but also how this will drive business value with someone who has a long history working for as a security leader within large, well-known global companies such as Deutsche Bank, Daimler, or Adidas. Welcome to the CISO Perspective, the podcast with leading CISOs about how they think, they decide, and how they lead.
Today, my guest is Michael Schrank. Michael, nice to have you here in this hot August summer day. Thanks so much for having me, Berthold.
So, Michael, before we start with the main questions, can you perhaps say something about your career, how it went, and what experiences you made in the different? Yeah, sure, absolutely.
So, once again, thank you for having me today. I think this is a great format, and super happy to be here. Looking back at my career, actually, I think many people always ask me, did you want to be a CISO? And to be honest, once I finished university, I would have never thought that I would become a CISO at some point. But I always loved cybersecurity. It was always very near and dear to my heart. It was my hobby, and then somehow became my job at some point.
And gaining experience in different environments, I mean, like you mentioned, starting out in the financial service sector with Deutsche Bank, which was heavily regulated already back then, and had to do many things in security that a lot of unregulated companies are even not today. It was quite an interesting place to start, right? And then moving from that into automotive and retail, changed the perspective a bit, because all of a sudden the regulation was gone, and we had more the liberty of doing the things that really make sense in security.
Not everything that's regulated makes sense, right? You maybe do it for the regulation purpose only.
And so, seeing that develop across that journey, seeing those different environments really helped me. And I became a CISO quite early, actually, of those large-scale enterprises. I think it has to do with the fact that I love complexity, and that I love to build information security, cybersecurity teams for such large-scale organizations. And that's what I've done in the last few years.
Yeah, thank you. I think it's seldom that someone worked as a CISO in three very different industries, yeah.
Now, our motto today, there is no cybersecurity without AI anymore. Is that because AI has fundamentally changed how we defend, or is it because the attackers are actually using AI, even at scale, and therefore don't leave us a choice, but to use it as well?
Yeah, excellent question. I mean, what we've seen now in the last two, three years is really remarkable, right? Things have changed so quickly.
And yes, I definitely see that we are forced to change as well. We are forced by attackers adapting AI, using AI.
And again, we don't see attacks in general being way different. It's just the scale has changed a lot. We have seen in the past that if attackers wanted to get into your environment, laterally move, exfiltrate data, it would typically take them a longer amount of time of doing so.
Yes, they were splitting up already in their tasks, right? We all know that they had people specialized on getting in, others on the lateral movement, others for the exfiltration. But what we see now, at least on the attacker side, is an incredible speed up in how they do that, because they are leveraging AI. And so yes, from one perspective, I would say, we are forced to adapt, right? And I'm not talking about the number of vulnerabilities we need to fix, et cetera, and we can cover that later, maybe. On the other hand side, I also see this as a huge chance, right?
We do see that with AI and the usage of AI, we can get rid of certain tasks, or at least shorten the timeframes that we need in order to detect something and remediate something. And I think that's what we need to embrace a bit more. Not speaking of, and I think that this is one of the key things we need to consider as well, the immense value of AI for all the corporations that we are working for, so for the business. And we can cover that later a bit as well, I guess. So in your experience, is AI already delivering real measurable value? And where do we still, let's say, experiment with it?
Yeah, yeah, that's an interesting one. I think we all, let's say two years ago, saw what's happening in the market, right? All of a sudden in the security market, we saw everybody had an AI tech. And if you ask me, the areas where for now we have seen it proven to be super helpful is wherever we had a lot of manual work that we could not only automate now, because, I mean, we all know we had robot process automation in the past, et cetera, so we could have automated more. But now with AI having the chance to add the context there and do smart things in an automated way, right?
And if I look into it right now, I would say that's definitely in cyber defense, when it's about the enrichment around events, so preparing things for the analysts, even recommending actions, et cetera, many things in the GRC space. So many of those manual things like control attestation, also third-party risk management, where you had to do a lot of back and forth with information. That's where we see a huge lever with AI to reduce manual efforts.
And last but not least, and one of the parts, I guess, where I'm most hopeful right now as well, identity access management, especially also when it comes to identity access governance. So making sure that you're onboarding all of your applications into your central identity store, but also into your IAG tool, et cetera. That was a lot of manual labor in the past, keeping those integrations running and so on. And what we see right now is there are players that are focusing on that, and we already see a lot of benefits out of that. Let's not forget about code reviews.
I think a lot of privileged companies who can use methods and others use it exactly for that. And they claim that they have identified lots of vulnerabilities because of that already.
Yeah, that's an interesting one. It's interesting you bring it up. I wouldn't have mentioned it as one of the most beneficial ones, to be honest, at the moment, because what we see is a bit mixed message, right?
So yes, a lot more is discovered, and I guess that also goes back to the vulnerability management in general. AI helps us to discover more, but what's the quality of the findings? What's the real impact? So what are the risks behind it? Just because there's a finding, for example, in the code, is it really actively used in production, for example? Can it be exploited? I think those are the questions that need to be answered more. I do hear mixed messages of those that are part of the Mythos previews.
They say, yes, definitely there's a lot more that's being discovered, but also plenty of false positives and a lot more data that you need to go through and distill the ones that really matter. And I think this is also, just on a side note, I think this is where, again, security providers now can add a lot of value to make sense out of that large chunk of data and what to focus on. That's an interesting one.
Now, many say that because of AI, classic disciplines like whatever, patching, vulnerability scanning, or traditional IAM, even the SOC, as we know it, is less important. So what's your take on that? I wouldn't sign up for that statement, actually, and the reason for that is, I think they don't get less important. I think we just need to get the job done properly. And what I mean by that is, we need to focus on what matters most for our companies.
I think many security teams are today still trying, and we've talked about it in the past already as well, still trying to make the whole company secure, to make sure that any device that's on the network is secure, etc. With the sheer amount of vulnerabilities that we see now, this is even more impossible than it was before.
Yes, small organizations might have had a really neat footprint in a very clean network in the past, but as soon as organizations became larger, there would always be a large pool of vulnerabilities as well and untreated devices, etc. And I think that's perfectly fine because, again, with AI now, what we need to do is, we need to make sure that what we often call our crown jewels, etc., where it really hurts us, those need to be the areas where we need to speed up. Those are the areas where we need proper detection, where we need proper patching, etc.
The only thing that we have seen in the past few years, and with AI now even more is, and sometimes we didn't focus on that too much is, we need to speed up the recovery as well. So that was very often a point as well, where we as organizations, security organizations, couldn't prove that we can recover, especially for those critical environments. And I think we need to have an additional focus on that as well. But all in all, answering your question, I don't think that those traditional areas go away or are less important. I just think we need to even more refocus them.
I remember when we started with the cyber council, one of our first discussions, we talked a lot about what we called cyber hygiene. So obviously, and my impression now is that with the AI, that's even more important than it was in the past.
Yeah, yeah. And because also what we've seen now, things that in the past were too tedious for attackers to abuse them, to write exploits for them, etc., are now being abused because AI can more easily do it, obviously. And so yes, fully agree, cyber hygiene will be one of those key factors going forward as well. Just earlier this year, we reached out to our cyber council members and asked them about usage of AI in practice, and to what extent they would actually rely on AI. And it was a bit of a mixed message.
So on the one hand, most said that they wouldn't, at least not today, trust or allow AI to take decisions without a man in the middle, so to say. On the other hand, when we asked them, okay, what is your wish for the future, many said we want autonomous response from AI.
So I mean, that's an interesting take, isn't it? Yeah, for sure. I guess we are all still a bit scared and we don't know what's going on, right? Or the way I see it right now is I think in certain areas where we have a good understanding ourselves and also the right data, and we all know AI is all about the data you can fit into it, I think even today autonomous decisions are okay. What am I talking about? Let's make it concrete.
If you have an infection on a regular endpoint of an end user and you need to quarantine that endpoint, I think those are things that can be decided autonomously and can be done autonomously even today. That's where I would trust the AI to follow the playbooks we know, et cetera. And then you can also question, do you need an AI if you have a proper playbook? But I guess where it gets tricky is where that context is missing, right? Let's say you see something on a server, do you want that AI to take autonomous action?
Well, it will have to do with the fact, is that server very business critical or not? And then it again goes back to the data we have. So do we have a perfect CMDB that tells us what business line that server is for, how critical it is, can we take it down or not?
And today, and I think that's the interesting thing, but I also say we are maybe still a bit scared. Today, our assumption is that our analysts or even we ourselves have more data in our head, a better understanding of the organization, et cetera, that we can take a more informed decision. And I do think that this is true to a certain extent, but I also think that sometimes we overestimate that. And so I get that take that people are curious, want to explore, and would hope that going forward, there is more autonomous action.
But I think we all need to gain some more trust and actually get the right data together so that it can really work. So let's switch perspective a little bit. So we talked a lot about what is the impact of AI for security or within security.
Now, of course, we know that our business is a bigger change or equally big change on the business side. So what can security now do? So it was always known as the department which says no. So has this changed now? Are we concerned or what's your view here?
Yeah, that's a great one. And that's where I have a very positive view actually on things. People who know me and how I build security organizations, security organizations, I see this as one of the biggest opportunities that is out there. And why do I say it that way? There are very few points in time where you as a security organization can prove that you're an enabler, you're allowing the business to thrive with new technology or whatnot, or you are the department of no. And I think we are in that situation right now.
And so how I love to build security organizations is that people and even my directs, for example, are responsible for certain areas of the business and need to interact with those business leaders on a regular basis so that we understand what's going on in their area. And again, I see that huge opportunity right now with AI. And it actually comes in quite handy because everybody's kind of scared of AI as well. And everybody is reading the news that AI agents are going rogue, et cetera.
That's not just us technology folks that are reading that, but that's regular people working in all the business functions. And from my perspective, it's that huge opportunity right now that you can come in as security and say, hey, let's make sure that you can leverage AI, but in a secure manner. And you're the partner doing it together with them rather than the department of no saying, well, you can't use that yet, et cetera. Because what we all know is they will use it anyway. If we don't talk to them in an open way, they will find a way of using it without us.
And then you're having transparent risks, right? I think when we prepared for this session today, you mentioned that one could even use AI to generate new opportunities. So what did you mean by that? Yeah. So one of the things that we see a lot right now, and I would answer that from two perspectives. Number one is from a pure business perspective, AI at the moment enables us to pursue new areas of business that have been too tedious in the past. So there was no real business case behind.
And I do see the same actually happening in security because the challenge we had, for example, with my wish of being very close to the business, obviously we security folks also have limited time, right? And how much can you interact directly with the end user, with your business partner, et cetera. And what we see right now is that with AI, we can scale that better. And I think, especially in security as well, going forward, a lot will be more about that interaction and leveraging AI for it.
So just to give a very, very concrete example, what we've seen in the past is when there is phishing waves, et cetera, very often you would want to ideally reach out to the end user, quickly talk to him about something, reconfirm something, et cetera. Or even if you had an alarm in the sock, you wanted to reconfirm something. Super hard to do with a limited amount of staff, right? Those are things where you can leverage AI now to increase that interaction.
And that in turn, from my perspective, helps the security department's reputation again, because the security department is not somewhere hidden and you never hear from them except for when they say no, but rather you're building that relationship and you're seen more often. And not just in those cases where you say no, but in those cases where you add value. And so I think both for the business, but also for security, there can be a lot of value add. Okay. So let's switch perspective again, perhaps look at the vendor side.
You mentioned it earlier in this talk already that now almost every vendor obviously claims to have some sort of AI integrated. So how much AI washing is in that talk? So what are you seeing at the moment? I think that was maybe a bit the disappointing thing in the last two years as well. So we all started out very hopeful to see the adoption of AI in the security tool landscape as well. My number one favorite, and I think this is what you see across the board is you now have a chat window and you can crawl through the data that's in your whatever IAM, cyber defense, you name it tool.
I think that's quite neat. That's I guess the pure minimum that you can do. Is there a lot of value add? Not as much. Sometimes it's helpful.
Yes, absolutely. But overall it's not a game changer, right? I think there are two game changers in the market, which we haven't seen as strongly yet. But number one is it's way easier. And we all know that, right? It's way easier to build new software. And I've definitely seen, even in very traditional markets, new players now coming up, trying to disrupt those markets, not with a fundamentally different product, but just with a modern version of that product.
And yes, they are doing that with a lot of white coding, etc. And there might be challenges in the beginning with quality, but we all know that you can yield very good results in a very short time there. And I think that's for many established players on the market a bit the challenge now. It's easier to enter a market. On the other hand side, for those established players I would say are smart enough, it also enables them, right? It enables them to build new features way more easily, etc. So this is where I see a positive impact of AI already.
The kind of third thing that, and that's the main thing, I guess, where we are all looking for and hoping for is where do we leverage AI in the products to fundamentally change things? And I guess one of the biggest hopes there is that in detection products there will be AI that can go through all those amounts of data that we have, make sense of it and detect things that are not just in correlation rules, in playbooks, etc. So that's the big hope. We haven't seen a lot of successful things there yet.
But what we've seen already is leveraging AI in other spaces, and I mentioned it earlier, removing a lot of manual labor. So be it on the detection side for the analysts, but also on the identity access management side and GRC side. I think this is where we really see that AI embedded in those tools can really help. And I have one super trivial example that drove me personally crazy in the past because you always had to spend a lot of money, especially for consultants on it.
If you had your GRC tool suite and your company was using a control framework like ISO or NIST, you went to a new country and they had another control framework, you manually had to do a huge mapping exercise, etc. Now what we see is with modern GRC suites, you just put in whatever you have, they make a common control framework out of it, and then they can answer all those questions for all the other frameworks. And I think those are really the things where we see the true value already.
Okay, yes, yes, interesting. Now, last switch of perspective, let's talk about the people, the people who work in security. So if AI now, and you mentioned that, takes over parts of the classical security work, so which skills become now more important with AI?
Yeah, so I think first and foremost, and that's something that we see across the board, and I think that's one of the big challenges we need to tackle going forward. You don't have beginners positions anymore, you mostly have senior positions. So what does that say about the skill sets that we are looking for? We are looking for the skill sets where people can interpret what comes out of the AI or what the AI is doing. And so that essentially means all of the basic stuff that you had to learn in the past is a preset thing. So it's assumed that you have it in order to really add value.
And that makes it difficult for new people to come into that space, right? And so I think this is something we definitely need to work on. I always have in my mind that example of at some point, school kids had a calculator and didn't have to learn how to calculate anymore, because they could rely on the calculator. We are kind of in a similar situation now, even in our expert areas, right?
The thing is, if I look at the skill sets that you require, I would say the more abstract type of things that are really about judging is an outcome that AI created the right one or not, are the ones that are going to matter going forward. And I also think, and we have seen that in the last few years already, actually, security areas are evolving, right? Think of vulnerability scanning and management. In the past, you had folks mainly working with vulnerability scanners, network-based vulnerability scanners. And then cloud environments came with all of those CSPM players.
And all of a sudden, you could see those vulnerabilities in one moment without operating those tedious scanners, et cetera. So we've always had the need to evolve. I think with AI, it's just accelerating. And I truly still think that what will matter most in the next few years is building up the expert knowledge. So become an expert in those areas and be the one who can, number one, leverage AI. So anything you do today, you need to be able to do it in a smarter, faster way tomorrow with AI.
And number two, make sure that you still have the understanding from the basics up so that you can judge what AI is actually doing there. The judgment part that will remain, and somehow that also fits to the, let's say, skepticism the CSOs had by leaving everything to AI at the moment. Will this change the next two, three years? What do you think? I am afraid it must change. And we huge speed up in what the attackers are doing.
And again, in the past, I think many security teams could still lean back a bit because their companies were not as interesting targets, et cetera. They were just not interesting for the attackers because the business case wasn't there yet. Now the economics have changed. It's way easier to go broader and deeper at the same time. And so more security teams will see larger impact. And we can't cope with that in a manual way. And so I think, or am I afraid?
No, I see it as an opportunity. We need to leverage AI more and we will be forced into it. Okay. Thank you. And I think by that, we will close the main question and answer section. But it's almost already a tradition that at the end of these talks, we have a round of quickfire questions. Hopefully also short answers. Very spontaneously, first thing, what comes to your mind? All right. So first is of course centered around AI again. AI and security, game changer or overhype? I think it's a game changer. One security task you would hand over to AI tomorrow and one you would never.
I think I mentioned it earlier, remediation of attacks, taking action in very clearly defined boundaries and where you have the data. What would I not hand over to AI now and in the near future? My own job, I hope the boards still talk to us CISOs rather than AI. Good answer. Will the SOC of 2030 have more people or fewer? Fewer. Now a very provocative one. Passwords in 2030, still with us or finally gone? Finally gone. Actually at my last company, we have mostly pass keys and folks just focus on that.
I just recently in my private environment learned that a company has 20 digit passwords now and very little single sign-on. I think those ages are over. We need to get rid of passwords.
Now, personal question. In a crisis, coffee, tea or energy drink?
For me, as you know me very well, the answer is very clear. It's green tea, but very little.
Otherwise, I tend to get nervous. The crisis doesn't make me nervous, but too much coffee does. All right. I think you touched on that already, but nevertheless, one capability every future CISO must have? The capability of understanding the business and adding the right context. When it comes to people, higher for skills or higher for attitude? I am mostly higher for attitude because people who have the right attitude can get the skills. Last question. If you were not a CISO, what would you be doing? That's a funny one.
I think I would be doing something with my hands where you see at the end of the day the result out of it, be it building houses, gardening. I just had a CISO. I always see the real value immediately.
Thank you, Michael, for this very interesting talk and discussion. I think we learned a lot about the state of AI in large companies.
It is, of course, as we said, there is no security without AI anymore and it will continue to change. However, the humans will remain to be important.
Also, of course, the skills likely change. Thank you very much for being with us, spending these last 30 minutes with me.
Also, thank you to the audience for watching the episode of the CISO Perspective. I do hope that we see each other soon in one of the upcoming episodes. Stay safe and resilient. See you later.