What should security leaders do with AI? They don’t know.

What should security leaders do with AI? They don’t know.

Source: YouTube · IBM Technology · published Aug 19, 2026 · 29:07

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: Security leaders are paralyzed by AI adoption due to decision fatigue and high costs, but experts recommend starting with repetitive tasks and red teaming to build experience, while maintaining realistic expectations for AI's current capabilities. 1:07

Key Takeaways:
Start with Low-Risk Automation: Experts suggest deploying AI for repetitive, well-understood tasks like L1/L2 alert triage and vendor risk assessments to reduce alert fatigue and free up staff for complex work without high initial risk. 0:08
Arm the Red Team: Giving red teams AI tools allows them to simulate attacker techniques (like prompt injection) and understand threats, which helps defenders develop more robust protections against emerging attacks. 6:45
Combat "Ghostjacking" via Zero Trust: The "ghostjacking" technique, where attackers inject malicious prompts into trusted logs to compromise agents, highlights the need for strict Identity and Access Management (IAM) and limiting agent permissions to prevent overreach. 10:48
Contextualize AI Patching Limitations: Recent research showing AI-generated patches have a ~50% failure rate is not significantly worse than human patching success rates, emphasizing that AI should be viewed as a tool to assist humans rather than a replacement, requiring human-in-the-loop validation. 21:07
Adjust Procurement and Expectations: Organizations should adopt shorter, more flexible contracts to allow for "failing fast" and cheaply, while recognizing that AI is still in its early developmental stages and should not be expected to solve complex problems autonomously. 5:23

The panelists agree that while AI presents new and sophisticated threats like ghostjacking, the fundamental principles of zero trust and rigorous testing remain critical. By treating AI as a junior partner that requires guidance and oversight, security leaders can navigate adoption more effectively.

Sources:

  • 1:07 Discussion on security leaders' paralysis and decision fatigue regarding AI investment.
  • 0:08 Recommendation to start AI deployment with repetitive tasks like alert triage.
  • 6:45 Strategy of using AI in red teams to learn attacker techniques.
  • 10:48 Explanation of "ghostjacking" and its implications for agent security.
  • 21:07 Analysis of AI patching success rates compared to human performance.
  • 5:23 Advice on shortening AI contracts to allow for cheaper failure and faster iteration.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Cybersecurity leaders can't figure out
where to deploy AI. Panelists,
where do you think they should start? Dave, we'll go to you first. I think they need to start
at their red teams. Start with AI in the repetitive tasks,
not so much trying to bite off more than they can chew. It's good for repetitive tasks,
especially those kind of like L1, L2 ones, looking at alerts and stuff,
preventing alert fatigue. Hello
and welcome to Security Intelligence, IBM's weekly cybersecurity podcast,
where our expert panelists turn the biggest industry news stories
into practical takeaways that you can use. I'm your host, Matt Kosinski, and joining me
this week we've got Claire Nunez, creative director, IBM, X-Force,
Cyber Range. We've got Curtis Pitts, lead CISO trust,
and we've got Dave Bales, North Amer…