17 Comments
User's avatar
Dallas Payne's avatar

Loved this line: "You don’t need to become an AI expert. You just need to know which of your assumptions stopped being true. That’s the work now." I think this applies across the board to every sector.

A great read, team!

ToxSec's avatar

🙏 Thank you so much Dallas!

Erich Winkler's avatar

That’s something we see in cybersecurity all the time! Many people ignore the topic completely because they feel it’s too complicated.

Yes, some concepts are very complex, but you don’t need to understand everything in detail. Often, you just need to learn the basics and understand how they influence your decisions.

ToxSec's avatar

Absolutely. And depending on your team structure, we're often not the person who even knows the most.

We just need to know enough to find out that the product is vulnerable and get it to the right people for remediation.

Erich Winkler's avatar

I can only agree here. It isn’t about being the most experienced expert in every room.

Even the CISSP exam doesn’t test you on technical details in every domain. You need to understand the concepts that allow you to manage risks.

And there are certainly people who know far more than I do in each domain.

ToxSec's avatar

it’s actually pretty incredible the breadth the cissp covers. but then again that’s why it’s the gold standard.

Dallas Payne's avatar

I think you guys need to team up again - this is sounding like a part two!! And, it's also so very applicable to how we should all be working with AI no matter the industry or role - don't make assumptions, know enough, keep learning, be proactive, know how to identify and manage risks, know when to escalate and who to direct it to...

Erich Winkler's avatar

I’m already working on my guest post, so we’ll be teaming up at least one more time, hopefully more!

Very true! I can only agree!

ToxSec's avatar

very true on all accounts!

Dr Sam Illingworth's avatar

Thanks both for this excellent article. I learned a lot in reading this. I think for me the key takeaway is that process beats detection. Ultimately we need to really be thinking about working with our employers and our employees to make sure that people are asking the right questions rather than trying to spot patterns, which themselves are becoming very difficult to tell apart.

ToxSec's avatar

I think that's a pretty great way of looking at it. Process beats detection. And right now, we are struggling to keep up. But you're right; investing in our employees is the way through this right now.

Dr Sam Illingworth's avatar

Exactly. And what’s the downside? A more informed and AI literate workforce. Seems like a win-win to me.

ToxSec's avatar

and win-wins are pretty rare in the security space!

Erich Winkler's avatar

No doubt about that!

Erich Winkler's avatar

Thank you for your comment, Sam. I think that’s a great takeaway from this article! And you’re absolutely right, investing in employee education is the first line of defense.

User's avatar
Comment deleted
Dec 8
Comment deleted
Erich Winkler's avatar

Thanks, Larry!