Unlocking the Future: AI is the Key to CISOs Top Challenges
Caleb Sima
BSidesSF 2024 · Day 1
Overview
Caleb Sima delivered a keynote address at BSidesSF 2024, offering a positive and hopeful perspective on the role of Artificial Intelligence (AI) in solving the most pressing challenges faced by Chief Information Security Officers (CISOs). The talk, titled "Unlocking the Future: AI is the Key to CISOs Top Challenges," moved beyond the common fears surrounding AI in security to focus on its practical applications and predictive capabilities. Sima aimed to outline how AI, specifically generative AI and Large Language Models (LLMs), can fundamentally transform the security landscape by addressing long-standing issues that have plagued the industry for decades.

Key moments
- 01:00 AI Fundamentals: Strengths & Limitations of LLMs
- 04:00 AI Learning Model: Context Windows, RAG, Fine-tuning
- 06:00 Future AI Capabilities: Expanded Context, Self-Improvement, Localized Models
- 15:00 Enterprise & Engineering Impact: Oracles, Self-Documenting Code, Auto-Integrations
- 20:00 CISO's Core Security Challenges: Context, Coverage, Communication
- 22:00 Deep Dive: Context - The S3 Bucket Example
- 26:00 Deep Dive: Coverage - Shadow IT & Missing Logs
- 38:00 AI-Powered Security: Enriched Alerts & Automated Approvals
Unlocking the Future: AI is the Key to CISOs Top Challenges
Speakers: Caleb Sima
Conference: BSidesSF 2024
YouTube: https://www.youtube.com/watch?v=3p9c5_5mmvk
Overview
Caleb Sima delivered a keynote address at BSidesSF 2024, offering a positive and hopeful perspective on the role of Artificial Intelligence (AI) in solving the most pressing challenges faced by Chief Information Security Officers (CISOs). The talk, titled "Unlocking the Future: AI is the Key to CISOs Top Challenges," moved beyond the common fears surrounding AI in security to focus on its practical applications and predictive capabilities. Sima aimed to outline how AI, specifically generative AI and Large Language Models (LLMs), can fundamentally transform the security landscape by addressing long-standing issues that have plagued the industry for decades.
The presentation began by establishing foundational AI concepts, including its surprising strengths in creativity and problem-solving, as well as its current limitations. Sima then drew parallels between human learning and the evolving capabilities of LLMs, setting the stage for predictions on how AI will mature in the coming years. He detailed how these advancements would impact not only the broader enterprise but, more critically, the core functions of security teams. The central thesis revolved around AI's ability to overcome the pervasive problems of context, coverage, and communication—three fundamental inhibitors that prevent security organizations from achieving substantial disruption in solving persistent challenges like vulnerability management, incident response, and least privilege. Through illustrative scenarios, Sima painted a picture of a future where AI-driven automation and intelligence provide unprecedented clarity and efficiency in security operations.
Background
▶ Watch: AI Fundamentals: Strengths & Limitations of LLMs (01:00)
Caleb Sima began by defining the scope of AI for his talk, specifically referring to generative AI and, more narrowly, Large Language Models (LLMs). He highlighted a fascinating paradox: while many initially believed AI would first automate menial, simple tasks, it has instead proven exceptionally adept at creativity, problem-solving, communication, and synthesizing information—skills traditionally considered complex and uniquely human. Conversely, its limitations are encapsulated by the analogy of a "genius 13-year-old who is overconfident with a short attention span and no street smarts." This characterization underscores AI's current need for precise prompting and its susceptibility to "hallucinations" or factual inaccuracies.
To explain the future trajectory of AI, Sima drew a rudimentary analogy to human learning. He described a four-stage process:
- Short-term memory: Initial absorption of information (e.g., reading tutorials, doing labs for cross-site scripting).
- Working memory: Iterative processing to condense information into foundational principles, abstracting and synthesizing knowledge.
- Specialized knowledge: Deep expertise gained over months or years, allowing one to become an expert in a specific domain.
- Foundational knowledge: Instinctive understanding and pattern recognition developed over decades, becoming an integral part of one's core knowledge.
Applying this analogy to current AI, Sima explained that today's LLMs possess:
- Context windows or context memory: Equivalent to human short-term memory, often likened to "64k of RAM." This is where immediate input and processing occur.
- Retrieval Augmented Generation (RAG) or Vector databases: These serve as the AI's "working memory," allowing it to retrieve relevant information from a larger corpus when the context window is insufficient.
- Fine-tuning: This process is used to create "specialized knowledge," adapting a general model to a specific domain (e.g., a cybersecurity expert, a cross-site scripting expert).
- Foundational model: The base model itself, which is not trainable in the same way as fine-tuning.
A critical distinction Sima emphasized is that, unlike human learning where knowledge flows seamlessly between these stages, current AI systems maintain these phases as "very distinct and very manual." There is no automatic carryover from context windows to RAG to fine-tuning or the foundational model. However, Sima predicted that within the next one to two years, AI will evolve to mimic human learning more closely, with continuous or constant fine-tuning and automatic caching mechanisms, allowing knowledge to persist and generalize across these stages. This continuous self-improvement, where AI models learn and adapt autonomously, forms the bedrock of his optimistic predictions for cybersecurity.
Key Findings
▶ Watch: Future AI Capabilities: Expanded Context, Self-Improvement, Localized Models (06:00)
Sima's core findings revolve around the imminent advancements in AI capabilities, which he describes as "what is here today but is coming tomorrow"—meaning the underlying research, discussions, and even nascent products already exist. These advancements are poised to fundamentally alter how enterprises and security teams operate.
The key findings and predictions include:
- Expanded Context Awareness: Current LLMs operate with limited context windows, analogous to "64k of RAM." The future demands significantly larger capacities, such as the ability to pass "a gig of log data into my LLM and have it analyze this." Sima cited examples like Gemini's 1 to 1.5 million token context, but stressed the need for even greater scale to process real-time, large-volume data effectively.
- Continuous Self-Improvement: This refers to the ability of LLMs to continuously fine-tune and learn autonomously. As an LLM processes vast amounts of real-time data (e.g., log data), it should automatically identify patterns, free up its context window, and move insights into more generalized, specialized knowledge. This self-learning mechanism is crucial for dynamic security environments.
- Localized Intelligence: AI models are rapidly becoming smaller, cheaper, and more efficient. Sima noted that models with 3 billion or 7 billion parameters are now achieving performance comparable to older 70 billion parameter models. This miniaturization enables these models to run locally on devices, in containers, or as serverless functions (lambdas), allowing for highly specialized and efficient monitoring at the edge or within specific application contexts.
- Deciding and Acting Models: Beyond mere translation or content creation, future AI models will be capable of making decisions and executing actions. Sima posed the provocative question, "what happens" if an AI is given access to tools like
user bin, acknowledging the security implications but emphasizing the inevitability of this capability. - Low Cost and High Performing: The cost of running these models, especially for inference, is projected to decrease drastically. Concurrently, performance will skyrocket; Sima predicted a leap from current cutting-edge speeds of around 600 tokens per second to "100,000 tokens per second" within the next year, making AI responses virtually instantaneous.
These technological shifts are expected to enable profound changes across the enterprise, laying the groundwork for AI to tackle the most persistent security challenges.
Technical Deep Dive
▶ Watch: CISO's Core Security Challenges: Context, Coverage, Communication (20:00)
Sima delved into the specific ways these AI advancements will impact the enterprise and, by extension, security. He outlined changes across general enterprise functions and then focused on engineering, a critical partner for security.
Impact on the Enterprise:
- Automated Meetings: "All meetings will be absolutely recorded, analyzed, and notetaken by AI." This transforms ephemeral discussions into recorded, searchable, and communicable data, capturing decisions and insights that were previously lost. Sima noted he has been using an AI notetaker for six months with phenomenal results.
- Self-Updating Wikis: Enterprise wikis, notorious for being outdated, will be maintained by AI. The AI will "know and understand some versions of truth" to automatically document and keep information current.
- Automated Management Reports: The tedious and time-consuming process of generating management reports (e.g., progress on OKRs, project status) will be automated. AI can pull data from sources like Jira tickets, synthesize it, and generate reports, freeing up significant human effort.
- Local Agents or Oracles for Expertise: Sima envisioned specialized AI models acting as "oracles" for specific domains (e.g., AWS, identity, email, Jira, Salesforce). These oracles would understand their respective environments and data, acting as intelligent API endpoints capable of answering complex questions and performing actions. For instance, an AWS oracle could detail asset privileges, including inheritance paths, without manual investigation. The fascinating prospect is these oracles "talking to each other" to provide holistic insights.
Impact on Engineering:
- Self-Documenting Code and Cloud: AI is already superior to humans at generating code comments. This capability will extend to automatically documenting functions, classes, libraries, and entire applications, reflecting ongoing code changes. Similarly, cloud configurations will become self-documenting, aided by the "oracles."
- Requirements as Code: Sima predicted a resurgence in the importance of requirements. AI will generate code blocks directly from requirements, leading to "requirements as code." This will streamline the initiation of new projects and the modification of existing ones, akin to the framework benefits seen with Ruby on Rails.
- Automatic Integrations: AI's ability to understand documented APIs and generate prototype client libraries will make integrations between disparate products significantly easier, potentially eliminating the need for engineers to write integration code manually.
- Localized Models in Operations: For infrastructure engineers, many on-call and incident response tasks involve repetitive actions like rebooting, respawning containers, or killing instances. Localized AI models can perform these actions automatically and at scale, reducing the burden on junior engineers.
CISO's Top Challenges and Underlying Problems:
Sima then pivoted to the CISO's perspective, distinguishing between the "real" CISO challenges (reporting, talent, relationships, budget, management—which he noted are not unique to security and will never change) and the "top security challenges." Based on interviews with over 40 CISOs, he identified six persistent security problems:
- Vulnerability Management
- Detection and Response
- Compliance and Measurement
- Third-Party Risk
- Incident Management
- Least Privilege
He observed that these problems have remained largely unchanged for 10-15 years, despite billions invested in products. This led him to identify three underlying fundamental problems that inhibit substantial disruption:
- Context: The "who, what, where, why, and how" needed to make confident decisions. Sima used the example of a high-rated CVSS vulnerability: without context (exploitability, compensating controls, remediation difficulty, priority vs. criticality), the alert is unactionable. He illustrated this with the "public S3 bucket" scenario: an alert about a public S3 bucket requires immense manual effort to determine if it should be public, what sensitive data it contains (PII, customer info, keys), who owns it, and how to disable it, involving searches across spreadsheets, CSPMs, Slack, and Jira. This "iceberg underneath the water" of context makes thousands of alerts unactionable.
- Coverage: The width and depth of visibility. Sima boldly stated that "99% of breaches are caused because of coverage." He elaborated with the S3 bucket example:
- Width: An engineer used a corporate credit card to set up an AWS account for a prototype, bypassing security's SCPs and ticketing process. This "shadow IT" meant the bucket was outside the security team's visibility.
- Depth: The engineer accidentally uploaded their entire home directory (source code, keys, access) to the S3 bucket. Even if the bucket was known, object-level logging was absent due to performance and cost constraints, preventing detection of key access.
Other coverage examples included MFA exceptions for contractors leading to account takeovers, missing logs or event fields preventing lateral movement detection, and the inability to triage thousands of medium/low vulnerabilities, which often combine to form attack paths.
- Communication: Described as the "most important and biggest waste of time." This involves justifying existence through status reports, manually mashing data from disparate security products (CSPM, DSPM, ASPM) to assess asset risk, and breakdowns in communication between security and engineering regarding vulnerability priorities. Vendor trust is also a communication issue, often reduced to "lying" on Excel spreadsheets for legal compliance. Communication, to Sima, is fundamentally about "translation"—translating a version of truth for different audiences (managers, engineers, auditors, regulators, partners).
Sima concluded this section by asserting that AI's strengths in translation, synthesizing data, and acting on tasks make it uniquely suited to address these three fundamental problems. AI can provide the scale for coverage (e.g., 10,000 "smart Junior security Engineers" triaging every medium/low alert), the intelligence for context (agents talking to agents to synthesize information), and the capability for communication (formatting and translating data for the right audience, enabling chat-ops for real-time context gathering).
Demo / Proof of Concept
▶ Watch: Deep Dive: Context - The S3 Bucket Example (22:00)
While Caleb Sima's talk did not feature a live demonstration of AI tools, he presented several compelling "tomorrow" scenarios that served as a proof of concept for how AI could transform security operations by addressing the issues of context, coverage, and communication. These hypothetical examples illustrated the practical application of the AI capabilities he discussed, contrasting current, often frustrating, security workflows with an AI-enhanced future.
Scenario 1: Outbound Call Alert
- Today: A security analyst receives a generic alert: "A new outbound call to stripe.com was identified." This alert is often "pointless and useless" due to a lack of context. Is it expected? Is it malicious?
- Tomorrow (AI-enhanced): The alert is transformed into actionable intelligence: "This is expected behavior and is considered a low risk for the following reasons:
- Stripe is a trusted provider, and outbound calls are only allowed.
- Engineering documentation and discussions have identified Stripe being the new accepted payment provider.
- The Stripe libraries were introduced to the code repo
payment libon this date. - A discussion with Cosmo, the active contributor to
payment lib, occurred at this time frame via Slack, and he did confirmstripe.comas a domain should be allowed."
This rich context, synthesized from multiple sources (documentation, code repos, communication logs), allows for immediate, confident decision-making.
Scenario 2: Vulnerability Management - Cross-Site Scripting (XSS)
- Today: An alert states: "A cross-site scripting issue was identified in our internal CIS system via the case commenting function." Again, lacking critical context for prioritization and remediation.
- Tomorrow (AI-enhanced): The AI provides a comprehensive analysis: "It's located here. The total exposure time was 22 minutes. At this time frame, the issue was identified via the Nuclei assessment that was done. The issue is rated low risk due to internal system, limited authenticated users required, and on a staging system. The issue was then introduced in the last push to staging. The code that has the vulnerability was found to be introduced by Josh Smith. A fix with a PR was submitted, and Josh was notified via Slack. Josh has recognized this issue and has accepted the PR. A new rule was added to Semgrep, and the requirement stock was modified for this type of issue."
This scenario demonstrates AI's ability to provide granular details on exposure, risk rating, root cause (code commit, developer), remediation status, and even proactive measures (new Semgrep rule, updated requirements).
Scenario 3: Permission Approval Request
- Today: A CISO or security engineer receives a request: "Your requested approval settings are high for any Crown Jewel trust zones. A request for delete access for role SP report jam on S3 bucket. Do you approve?" This is a difficult decision, even for experts, due to insufficient information.
- Tomorrow (AI-enhanced): The AI provides a clear recommendation with supporting evidence: "Our recommendation is to Grant access for the following reasons:
- This request was made by Martin Bryce, who is the principal engineer of the data infer team, who has ownership of this asset.
- Meetings with Martin and The Business Media team discussed cleaning up and discarding reports on a regular basis on this date.
- Jira ticket 2928 was filed with a request for expanded permissions for regular cleanup activities.
- The requirement DOC for the SP report gen role was added to have delete capability.
- We reached out to Warner Brondz, who is the head of security engineering via Slack at this date, who also says he gives his approval for this."
The AI synthesizes information from ownership data, meeting notes, Jira, documentation, and even direct communication (Slack) to provide a fully contextualized approval recommendation.
Scenario 4: Automated Status Reports
- Today: Manual effort is required to generate status reports, often "justifying their existence."
- Tomorrow (AI-enhanced): AI automatically generates reports based on specific security objectives. For example, for Crown Jewels and least privilege, the AI can track "how many accounts have been reduced" and "how many privileges have been reduced" on a day-to-day basis, pulling the right data and translating it into an easily digestible format without human intervention.
These scenarios collectively illustrate how AI can move security from a reactive, context-starved, and manually intensive process to a proactive, context-rich, and highly automated one, significantly reducing the "iceberg underneath the water" of manual investigation.
Defensive Implications
▶ Watch: AI-Powered Security: Enriched Alerts & Automated Approvals (38:00)
The insights shared by Caleb Sima offer profound defensive implications for security practitioners and CISOs looking to leverage AI effectively. The core message is that AI can fundamentally address the long-standing challenges of context, coverage, and communication, thereby enhancing defensive capabilities across the board.
- Massive Scale for Coverage: Defenders should embrace AI to achieve unprecedented breadth and depth in security monitoring. This means deploying AI to:
- Automate triage: Eliminate the backlog of thousands of medium and low-priority vulnerabilities and alerts in SIEM/detection systems. AI can triage these at scale, identifying the critical combinations that often lead to real attacks, which humans currently lack the time or resources to address.
- Proactive security in engineering workflows: Integrate AI into engineering discussions, requirements documents, and code commits to automatically identify security-related concerns. This shifts security left, catching issues much earlier in the development lifecycle.
- Expand asset visibility: Utilize AI to detect and monitor "shadow IT" assets (like the S3 bucket example) that fall outside traditional corporate accounts and rules. This could involve analyzing broader data sources, network traffic, or even financial records to identify unsanctioned cloud resource provisioning.
- Comprehensive logging: While currently cost-prohibitive, the future low-cost, high-performing AI models could enable object-level logging on all assets, providing the depth of coverage needed to detect granular access and data exfiltration attempts.
- Contextual Intelligence for Actionable Alerts: Defenders must focus on building AI systems that can synthesize context from disparate sources to make alerts actionable. This involves:
- Developing "Oracles" or Agents: Create specialized AI agents that can query and understand specific enterprise systems (e.g., AWS, identity providers, Jira, Slack, documentation, CSPM, DSPM, ASPM). These agents should be able to communicate with each other to build a holistic picture of an asset, vulnerability, or incident.
- Automated root cause analysis: AI should be able to trace a vulnerability back to its code commit, the responsible developer, and even relevant discussions, providing immediate context for remediation.
- Risk-based prioritization: Move beyond simple CVSS scores. AI can incorporate operational context (exploitability, compensating controls, asset criticality, remediation difficulty, developer availability) to provide a true priority score for vulnerabilities and incidents.
- Enhanced Communication and Collaboration: AI can bridge the communication gaps that plague security teams:
- Automated reporting: Leverage AI to generate status reports, compliance reports, and risk assessments automatically, tailored for different audiences (management, board, auditors). This frees up significant time currently spent "justifying existence."
- Chat-Ops for context gathering: Implement AI-powered chat interfaces that can interact with engineers via platforms like Slack, asking follow-up questions, synthesizing information, and providing real-time context for security investigations.
- Improved engineering collaboration: AI can translate security requirements and findings into terms that engineers understand, ensuring that security fixes are prioritized correctly and integrated seamlessly into development workflows.
- Streamlined vendor trust: Explore AI-driven solutions for vendor risk assessments that move beyond static questionnaires, potentially by analyzing real-time security posture data or public intelligence.
- Prepare for Deciding and Acting Models: As AI gains the ability to make decisions and take actions, defenders must establish robust governance, oversight, and safety mechanisms. This includes:
- Defining clear boundaries: Establish what actions AI agents are permitted to take autonomously and under what conditions.
- Human-in-the-loop: Ensure that critical decisions or actions always have a human review and approval step, especially in early deployments.
- Auditing and logging: Implement comprehensive logging of all AI decisions and actions for accountability and post-incident analysis.
- Data Quality and Accessibility: The effectiveness of AI is directly tied to the quality and accessibility of the data it consumes. Defenders should prioritize:
- Data integration: Ensure that all relevant security, operational, and business data sources are integrated and accessible to AI systems.
- Data hygiene: Maintain clean, accurate, and up-to-date data across all enterprise systems, as AI will amplify both good and bad data.
- Standardization: Promote data standardization where possible to facilitate easier ingestion and synthesis by AI models.
By proactively adopting these defensive strategies, organizations can harness AI to move beyond the persistent challenges of the past, creating a more secure, efficient, and intelligent security posture.
Key Takeaways
- AI's Unique Strengths for Security: Contrary to initial expectations, generative AI and LLMs excel at creativity, problem-solving, communication, and synthesizing information, making them uniquely suited to tackle complex, long-standing security challenges.
- Mimicking Human Learning for Continuous Improvement: Future AI models will evolve to continuously fine-tune and learn autonomously, expanding context awareness to process vast amounts of real-time data and localizing intelligence for efficient, specialized monitoring.
- Enterprise-Wide Transformation: AI will automate and enhance core enterprise functions, including meeting notetaking, self-updating wikis, management reporting, and the creation of specialized "oracles" that provide expert knowledge and inter-agent communication.
- Addressing Fundamental Security Inhibitors: The persistent security challenges (e.g., vulnerability management, incident response, least privilege) are rooted in a lack of context, coverage, and communication. AI's ability to scale, synthesize, and translate data directly addresses these core problems.
- Contextual Intelligence for Actionable Security: AI will transform generic security alerts into rich, actionable insights by synthesizing information from code, documentation, communication logs, and other enterprise systems, drastically reducing manual investigation time.
- Unprecedented Coverage and Automation: AI will enable security teams to achieve massive scale in coverage, automating the triage of low/medium vulnerabilities, proactively identifying security issues in engineering workflows, and potentially monitoring assets outside traditional visibility.
About the Speaker(s)
Caleb Sima is a distinguished keynote speaker at BSidesSF 2024, known for his optimistic outlook on the future of AI in cybersecurity. With over 20 years of experience in the security industry, he possesses a deep foundational knowledge that allows him to instinctively identify patterns and correlations in new technologies. As a CISO, Sima is intimately familiar with the top challenges faced by security leaders and has dedicated his expertise to exploring how AI can provide tangible solutions to these persistent problems.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
This talk presents a high-level, optimistic vision for how generative AI, specifically LLMs, can address long-standing CISO challenges related to context, coverage, and communication. While the speaker effectively articulates common pain points and offers compelling future scenarios where AI enriches security operations, the underlying technical depth is superficial, focusing more on the 'what if' rather than the 'how' of novel AI applications in security.
Heather Calloway (CISO) — MUST SEE
This presentation offers a highly relevant and actionable vision for how AI can fundamentally transform security operations by addressing the critical challenges of context, coverage, and communication that plague CISOs. The speaker effectively translates complex operational pain points into clear opportunities for AI-driven solutions, providing compelling examples that resonate with real-world institutional failures and the need for improved decision-making and accountability.