This year's RSA conference, much like last year, was dominated by discussions about artificial intelligence (AI). However, the conversation has evolved significantly, Prakash Venkata, principal of cyber, risk and regulatory at PwC US, told SDxCentral.
At the event, “whether you walk the hallways or you talk to anybody, it was all AI,” Venkata said. “Now people are differentiating between the AI and genAI [generative AI] pieces, they are picking nitty gritty things [and] saying: ‘Okay, what does it mean and how practical it is?’”
The maturity of AI use cases in security In 2023, the focus of the AI-related discussions was primarily on automation, Venkata recalls, revolving around basic security use cases such as optimizing security operations centers (SOCs) by correlating different data points for better alerts and responses.
This year, however, the conversation has shifted toward the journey of AI integration. The cybersecurity use cases are more mature and beyond automation, he said.
In addition, some of PwC's clients told Venkata as they walked the show floor at the RSA conference that every time someone said AI, they filtered it out to understand what exactly they were trying to do. That shows maturity on the customer side, he said.
Differentiating traditional AI and genAI Even at this year’s RSA conference, some cybersecurity vendors still use the term “AI” to refer to both traditional AI capabilities and genAI, Venkata noted. “It's a 50/50 kind of thing. Most people still don't get that, like genAI is a little different than AI, but they put it into the same bucket.”
He added that it's not about the terminology but the maturity of the use case. Companies will not bank on something just because it’s labeled AI, Venkata said. Instead, they need to answer questions like, “Where are the use cases? How exactly are you doing it? And what is the value I'm getting?”
“It’s more about the value,” he emphasized. For companies that don't evolve, “it's going to be difficult for them [to compete] in the marketplace.”
Moving from hype to reality One of the changes Venkata observed at the event is the shift from hype to reality in AI applications.
Last year, AI, especially genAI, was a buzzword, surrounded by speculative discussions. This year, however, organizations have already started applying genAI to real-world scenarios.
“I don't think it's a hype anymore because people are seeing it in action already in a lot of places,” Venkata said.
This practical application of AI is evident in the adoption of tools such as Microsoft Copilot for Security and Google's Gemini in Security Operations. “Quite a few of our clients have been already using [these tools] … They're already embedding into their security toolsets to see how they can leverage them,” he said.
Some PwC clients, who are already using these genAI tools in security, told Venkata that accuracy remains a critical concern. For example, they still face challenges like ensuring the right data is used in the background and managing false positives. “They wanted that maturity to improve significantly.”
In addition, Venkata noted that last year, organizations were looking for genAI-specialized roles like prompt engineers, but now they want everyone in the company to be prompt engineers.
He added most of the organizations are open to using AI for security. That's what PwC is seeing with its clients, not just at the RSA Conference.
“Even though they don't want us to use the word ‘AI,’ they are saying how am I moving forward on this one,” Venkata said. “Definitely every one of our clients is saying, ‘Is there anything we can do? Whether it's automation, or future-proof ourselves.”
“Everybody is adopting [AI]. There is no pushback at all,” he added.
Comments