In the era of big data and artificial intelligence (AI), organizations embark on a transformative journey that integrates these technologies into their core operations. Databricks CISO Omar Khawaja sheds light on the company's journey, along with the challenges and strategies for securely shepherding data and AI at scale for security teams and leaders.
From its inception, Databricks has been a cloud-native data company, Khawaja told SDxCentral during the HITRUST Collaborate Conference. “We've been thinking about ML [machine learning] from the very beginning. And we use machine learning to enable functions across almost every part of the enterprise.”
The data analytics platform provider has been using ML to drive functions across the enterprise spectrum, including marketing, finance, customer service, threat detection and code reviews, he added.
Khawaja noted the varying stages of AI adoption among its clients, from technology startups to century-old public sector organizations. “Databricks helps them with that work of preparing the data and building the pipeline and gathering the data and being able to featurize it, so the machine learning models can consume the data and enable and improve particular processes within the business.”
According to a recent report from Databricks and MIT Technology Review Insights, a majority (81%) of 600 surveyed technology leaders worldwide expect AI to boost efficiency in their industry by at least 25% in the next two years, while one-third said the gain will be at least 50%.
Additionally, every organization surveyed plans to boost their spending on modernizing data infrastructure and adopting AI during the next year, and nearly half (46%) of them expect the budget to increase by more than 25%.
Lacking the understanding of AIThe data and AI journey is not without its challenges. Khawaja acknowledged some security leaders and teams are hesitating to embrace AI due to the lack of a good understanding of what AI is.
“They've heard the scary stories about AI can cause harm, and when their business wants to utilize AI, they don't know if it's in that tiny minority of AI that could likely cause harm, or if it's in the majority that wouldn't,” he said. “Security people tend to have a low tolerance for risk just instinctively. And so they're likely to respond with ‘We shouldn't do it’.”
Khawaja argues ML is the part of AI that the security team should learn more about because it’s dynamic and different compared to traditional statically developed programs.
“The world of machine learning is the manifestation and the combination of three different frameworks all coming together, and it's the union of them,” he said, adding the three different lifecycles include data operations, model operations and DevSecOps.
The next step for security teams is to identify where and how to implement controls effectively.
“Since we talked about the lifecycle … then when we talk about the risks, we can overlay the threats that would cause that risk to be realized over that whole ML system that we've defined very deliberately. And then we can talk about what are the controls that you can apply in which particular boxes of the machine learning lifecycle in order to prevent those threats from being successful and the risks being realized,” Khawaja said.
The end goal is to empower CISOs and security leaders with the confidence to shepherd the successful AI and data journey of their organizations by ensuring they adopt AI securely while minimizing the risks through deliberate action, he added.
CISO’s role in AI securityKhawaja recommends fellow CISOs educate themselves on AI technology and security.
He argues that CISOs should take a balanced approach and keep an open mind on the adoption of emerging and complex technologies like AI. “We may need to be applying new controls or applying old controls in novel ways and novel places.”
For CISOs operating within sizeable organizations, Khawaja noted “CISOs do not need to be the foremost expert on AI and AI security.”
Instead, they should focus on talent development, operating models, change management and decision support to ensure AI safety.
“These are four things that CISOs have always needed to be very skilled at,” he said. “The difference is with the introduction of machine learning into our organizations, CISOs really have to get good at these very, very fast and this is something that they can't rely on their team. They, as the CISOs, actually have to drive this and sponsor this.”
Comments