The CISO of National Life Group predicts an exponential increase in vulnerabilities over the next six months
During an interview with Help Net Security, Becky Palmer, Vice President and Chief Information Security Officer (CISO) of National Life Group, discussed the challenges of defending against AI-driven attacks. Palmer highlighted how patching cycles, designed for human speed, cannot keep up with AI-driven threats, and shared strategies to compensate for this disparity.The acceleration of vulnerabilities and the impact of AI
The fundamentals of vulnerability management have not changed, but the speed and scale of vulnerability discovery and exploitation are changing drastically. With the introduction of the AI Frontier, it is likely that we will discover more vulnerabilities in the next six months than we have seen in the last thirty years. AI helps attackers find and exploit vulnerabilities at machine speed, reducing the time required for an attack from weeks to, in some cases, hours.The inadequacy of human patching processes
When attackers operate at machine speed, a patching process that works at human speed cannot keep up. Palmer emphasized the need to fight AI with AI to automate patch management. This includes using AI to correlate new vulnerabilities with the organization's environment, prioritize them based on exposure, and guide the testing and deployment cycle to compress patching times.Compensating controls to reduce exposure
When immediate patching is not possible, it is essential to implement compensating controls to reduce exposure until the underlying vulnerability can be remediated. Palmer listed some examples of compensating controls used by National Life Group: 1. Virtual patching: Using web application firewalls, intrusion prevention systems, and endpoint protection to block specific exploit traffic. 2. Access restriction: Limiting who and what can reach the exposed system, implementing the principle of least privilege and more robust authentication. 3. Enhanced monitoring: Implementing targeted detection on the vulnerable asset to immediately detect exploitation attempts and respond promptly.The impact of AI in the SOC
National Life Group has recently started using AI agents in its Security Operations Center (SOC), with significant results. AI has enabled the automation of complex investigations and bridging the gap between detection and human context. Palmer reported that, for AI-enabled cases, four out of five are resolved without human escalation, saving hours of work every day.The distinction between AI and human analysts
Palmer emphasized that the goal is not to replace analysts but to enable them to operate faster and focus on risks that require human judgment. AI helps free up the team to focus on risks that require human skills, improving the overall efficiency of the SOC.Assessing AI claims from security vendors
With the increase in security vendors claiming to offer AI solutions, Palmer shared some key questions to distinguish a functioning product from a mere marketing label:Managing third-party AI risk
National Life Group treats the use of AI by third parties as a vendor risk and data governance issue. Vendor risk assessment requires vendors and independent agents to disclose the AI tools and models they use, the sensitive data involved, where the data is processed, how long it is retained, and whether it is used for training. Contracts then establish guardrails, including prior approval, approved corporate LLM environments, restrictions on the use of unauthorized third-party LLMs, limits on training and secondary use, and controls on AI providers and subcontractors.Three steps to reduce AI risk in 90 days
For security leaders in small insurance companies or banks without an AI budget, Palmer suggested three priorities to reduce AI risk within a 90-day period: 1. Understand and prioritize the highest risks: Identify where most sensitive information resides, where you are most exposed, and which risks could have the greatest impact. Focus resources on these critical areas. 2. Strengthen identity and access management: Limit administrative privileges and ensure employees have access only to necessary systems. 3. Train employees: Educate employees about the risks associated with using AI platforms and the dangers of phishing and deepfakes. The interview with Becky Palmer provides a comprehensive view of the challenges and opportunities related to the adoption of AI in cybersecurity. Her strategies and advice can be useful for organizations of all sizes, helping them navigate an ever-evolving threat landscape.Useful Links
- National Life Group
- Speed and scale of vulnerability discovery
- Compression of the patch cycle
- Prioritization based on exposure
- The future of the SOC with AI
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the misuse of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.