
Loading summary
A
A very warm welcome to cyber leaders with me, Kieran Martin, and me, James Line.
B
Now, we're both from the SANS Institute, who are kindly backing this podcast. I myself am a geek, a massive geek, I might say, that spent my life chasing cybercriminals around the Internet.
A
And what am I? Well, whatever I am, I'm not that. But I dealt with cyber security policy and government and cyber operations, and I set up the UK's National Cyber Security Center. Now, together these days, James and I are trying to unpack the weird, wacky wired and wireless world of Texas security and all the complicated things that it involves.
B
I love that over each season you're adding an additional W, and by the end of this, it's going to be a mega paragraph.
A
Wolverine will make an appearance.
B
I'm holding you to that. Okay, but look, folks, this podcast is a voice for security leaders and Wolverine. Apparently, we want CISO security directors and beyond to build up their knowledge of what works, what doesn't, and ultimately secure your organizations more comprehensively and quickly. Now, Kieran.
A
Yes?
B
Starting off today, I've got some questions for you.
A
You have so many questions. I'm here for you, my friend. Times are tough. We must stick together. Tell me what's bothering you and I will help you find true peace.
B
Great. Well, that's not exactly where I was going. This is actually less existential and more cyber security question.
A
Well, that's very embarrassing. I'm sorry, I thought you were going to ask me what the purpose of it all is, and I was ready for some existential questions about the meaning of it all. But anyway, you carry on.
B
Yeah. How are we going to recover? Well, here we go. So I have some existential cybersecurity questions for you. How about that?
A
Well, I'm just as bad as those meaning of life questions, but let's give it a go.
B
We're back on track, Kieran, in as
A
much as we ever are.
C
We're never on track.
A
In this podcast, there is no such thing as on track, only variations of
B
off track Graduations of off track. I like those. Graduations of hacked, maybe. One might say yes. Anyway, look, two questions.
A
No, 42. That's the answer to number one.
B
Probably number two as well. Look, no Hitchhiker's Guide to the Galaxy for you. These are important questions.
A
Oh, okay.
B
So behave if you can.
A
I'll try.
B
So, first, when you were at the National Cyber Security center, what sort of sectors did you worry about the most?
A
Well, there were all sorts at the time, 12, 15 years ago. The banks the telcos and the energy sector, they were always banging at your door. But then you had all the really serious ones like pharmaceuticals, healthcare, food production, transport, defense, and we started to worry about them big time, but they weren't on the radar so much right at the very start. But I think now with all the resurgence of criminal attacks, We've talked about those in previous seasons, all those attacks disrupting networks, the whole geopolitical situation getting worse. We had a whole episode on Volt, Typhoon type stuff. Those sectors like health, pharma, agriculture. Absolutely crucial.
B
Yeah. Look, Carol, I was half expecting you to say there were 42 companies you
A
were concerned about way more than that,
B
but that was actually half sensible.
A
Thank you.
B
And by the way, folks, if you didn't listen to it, going back and listening to the story on Vault Typhoon, absolutely worthwhile. Just fascinating and incredible guess. But let me continue to question two here. Kieran, whilst I've got you in sensible mode.
A
Yes.
B
When you think about that now and these massive crucial economic sectors, what do you think those sectors need to be thinking about? In the age of AI, has anything changed?
A
That's a really good question.
C
Can I ask ChatGPT?
B
And there I thought you were making some sense for a minute. Oh, oh, well, I think you technically could. But as for the podcast today, no, we will not ask ChatGPT or other LLMs that are available for that. Matter of fact, we will ask our guest. Now, he may decide to use ChatGPT, of course, Kieran, but that's up to him.
A
Well, that sounds much better.
C
So who is this guest?
B
Well, great reveal. Will happen momentarily, presumably whilst he's asking chatgpt. But put it this way, it's someone who is breaking new ground in AI security strategy at a massive scale across a whole range of critically important sectors.
A
So what you're saying, James, is that you want to know more about how to do AI security strategy in some really complicated and important sectors, and you've got three options. In third place, it's ChatGPT. In second place, it's me. But in first place, you have a great guest.
B
Yeah, well, let's leave the second versus third place discussion for now. Oh, that's probably some version of Right. But you got one thing right here that's crucial. We've got a great guest who's better placed than anyone to bring to life the implications of revolutionary new technologies to really complex and important environments.
A
Okay, so it is time for your great reveal. Who is our guest?
B
We have Today the group CISO of an organization of around 90,000 people, enough to fill Wembley Stadium. Medium who operated across 80 different countries. That in itself makes it an incredibly challenging job. I am sure that company is Bayer, a world famous conglomerate operating across pharmaceuticals, healthcare and agriculture. But that's not all. Oh, no, that wasn't enough to have someone on a podcast telling us about the challenges of cyber security. Before that, he spent well over a decade at very senior security roles at Airbus, applicable again, building on an already very wide and deep experience in cybersecurity. And there's more. He's an honorary professor of Cybersecurity at the University of Cardiff. He's very familiar with Rain, of course, in his native Wales, and He's published over 50 articles on everything from the use of threat intelligence to the cybersecurity of industrial robotics. And rumor has it he didn't use ChatGPT to write any of them. It is the one and only Dr. Kevin Jones.
A
Hello, Kevin. Welcome.
C
Thank you both. ChatGPT reliably informs me that I am in fact a recovering techie. So I sit perfectly between the two of you. I used to be techie, now I'm more on the policy and strategy side. But really good to be with you and to see you all again and have the chance to spend some time with you both.
A
Well, thank you and let's feed ChatGPT with some more lines of varying degrees of truthfulness. So, James, why don't you get started with our normal question for cyber leaders about Kevin and his path into this industry of ours?
B
Absolutely. Well, look, Kevin, as Kieran said, thank you so much for coming on the show. It is a privilege to have you. Now that we asked this questions, Kieran says to pretty much everyone to show the diversity of ways in which people get into cybersecurity leadership positions and how their background shapes their thinking and produces the different types of leaders that we run into out there. So for you, tell us your path. Were you a cyber geek growing up? But you've already mentioned you're recovering, a late bloomer. Did you always want to mix private sector work with academia? How did you get into it?
C
I actually, believe it or not, joined the industry at the age of 14 or 15, working in cyber cafes, if you can remember what they were. Back in the days before everyone had the Internet at home, it was all
B
isdn, oh, scratching the back of my brain there, Kevin. Oh, isdn, oh, and ripping out token
C
ring networks, replacing them with early Ethernet. That's how I really started and started learning. But actually, unlike today, where there was so Many career paths and directions you could go in. I mean there was nothing like online hackathons or even formal training courses in the UK in schools. It didn't really exist, it was kind of desktop publishing type thing. So for me it was all self learn and another blast from the past. If you remember things like ICQ and the chat message. And that's how we all self taught each other and drove from there and continually learned. Thankfully, I was very fortunate to go to university and do computer science. That's where the academia piece really started to come in. And equally was able to combine both my passions because I was able to play sports at a decent level as well at university whilst studying and rather enjoyed that. So did a master's and then eventually went on to do my PhD, but always kept a hand in industry as well as academia. So consulting, doing various things. And I'm very privileged to have worked really on the offensive security side ethically, but of course testing security of companies and environments and actually over the years in some very specialized areas. I mean I built out one of the UK's leading commercial industrial control system labs and built out a red team that was specialist in aircraft or satellites and industrial control systems. Worked very much on the defensive side too as an architect and then gradually shifted away from hand on keyboard and into the more strategic and business side of life. And I think that's a natural direction to go as you're managing business risks for the ciso. So really always learning, always wanting, do different things. I get bored easily. I think that's probably my downfall. So come through the industry in that direction and it's really multidisciplinary and then that's one of the things I love about this industry. It doesn't matter really how you get into it. I know some great people who come from degrees in all kinds of different subjects, humanities subjects, and really huge amounts of value they can bring to our industry. It's not just about tech. And I still today, even as the C of a company, you never stop learning. But I love conversations, deep technical conversations one minute, conversations with governments the next about what's going on and then risk teams and then business teams. And I think you really need that flexibility. And somebody used the word fungibility. There's one you can look up on ChatGPT later on about how you adapt and evolve.
A
So this is absolutely fascinating. Thank you. Really varied. In James's introduction, we could have gone even further and talked about not just the range of experience you had, but sort of the depth of it. Across different subjects, this academic stuff. Now I also work in a university so find it quite interesting. So first of all, straightforward question because I think the answers are always fascinating. Tell us about your PhD.
C
What was that?
A
And after all your cyber cafes and then studying computer science and then you sit down, you've got something of your choice. What did you do that in?
C
My PhD was actually in mapping human trust in multi agent systems. So this is long before zero trust was a thing. It's long before we're in the AI world. And I keep saying this is over 15 years ago, I mean nearly 20 years ago probably I was working on some of these research topics. So I keep joking and saying now is my time that we were doing formal mathematical modeling in temporal logic of human cognitive trust in multi agent systems and identity of agents system. So I'm looking forward to seeing where the industry goes. Sounds familiar, right?
B
That does sound a little applicable to Zeitgeist of the moment. It does, doesn't it?
A
And when did you do this PhD? Sorry, I know this is asking you to give away your age in part, but you know, so I think the
C
early research was sort of mid 2000s, right the way through to about 2010, I think we were there.
A
Well, if you're interpreting our questioning as hostile, then we're asking you to give away your aids. If you're interpreting it as friendly, we're asking you to measure how far ahead of your time you were. So one last question for me on this academic side. So you've published, I think several dozen articles on all sorts of different subjects other than your PhD, is there one area where you thought, wow, this is really cool and I've made a difference here.
B
Stay with us, we'll be right back. Hi everyone, James Lyon here, the CEO of the SANS Institute. A quick thought for you. Cybercriminals have networks, dark web forums where they share what works, what doesn't, and where they're constantly sharpening their playbooks against us. So why shouldn't we do the same? That's exactly what the SANS Cyber Leaders Network is about. It's a place where CISOs and security leaders share what's actually working inside their organizations and what isn't, while getting access to world class experts sharing insights into the latest threats and trends. You'll find me in there surfing around, sharing what works. So come join us at go.sans.orgcln that's Charlie Lima November. And if you're enjoying the show, one teeny tiny small favor hit subscribe. That's genuinely all we'll ever ask of you. And in return, we'll keep fighting to bring you the guests and conversations that you want to hear. Appreciate it all. Now, let's get on with the show.
C
I'm really proud of things like the human centric research that we've done in the past with Cardiff University and other universities as well, De Montfort University and Leicester. And I think I was, if not the first, I was certainly one of the early adopters for employing psychologists in cybersecurity teams. And even today, some of that research is paying dividends in terms of being able to protect ourselves, design systems. And actually there's a great book called Black Box Thinking by Matthew Seyed, which is all about the aviation sector.
B
That is a good book.
C
And how you design systems, think about decision you're making, think about the psychology and security can learn a lot from that. So I'm really proud about that. I'm also quite proud about some of the industrial control system stuff we were doing. So I said that there was an incident, small one, that everyone seemed to realize in about 2012, in the industrial control system space, which I won't name.
A
In a faraway land.
C
Yeah, yeah, faraway land. Those kind of things. We were doing research long before that and in that domain and definitely shortly after that. So I'm really proud of that. And one thing right now, actually, I've switched it up a little bit. So I'm really proud of some of the work we're doing right now with Cardiff University around the Cyber Innovation Hub and Cyber Innovation Hub Wales in the uk. For me, we have fantastic ideas and fantastic academic approaches to these type of things. We don't seem to be able to commercialize them very well. So the idea of Celebration Hub in Cardiff is that we put academics with entrepreneurs and we actually train and educate entrepreneurial mindset into people and even seed some new businesses and some new startups with a little bit of funding to get them off the ground. And there's some really cool businesses coming through. And the idea being that we're going to design for scale and growth and not just cottage industry security for the uk, but really design from the outset for investment into and go for seed rounds and A and B rounds, and I think that's quite innovative. I'm not really seeing anybody else doing that, taking the academia, the government, the industry and entrepreneurs and putting them all in a melting pot and seeing what comes out. So I'm really proud of the team there and what's going on. On.
A
Well, this is going Great so far in that. Absolutely fascinating stuff. But I think if I've been totting it up, we're on about 27 different topics we could explore because we've, you know, we've referenced offensive security, now skills, innovation, the human centric aspect of it, robotics, whatever, industrial control systems. And so that's five. I'm not going to try and list all 27. So we're going to have to try and narrow this down a bit and focus in on some points, particularly on some of that big system security and AI. So I'm going to go get James to start leading on that. But just to segue into it, we always debate terminology in our industry, you know, and even pronunciation. So sisos, sisos, sisos, et cetera. So I need you to give us the official pronunciation of your employer company because I've heard so many different versions of Bayer, buyer, bah, et cetera, and my accent doesn't help. So how do the Germans pronounce this world famous and strategically crucial company?
C
I can disappoint you because the Germans and the Americans pronounce answered slightly differently. And we're a global organization.
A
Oh, this is good. No, this is good.
C
So I think you can say either Bayer or buyer or buyer buy in. So you can have as you wish, feel free.
A
Excellent. Right, well, with that clarity, over to you, James.
B
So many options. I feel like we should maybe take voice prints of each and then run a mathematical average and ask AI to form a perfect pronunciation that everyone could agree on. But as we're not doing that today, and you've asked me to focus. Kieran. Kevin, one thing that's really obvious as you read about you and talk to you, is you don't do cyber security. Small. I mean, just all the descriptions you've given us in the opening, big problems, big ideas, many of them considered kind of many years before they hit their mainstay. But also organizations, I mean, Airbus are now Bayer. I mean, huge organizations, really complicated supply chains, tons of operational technology, fascinating and challenging customer base, massive risk profile. I mean, it's probably easier to list the threat actors that might not be interested in you, rather than the ones that might be helped to get you, unlike many people on the planet. So a lot of our listeners will be from smaller organizations and kind of wondering what's different about operating at the scale that you do as a leader in terms of the security problems. I mean, interested from every perspective. There must be some real advantages, but there's got to be some drawbacks as well.
C
Yeah, I mean, I told you I didn't like to be bored. So these big organizations are definitely keeping life interesting. I think the first thing to say though is every company is a target either because of what the company is, what the company does, who a company is a supply chain to, or just because. Because cybercriminals are randomly targeting things on the Internet to see where they land and spray attacks. So it would be a myth, I think, and a misconception to say it's only the big companies that are targeted. But you're absolutely right. I mean, companies like ours are usually targeted for different reasons. I mean, obviously things like intellectual property theft, big whale hunting, we'd be a big target in terms of cybercriminal gangs, those type of things. And some of the headline news is that you're seeing in other companies that are being targeted, especially in the uk. The reality is that they were done because of who the company was more than anything else. I think in terms of specific challenges. You've said it already. The challenge is scale and complexity of the environments that we operate in. And how do you get a handle and an understanding of the level of digital footprint that companies like Bayer actually have. The second part to that actually is global operations also mean global regulations. So we have to do regulations at scale as well. And we're seeing a very increasing number of national or regional cybersecurity regulations. So I think for us that's definitely a factor we can talk about in terms of how we're delivering that global regulation in the right way. And I think also for companies like ours, some of your listeners may be coming from say digitally native organizations or cloud native organizations. Others might well come from more traditional organizations. And I think companies like ours that have a very long history in the digital space are operating mixed environments too. Right? We have super modern agentic AI platforms that we're building out more traditional applications, OT environments. And how you manage the security operations across all of those that deliver that scale I think is good. And to be honest, the way we handle that is through strong standards in the way we operate. We have to build clear accountabilities and well defined workflows for our security operations. And Bayer over the last two years we've actually moved to a platform based model for delivery of our security. So it's not projects, it's not different operations every time. We're fundamentally delivering full stack platforms and I think that really helps us build those workflows and engage them out in a risk based approach. Generally. I find that works exceptionally well with the stakeholders. The clear advantage for companies like ours is, is to be honest, we're reasonably well resourced. I mean, we have fantastic and talented people that we can bring into the companies to help us deliver forward thinking security platforms and security programs and manage that and make the changes we want. And it's fantastic to be able to walk in and just randomly jump into a meeting somewhere in a workshop that's going on and you're talking about how to protect AI, for example, or moving a technology platform from one to another. And the people we have really make organizations like this and it's a privilege to work with people day in, day out. And the final piece, I think that's an advantage for us. Us evolution and change is constant and the platform based model allows us to have the stability but still deliver constant change and constant improvement in those platforms to adapt to whatever's going on in the business. And we weren't talking about businesses rolling out agentic AI two years ago. We were still talking a lot about cloud and full DevOps and DevSecOps and now we're suddenly pivoting. So the scale that we have is the challenge, but actually the advantage we have is our ability to move, to adapt to those challenges and those scales.
B
Yeah, it makes a lot of sense that the pros and cons, and I just love that point you have on being able to walk into rich discussions on kind of fascinating security and technology challenges. The joy of a team who are well trained. You've got great ideas, you know, at your disposal. You can super quickly. I guess one of the big challenges that comes with such a sizable team and all that expertise is how you coordinate and create focus for those security teams and how you communicate it. And one of the things that's always impressed me in our discussions is your ability, ability to take large numbers of initiatives and kind of compress them in a way that a board and business leaders can understand. The kind of focus at the level of two or three things as opposed to 20 technology projects and a kind of vast roadmap quarter by quarter, which at some point someone might want to see. Of course, any quick pro tips for, you know, folks listening who maybe aren't as gifted at that, that you'd suggest in trying to communicate the myriad of stuff that's always going on in security teams. Even a small cybersecurity team usually has 15 things, not two. How do you simplify it?
C
I mean, for us, this is something we've worked very, very hard on and there's two challenges here. Number One is the number of changes and technical changes you've spoken about. The second challenge to this is cybersecurity. And generally it can be seen a long way from the business in air quotes. And I keep saying, if we're not the business, who is? We're here to enable the business, digital operations. So they're part of us. So when you start to overcome them, you can really break down and say, what is the value proposition of security? Why are we all here doing our jobs day in, day out? And yes, it's to defend the business, but actually we broke it down and we said everything we do should underpin on three things. Number one, license to operate. And recently we're not just talking about are we compliant to this or that regulation. Where are we? It's like you can flip this into outcome thinking. So our license to operate is all about enabling market access. And I know it's a subtle change in the language we're using, but concretely, if I use a UK example, we don't just say Cyber Essentials or ISO 27000 certification tick, we're compliant. We say we can deliver our business services to the National Health Service or we can deliver our business services into other areas. That's an enabler that security gives us. So, number one, license to operate, number two is customer trust. And in organizations like ours and anywhere else, we have to add to the the company's mission to deliver with trust to our customers and our stakeholders and our engagement so all of our teams can pin what we do in security somehow to that outcome of that mission. And then the third one is company resilience. Sometimes if you listen to Gartner, it's called anti fragility because they like a term that's very Gartner esque. We basically refer to it as resilience and cyber resilience. And part of that is how do we reduce blast radiuses, how are we resilient to cyber incidents? But not only from a technical point of view and a business. And I think if you really break it down to those three things, license to operate, customer trust and company resilience, at the end of the year, I can look back and say we did a good job.
A
Well, let me pick up on that and maybe even arguably attention that you get some organizations between the second and the third, between trust and resilience, sometimes they're complimentary, but in a company like yours and an Airbus beforehand, you've got these hugely complicated, really sensitive systems. And if they go down, not if
B
they get a Data breach.
A
You've talked very passionately about protecting customer data, but if they go down, you could have serious real world consequences in food production, healthcare, pharma and so forth. And I'm just wondering in that whole you've worked and thank you very much for doing this, you've worked with the NCSE community of interest on industrial control systems and you'll be familiar with all the industry totems like my threat model is not your threat model and if you're protecting everything, you're protecting nothing and so forth. So let me ask you one specific sort of provocative thing and I'm mildly obsessed out of them minute. You know, if you look at your risk profile and all the things you have to worry about and you think, well I've got all these data protection laws, but actually some of the systems you have to protect, the implications of those going down are way more important. How on earth do you prioritize?
C
Yeah, I think the reality is we take a risk based approach to everything that we're doing here and for us that consideration that not all systems are equal from the outset and that allows you to really prioritize where you're doing and, and even to things like vulnerability patching. The second part of that is around threat modeling and threat intelligence. Large organizations are able to leverage those type of skills and capability. I'll say it's also very dependent on the maturity of the organization as to how valuable threat modeling and threat intelligence is. Threat intelligence has to be timely and actionable and have situational awareness and context and maybe even a confidence value to it. So for us that's really good and helps us to prioritize and understand and the offensive attacker landscape coming back at us as well. The third part to it really would be about data driven decisions wherever possible. And this is something we're actively working on to give us tooling to drive visibility of our environments and our digital landscapes. It's always worrying as a ciso, I don't know what I don't know and I can't protect what I can't see. So for us those aspects about leveraging automation and potentially in future also leveraging AI to help us drive those data approaches and where we want to go. And one may be slightly controversial, but I always like to think about in our platforms we talk about capabilities that we deliver. I have to admit as an industry we're not very good at consolidating the capabilities or interconnecting the capabilities. All of the vendors like to have their own dashboards. All of the vendors like to sort of say, hey, I specialize in this area and that area. We're seeing an industry trend around consolidation of tools. For example, I'm working to this concept and I've stolen the idea with pride from data scientists who talk about data fabric. I think we should be working towards a security fabric. Every element of the capabilities is interwoven into each other, and that's a design principle. It means if you're sitting in Identity Platform or you're sitting in the SOC or even connectivity Security, you should be thinking in the mindset of how does somebody else in security use my logs, my data? Can I have an API? Or if we're talking about AI energentic, can I develop an MCP or an A2A that allows these security systems to work together automatically? Because that's the only way that we're going to have an ability to defend and do things appropriately in this, this environment. The other one I would say is culture is key. So the strategy around organizational culture is also really, really important.
B
Kevin, it's just fascinating, and we had quite a few guests on this podcast talking about the differences in industrial control and OT space. And one of the quotes I love from earlier in the season was this. We think that many of those environments and their reliance on segregation have ended up kind of 15 to 20 years behind the mainstream computing environment, you know, to the principles you're describing. It's just fascinating. Think about how one drags some of those kicking and screaming up to the standards that we hold the rest of our IT environment, particularly in an organization like yours, where there's just such motive for attackers in, in your threat model, that would have seemed kind of ludicrous to think about kind of 20 years ago. But I'm, I'm going to stop us from detouring further into that. You'll have to come back and talk about it more because that will turn into a whole podcast episode. And I want to get to the main item for today, a AI security strategy. So, opening thoughts. Kevin, where do you think AI has got to in terms of your industry or I suppose, industries, given the scale of the organization, where's it going and what does all of that mean for security, do you think?
C
Yeah, I mean, the obvious thing to say here is this is rapidly evolving. What I knew last week about AI and what was being implemented and the tools that were available is going to be not true by next week week. And I think that rapid pace of change is definitely driving forward a lot of great innovation and a Lot of business direction. The other thing is I think every business in the world is really looking for this as a transformative technology to adopt in the business sense. One thing I do want to pull out though is for me and for us in Bayer, the consideration is that this has to be a business led and IT or digitally enabled initiative, not driven by IT and technology. First you need the use cases that make sense sense. You need to really rapidly think about where AI adds the most value. And in that sense, whatever you do as a company, data is clearly the new gold or the new oil. It's going to underpin all of the systems that are going to leverage AI. Data and security really are some of the enablers for that. So we're trying to think about how to really design and build the right ecosystem around AI. And a term I keep using is is this use case case AI ready. And I think most people would do very well not to think about AI can do this. Think about your environment, your ecosystem, systems thinking and then you'll find some really good use cases for that. AI is also not fire and forget. Right. I don't just deploy a tool and it's AI and then I don't have to think about security. Those things have to be there. What I will say is certainly LLMs have been quite transformative and again we talk about different types of AI. I mean AI has been around for a very long time actually in a lot of industries, including ours for data analytics, neural networks, K means we've been using those to analyze data for a long period of time. That's not new. What is fundamentally changing here is this move towards LLMs and actually the next step into agentic AI that allows this interaction and interface with AI technologies and systems. So that's where I think it's going to be truly transformative for businesses if we get it right. The drive and evolution and the investments that are going into this, especially in the hyperscalers and other companies, I think we're will a transform business but will also transform the consumer space of technology. And I think the final consideration that probably the focus on is an awful lot about, I don't like the term but human capital. How do you make people more efficient by using AI, Whether that's a bot, so whether even some industries are looking at sort of the AI worker assistant type of thing that goes with that as well. For me the conversation is actually more about human intelligence. Kieran said, I'm not controversial and I'm not going to be here, but actually the intelligence part for me of AI is the bit that still needs work. They're definitely artificial.
B
That's a quote.
C
And they're exceptionally good at mimicking humans and finding data. And if the prompt part of it I think is underutilized and to get the best out of AI at the moment, certainly LLMs, it's all about how good you are at crafting prompts and the data sets that it's trawling over. So I think there's a discussion here for companies not only about how to make people more efficient, but how do we leverage human intelligence in this AI world. For me, those are the things that are in the back of my mind that are driving the security strategy that goes with it.
B
It's just fascinating. I admit confirmation bias to much of that view as well. I tended to find myself over the past 12 months saying things like if everyone has AI and you could take that as everyone across every industry, or you could take that as attackers and defenders, I could work to multiple levels. If everyone has AI, the edge once again is human. And to your point on the kind of very artificial and some of these technologies, I think the biggest leap for me is not particularly in the math or the kind of impressive scale of parameter based autocomplete. It is how friendly and accessible much of this seems and how therefore tempting it is to use to get to a first order answer. And what is really interesting is you see some people engaging with it and going, oh, it's done the work for me. And then when you inspect it closer, in many cases it hasn't particularly done it well or better. There are some use cases where Franklin is just trampling the need for humans and you know, automation is eradicating use. There's, there's some of that. The better examples are where you get to this rich prompting and you get to second or third order kind of solution and thinking. So this human creativity and pushing and using it I think is really important. But the ease of use and temptation of AI, the oh, you're so brilliant for asking that question question I think is pushing a lot of people into the kind of lazy, lesser use case versus better. So it's really fascinating having an AI industry that's trying to drive this feeling of I can do everything for you combined with a reality, Kevin, that you and I are articulating, that used aggressively with a lot of thinking, it makes humans better. But we're almost at odds with a lot of what the AI companies are trying to do in that statement, aren't we?
C
I mean, this is where it's going to be fascinating around the business case for companies and what is the business case is very difficult to make when you're talking about enhancing human intelligence with prompts. And I think that's something we need to be better at as an industry is looking at that and saying, okay, how do we get the right skills that we need to enable these aspects of AI? Where does it add efficiency? And even as you said, next order of operations for people in that role, but still gives breadth for this enhanced human intelligence that'll go with it. I will caveat all of that and say that is entirely based on AI and LLMs as it is today. And I revert back to my opening statement that everything I know this week may not be true next week. So somebody may develop something that is truly intelligent, context aware. And again, the ecosystem around it today, it's all about data, data analytics and predicting from the data. They're really good predictive engines. If I had a context aware system, which again, it's not new as a concept, it was around 25 years ago, then suddenly you're starting to talk about something completely different in this world of AI. We're just not there today.
A
So can I tempt you on this caveat to maybe go a bit further and revoke the whole there are no stupid questions attitude in cybersecurity of a telling me, Kieran, that's a really stupid
B
question, but, oh, this is going good, watch out.
A
You've majored on the LLM side and that's where all the use cases are and so on. But you've worked, you currently work for and previously worked for, you know, hugely complicated physical production companies making all sorts of stuff. So could you say a little bit, just even if it's very early days in terms of the thinking about how AI and AI security is actually applying to the physical world rather than just the sort of things that we've been talking about in terms of code, in terms of, you know, generation of advice services and all of that, because I just haven't heard that much about it yet and thought maybe if anyone I know is likely to have thought about it might well have been you.
C
So I think it's still early days. It's kind of embryonic in that world. I mean, you're producing things and elements and again, it depends on the maturity. Some production lines are still very annual actually, and others are fully automated depending on the level of production that you have in the industry you're working in and even the type of aspects that you have and there's a couple of constraints I'll put on this because the first one is some production industries obviously are safety critical. Even the products that you make are safety critical. So you need to have have absolute certainty in decision making, tolerances, quality. And if you're going to bring AI into those environments, you could do it. That said, I don't think there is this split anymore between OT and it. The worlds have been colliding for a decade already.
A
That's really interesting.
C
And some of the companies out there are already having digital twins of the production environment or digital twins of the product. And if you think about it, these systems are data driven and if you have enabled MES environments that are running, helping you to make decisions. The bit of development in AI is actually this link to human interaction. Right? And that's what we're seeing and I've seen in expos and shows digital and OT environments with wearable glasses and wearable tech and smart authentication devices, even that lets you say this is who I am. And then you get a customized screen on the production line. These are not fantasy things. They're coming. And again, it helps drive better production, better production costs, better safety and security standards if you have a good safety and security culture to go with it. So TB would be the answer. But the walls are colliding quickly, quicker than I think people realize.
A
Well, it's better than tell me it was a really stupid question, so thank you.
B
Well, I'm going to follow on with maybe my own stupid question, but I feel I've got to ask it because we've just talked about how elastic all of this is and all the ifs and buts and well, this might happen. So I'm just going to ask you to solve world peace and the complete future of AI for all organizations out there. But Kevin, I just being pragmatic at the moment moment, organizations are obviously struggling with this. They are obviously concerned about the impact that it's going to have from a security perspective. People are worried about their jobs, but you know, most folks are kind of getting on and deploying and then kind of thinking about security a little bit later in most instances. Not a new pattern in our industry for most organizations, should we say? So how should our listeners be thinking about AI security and strategy and policy for the here and now? You know, what advice would you quickly give them to focus on for the next 12 months? Months with the caveat of AGI suddenly turning up being out of scope Here
C
in Bayer, we're looking at this from really four Pillars. The first one is really AI against Bayer. It's attackers already have AI today, and in fact they're using it quite effectively against different organizations. And we're seeing a big evolution in that domain. That means we're having to already adapt our security defenses in certain areas. The first one I would say in there is deepfake. Technology is being used widely by attackers, replicating voice, using phone calls to people, especially more in fraud in security cases. And this is where some of the psychology that we were talking about earlier really helps. Because traditionally you teach the technology of a cyber attack, not the psychology of a cyber attack. And we've moved our systems to say, does the CEO or the CFO or the cso, do they normally call you undertime pressure ask you to break process? So really by teaching the psychology of an attack, it almost limits the need for us to keep retraining constantly every time there's a technology change in these attacks. And quite frankly, if you're still teaching about spelling mistakes or dodgy URLs, these things are all automatically generated with AI. Attackers have learned to spell in many different languages in parallel within like minutes. So that for me is one of the things we're defending against right now. And the second one we're looking at actually is around vulnerability management. One of the things AI is very good at is reverse engineering, writing code. Not necessarily good code, but it's effective to do what the attackers need. So what does the future of vulnerability management look like? If you don't have a day, 24 hours, the attackers can take a vulnerability exploit, exploit it, scale it, deploy it within hours. And we're already seeing that. And by the way, I had this debate about open source software and historically everyone was like, hey, open source software is more secure because it's got the many, many eyes looking at the code and fixing it and patching it. And the bugs would have been found. I said, yes, that's true, but can they keep up with AI either finding those really tricky vulnerabilities in open source code and libraries that nobody found? Or even worse, are you dealing with a bot that's updating open source libraries and embedding super complex obfuscated backdoors in there that you're never going to. That's AI against us. The second pillar for us is really Bayer plus AI. So all companies are leveraging AI third parties. There's a lot of AI tools and technologies around there. So this is really about us making sure we're doing the right awareness, promoting safe use, encouraging people to understand the limitations and the risks of AI governance is super important in here. I would encourage all organizations to have at least a governance council for the use of AI within your business. Not only security, but ethics, compliance, all of those type of aspects that go with it.
A
Well, do you mind if I just butt in there quickly because you've said everybody should have a governance council. What do you think, if anything, organizations like yours should be compelled to do? And given you work in 80 countries, I'm going to use the plural. Where are governments in all of this? And where do you want them to get out of the way and where do you want them to play usefully?
C
I think on the government side, there's a lot of regulation already out there and there's a lot of standards already out there as well. Governments should leverage the existing standards, ISO 27000, NIST, the technical standards, and then kind of harmonize what is best practice for the environment, industry. There's a lot of competing governance in those aspects. So certainly we are asked to show what we're doing in AI around having a council, how are decisions taken, where are things implemented? And that's part of our strategy. And then also we're asked to, and this is kind of the third pillar, we're asked by governments actually to show how we're defending and protecting our own AI models, whether that's the agent, orchestration layer and identity. We're going to see big changes in identity, lifecycle management. We're going to see MCP and A2A type of security controls, DevSecOps for AI. All of that's in there. And then how do we use AI to defend ourselves is also the fourth pillar. But governments will not and cannot keep pace with those evolutionary changes that we're seeing. So the best thing they can do is around how do companies standardize and harmonize on the control plane? How do we continue to have best practice? Because otherwise we'd be getting new regulations every other week around AI.
A
Got it. Okay, well, look, I think to try to summarize, I was working, wondering would I be scared or reassured? And I think probably both, but in the correct order. There's a lot going on, but I think you've brought it to a really pragmatic, practical, scare, strategic. Get the strategy right, get the capabilities right, that framework for government. We can manage this. The one thing I certainly wasn't was bored. And certainly you've got a huge challenge in the years ahead. So thank you for sharing it with us. And we need you to succeed. Because if you go down, then I think we're in quite a lot of trouble. So we're wishing you you well, but we would let you go, except we can't because we've got James's favorite bit of the podcast to do.
B
My favorite bit, Kieran, the 32nd takeaway. I love a 32nd takeaway. Kevin. Look, ultimately this podcast is about lessons for cybersecurity leaders. You've shared a lot of ideas with them already on where they can apply their focus, how they could think about these models, how they can communicate to their kind of fellow business partners. But if you have had just 30 seconds with a cybersecurity leader to help them think about the next couple of years, the decisions they're going to make, something to pay attention to, something to ignore, whatever you like. How would you spend that 30 seconds? What would you advise them on?
C
For me, the attitude that a security leader needs and in fact, all of our organizations. Number one, perpetual learner. The industry's moving so fast. Technology's moving so fast. We're all learning. And it doesn't matter whether you're early careers in this or you're the CISO of a global tens of billions company, you must be a perpetual learner to be able to survive in this industry. The second one is very much linked to that. Get comfortable with change. Change is the only thing that's constant for me. That's definitely true. And my third one, which is kind of my personal advice to people. In a world where our job is constantly a world that's on fire, sometimes it's good just to take a step back and give things some perspective because you can very easily end up in the weeds and there's always something happening and something going on and trust the people you've got. It's a fantastic industry, talented people in the business, but also there's great networks out there like Sans and I'll give you the last plug there as well. Join Commun.
A
Well, that is very kind and thank you. And a great set of takeaways, including actually taking time to think. Absolutely love it. So thank you so much, Kevin. We've really enjoyed having you on. We'll have to get you back on the other 26 issues that we identified in the first few minutes. But I guess apart from all the things James likes to talk about, I think that's probably it. What else do we have to do, James?
B
Well, you know, feedback.
A
Oh, yes, yes.
B
Go on, Kieran, do your thing.
A
Yes, I'll read it out at that advertising speed. Bum bum bum bum. You can email us@cyberleaderspodcastans.org or leave feedback at the podcast site. Tell us what you'd like to hear more of, less of anything you like.
B
Well, within reason it should be slightly related, I suppose. But hey, look, jokes aside, and my moderate flippancy in Kieran's ability to deliver the advertorial section on feedback, we do read it all, and we're always focused on what we can do with security leaders to help you, as security leaders, make life harder for cybercriminals. So if you do have an idea, we'd actually really love to hear about it. Suggested guest topic thing. That's Keeping up at Night. But anyway, with that, thank you for listening.
A
Thank you for listening and keep cybering. So, from me, Kieran Martin, and me,
B
James Line, it's goodbye and may the AI Overlords be kind to us.
C
Sam.
Guest: Dr. Kevin Jones, Group CISO of Bayer
Hosts: Kieran Martin & James Lyne, SANS Institute
Release Date: May 22, 2026
This episode of Cyber Leaders delves deep into the realities of cybersecurity leadership in one of the world’s largest and most complex life sciences conglomerates. Dr. Kevin Jones, Group CISO at Bayer (90,000 employees, 80 countries), shares his rich experiences, strategies for large-scale cyber risk management, AI security, the human and cultural dimensions of security, and practical leadership advice for CISOs. The conversation balances big-picture thinking with actionable approaches for both large and smaller organizations, highlighting people, process, technology—and above all, learning and adaptability—as the foundations of resilience.
(Start–11:37)
Early entry into the field:
Academic & industry blend:
Human-centric & multidisciplinary approach:
"Even as the CISO of a company, you never stop learning... Deep technical conversations one minute, conversations with governments the next..."
— Dr. Kevin Jones (08:40)
(11:37–14:41)
Human factors in security:
Cyber Innovation Hubs:
ICS security history:
(14:41–20:06)
Scale is both challenge and asset:
Platform-based security:
People as differentiator:
"Every company is a target either because of what the company is, what the company does, who a company is a supply chain to, or just because."
— Dr. Kevin Jones (15:46)
(20:06–22:01)
Communicating cybersecurity to the board:
Outcome-focused language:
(22:01–26:24)
Risk-based approach rules:
Threat intelligence maturity:
Data-driven security:
Security fabric vision:
Culture is key:
(25:19–26:24)
(26:24–37:57)
AI is business-led, not tech-led:
Data as foundation:
Transformative shift to LLMs & agentic AI:
Human intelligence & creativity:
"The intelligence part for me of AI is the bit that still needs work. They're definitely artificial."
— Dr. Kevin Jones (29:07)
"If everyone has AI... the edge once again is human."
— James Lyne (29:36)
Rapid evolution, perpetual learning:
AI in the physical world (manufacturing, pharma, etc.):
(35:27–39:15)
AI Against You:
AI Plus You / Third-party AI:
Protecting Your Own AI:
Using AI Defensively:
(40:29–41:19)
On the role of people:
"...technology's moving so fast... but it's a fantastic industry, talented people in the business... Trust the people you've got."
— Dr. Kevin Jones (40:49)
On integrating psychology into security:
"Traditionally you teach the technology of a cyber attack, not the psychology of a cyber attack."
— Dr. Kevin Jones (35:55)
On legacy OT:
"I don't think there is this split anymore between OT and IT. The worlds have been colliding for a decade already."
— Dr. Kevin Jones (33:44)
On AI readiness:
"Think about your environment, your ecosystem, systems thinking—and then you'll find some really good use cases for that. AI is also not fire and forget."
— Dr. Kevin Jones (27:28)