Is the cybersecurity industry repeating the same mistakes with prompt injection that it made with buffer overflows decades ago? As attackers iterate through 50 to 60 prompt filter bypasses daily, attempting to artificially separate instruction from data is becoming a futile effort.
In this episode, Ashish sits down with Cezary Piekarski, Group CISO of Standard Chartered. Cezary shares his techno-optimist view on how AI will ultimately benefit defenders, while also unpacking the hard realities of securing an enterprise that ingests 50-plus terabytes of observable data every single day.
He explains why reactive security operations are dead, why User Behavior Analytics (UBA) often fails at scale due to stochastic human behavior, and why deception technology must be built directly into your ecosystem to actually work.
Cezary shares his thoughts on executive communication, detailing a proven three-step framework for explaining complex AI risks to a board of directors without relying on fear-mongering.
Finally, we explore why the tension between AI data hunger and user privacy is largely a "fake dilemma" for security teams.
Questions:
00:00 Introduction: The Futility of Prompt Filters & AI Attack Evolutions
02:30 Cezary Piekarski’s Background and Role at Standard Chartered
03:30 What "Security as a Business Enabler" Actually Means
06:30 The Techno-Optimist View of AI in Cybersecurity
08:50 Why Reactive Security and Manual Triage Are Dead at 50TB/Day
11:30 Doing Deception Technology Right (No More "Surplus Bug" Buying)
15:20 The Flaws of UBA and Behavioral Anomaly Detection
22:30 The Buffer Overflow Analogy: Why Prompt Injection Needs an Architectural Fix
27:30 Under-Discussed Threats: Image-Based Prompt Injection & Data Poisoning
30:00 A 3-Step Masterclass for Explaining AI Risk to the Board
34:30 Why the AI Privacy vs. Security Debate is a "Fake Dilemma"
Cezary Piekarski: [00:00:00] Fifty, 60 different evolutions of prompt filter bypass attacks and prompt injections and every day. So we spend a lot of time on prompt security. There is lots of efforts to think about how you artificially try to distinguish the instruction piece from the data piece in prompt, but I also see all of those attempts as largely futile at this stage.
Ashish Rajan: We have a category called prompt injection, but we don't know if we have seen all versions of it.
Cezary Piekarski: We, we haven't, right? This, this is still a very evolving, uh, set of attack classes. I'm definitely in a sort of techno optimist camp because I think that the, the benefits emerging out there will outweigh the risks related to exponential growth of the code base that we need to secure.
Cezary Piekarski: When you really think about the scale, if you operate at 50-plus markets, you probably ingest a tune of 50 terabytes of observable data a day plus, and judgment tends to be wrong. There will be lots of data poisoning attacks, especially when, when more [00:01:00] established LLMs will be out there and you're gonna see categories of attacks that will leverage training data poisoning to influence the output of LLMs.
Ashish Rajan: What does security as a business enabler mean in the world of AI, and how does one apply that to a regulated environment like a bank where trust is the most important thing? I had a great conversation with Cezary Piekarski. He is the group CISO of Standard Chartered Bank, and we spoke about things like what does it really mean to be a business enabler from a security perspective?
Ashish Rajan: Where does AI give us overconfidence versus finding a balance between what the reality of running a security program for a regulated environment could be, and how AI could help compound how security could be a business enabler? All that and a lot more in this episode of AI Security Podcast. If you have been watching or listening an episode of AI Security Podcast and have been finding it valuable, I would really appreciate if you take a quick second to hit the subscribe or follow button whichever podcast [00:02:00] platform you listen or watch us on.
Ashish Rajan: We are on Apple, Spotify, LinkedIn, and YouTube, and other podcast platforms as well. I hope you enjoy this episode with Cezary, and I'll talk to you soon. Peace. Hey man, thanks for coming on the show.
Cezary Piekarski: Thanks for having me, Ashish.
Cezary Piekarski: Great to be here.
Ashish Rajan: Maybe to set things at least people to have some background, if you can share a bit about your professional background and where you're, where you are these days, man.
Cezary Piekarski: Yeah, sure. Uh, my name is Cezary Piekarski. I'm group chief information security officer for Standard Chartered Group, which is relatively large financial institution.
Cezary Piekarski: And, uh, I'm finance and, um, and, uh, IT engineering professional by, by education and by trade. I spent probably 25 years doing cybersecurity in various shapes and form across, um, consulting financial industry technology and media and, uh, yeah, enjoying computers. That's essentially what I do.
Ashish Rajan: I mean, enjoying computers is the reason why all of us joined tech as well, so I'm totally relating with that, [00:03:00] and I think I'm pretty sure many people who listen to this would as well. I was maybe starting point, uh, one of the things that I was talking about earlier was around security as a business enabler, like, I think everyone talks about it.
Ashish Rajan: It's probably the most commonly used terms among us executives alo- across the board, and not many people know what it actually means. I mean, if you think about it, it's like, you know, oh, it's just, uh, it's just a phrase people use. But-
Cezary Piekarski: Yeah ...
Ashish Rajan: maybe just to put a bit more depth to it, if you wanna share your opinion on it, how you structure it, what does it mean for business specifically when security's more involved, uh, as part of the team rather than, hey, it's a phrase we use?
Ashish Rajan: What does that mean from your, in your world?
Cezary Piekarski: Yeah, it is, it is probably, like, the most, most overused cliche phrase in, in the security industry. And, and I think it re- it remains, uh, a cliche, uh, until, until you do at least two important things, and those two important things are: the first one [00:04:00] is is a proper engagement and operating model, and this can be different depending on how your organization or your tech organization works.
Cezary Piekarski: Uh, so, you know, if you run engineering squads, it means that you have a, a security person actually embedded within the squad and connected to the security committee through some form of chapter or other construct that gives this sort of vertical alignment across across the organization.
Cezary Piekarski: Or if you are a more traditionally structured organization, there's gonna be your BSOS organization that kind of maps to your businesses or to your specific, uh, to your specific geographies and, and lines of of business. So in other words, the first thing is just the proper engagement model that ensures that the p- people, security professionals are embedded, uh, whether directly or indirectly into the business endeavors of, of the organization.
Cezary Piekarski: And the second important thing to make it real, not just a statement, is is how you create security culture and what kind of champions those security people across the organization [00:05:00] become. And this is, I think, two important mindset shifts almost within this bucket, right? One is- One is actually a set of shared priorities that that, uh, that help security professionals to approach this problem with how we make, how we make the, the business priority happen in a secure way, right?
Cezary Piekarski: And how we set the guardrails, how we ensure that the thing happens. So as far from being a department of no as, as possible. And the second thing within the culture bucket is w-we need to recognize that we do have a different roles, right? So, so sometimes we're gonna disagree with each other and sometimes these disagreements, uh, can get heated if people are very passionate about their jobs.
Cezary Piekarski: But ultimately, there is this shared set of goals and set of responsibilities that we try to deliver, and therefore, this is something that unites us, uh, at some, some level. So to sum it up, I think to make it practical, to make it a real embeddement, there is this operating model piece, and there is a culture piece, and [00:06:00] you need to perfect both of those for, for the system to work.
Ashish Rajan: I love the operating model example specifically also because you... Uh, people talk about the other, other half a lot more, but not the operating model, so I appreciate you sharing this. Maybe to add another layer to this, like these days, you cannot walk into any conversation without anyone mentioning the AI word.
Ashish Rajan: So it's almost like every other conversation that I've had there's an... AI just comes up naturally for some reason. Can we just use AI for that? I wonder what does this... or how does this operational model change with AI giving both sides, I mean, especially with, uh, with the attacker having equal opportunity as a defender with an A- with the same AI capability or, and maybe less restriction, uh, does this model apply for security as a business enabler in the AI context as well?
Cezary Piekarski: Uh, wh-why, why it wouldn't, right? It's, uh, actually, the, the whole discussion around the impact of AI on security it largely boils down to your system of hopes and beliefs at some point in [00:07:00] time, because people kind of throw in all of those arguments around, uh, around, uh, it's gonna kill us, it g- it won't help, it w- will help us, gonna kill us, it will help us.
Cezary Piekarski: And there, there is lots of really good case- cases and, and rational arguments on the both sides. I'm, I actually fall in the sort of techno-optimist, uh, uh, camp. But to your specific, specific point I think u- usage of, um, of LLMs and, and agents in the context of the specific engagement model and enabling organizations to move faster, uh, is, is very clear for security, right?
Cezary Piekarski: Plenty of, plenty of of standards, patterns, design best practices, rule books fit into the context window, and you can make sure that as you design your stuff, this factors in your internal and external prescriptions around how to do things securely.
Ashish Rajan: Yeah.
Cezary Piekarski: And this starts at the sort of design phase for new solutions, but then goes through the whole [00:08:00] ESDLC.
Cezary Piekarski: So, yeah, coming back to the beliefs point, I'm, I'm definitely in a sort of techno-optimist camp because I think that the, the benefits emerging out there will outweigh the risks related to exponential growth of the code base that we need to secure in the long run.
Ashish Rajan: I, I and A, I love that you, uh, are, uh, with, with me on this AI journey as well.
Ashish Rajan: But one... Another thing I wanna add, and maybe this goes back to the organizational thing that you were referring to earlier. Traditionally, a lot of the security folks have been more on the reactive side. Like, I think it's all about, hey, I'm doing detection response. A I'm preempting in a way my, my preemptive defense, for lack of a better word.
Ashish Rajan: Is this model still applicable in an AI world, and how does that change, uh, uh, if it needs to change? 'Cause obviously we spoke about the operational changes, uh, that makes the security as a business enabler. Then we also spoke about how AI could help compound this. Um, what does it mean in, [00:09:00] like, um, and my hope is, because people who would listen or watch this, a lot of them may not be that AI forward today, and for whatever multiple reasons, right?
Ashish Rajan: What is something that you've seen that, A, maybe still works in that preemptive defense world, and what should we be thinking or how we should be thinking about this in this AI world about, hey, should we be more reactive or proactive? What, what's the thinking there for a defense perspective?
Cezary Piekarski: Yeah, I, uh... And, and here's maybe the controversial thing but I don't think that that's actually a sort of change that AI introduced. I think, I think the, um, you know, the, the way people tends to think about how security operation centers works you know, you have a lot of alert and then you mobilize people, and there are, like, people coming to this room, and there, there is, you know, a PowerPoint screen and things are flying on the screen.
Cezary Piekarski: And I don't, I don't think that that's, that's a reality of majority of the security operation teams in, in large institutions for a long time already, right? Because when you really think about the scale, if you operate at y- 50 plus markets and you have relatively [00:10:00] extensive technology footprint, it means that you probably ingest a tune of 50 terabytes of observable data a day plus, right?
Cezary Piekarski: So, so you have this huge stream of, of data and signals that you need to react to, which means that the manual triage and the very detective focused, uh, approach is, is not right for you no matter whether you have AI or, or not, right? And I think, I think the notable shift there will happen, and there will be there, there will be even greater emphasize of just simply designing correctly and making sure that you bake into the significant chunk of your preventative controls, that you perfect them over time so that you have, like, the proper intelligence collection and in- intelligence translation and then intelligence ingestion into your defense systems.
Cezary Piekarski: And y- you can pivot the organization rapidly, right? There's actually a way to measure this, and plenty of people are speaking about time to adapt and how you, how you really quantify your your malleability of the organization. But My point is I think for advanced [00:11:00] organizations with the large technological footprint this trend of moving out of the preventative, or sorry, o- out of detective controls towards the preventative controls happened a long time ago and will only accelerate on the back of accelerate, accelerating threats.
Ashish Rajan: So from a preventative perspective, would you say deception is something you consider as a preventative measure that people have started adopting? 'Cause it's one of those things that it's funny, I, I had a recent conversation on AI Security Podcast about this, how deception is always looked at as a, "Hey, we are a maturity play.
Ashish Rajan: If you have a mature organization, you can do deception." And I see you smiling already, so I'm curious, what's your thoughts on deception, and what, what are some of the examples of prevention that you can share for people?
Cezary Piekarski: Yeah. I th- I think that, uh, so there is a part of, um, the deception as a concept, as a s- control, uh, clearly it, it has a a, a part in the broader defense ecosystem of the large institutions.
Cezary Piekarski: But I think [00:12:00] also the the approach that people taken to implementing deception over years was very much "We run our security program we do controls, and then when we have, like, a surplus money we buy these bugs- ... and, you know, we put these bugs- Yeah, that's right ... we put some breadcrumbs here and there, and we- Yeah
Cezary Piekarski: just kind of hope that something will go... And sometimes it works, right? Don't get me, don't get me wrong.
Ashish Rajan: Yeah, yeah.
Cezary Piekarski: But I th- I think really, uh, there, there are two parts of doing this control right if you want to do it at scale and, and really bear, bear fruits, right? Which is one it needs to be designed into the actual ecosystem, right?
Cezary Piekarski: So you need to, you need to design your, your infrastructure applications with a specific set of, deception controls in mind for deception to be believable, to be genuine, right?
Ashish Rajan: Yeah.
Cezary Piekarski: And, uh, the, the second part is that and there are products out there and there are people experimenting with this.
Cezary Piekarski: It needs to be very adaptable to a specific TTPs that are being used out there. So you almost need to [00:13:00] like design and pivot your deception platform to adopt to some of the adversaries that are out there. And you, y- so when you, when you really embed this well into your incident response process or intelligence collection process, it can bear fruits, especially that, uh, we are already seeing that some of the agentic attack scenarios broadly understood, uh, they have a tendency of walking into this trap, right?
Cezary Piekarski: Mm. Because they don't have this, this instinct of, uh, of, of experienced red teamer on an attacker, which is like something fishy here, right? Yeah, yeah. It's all, it was too easy, right? Like you know this feeling, right? It's-
Ashish Rajan: Yeah, yeah.
Cezary Piekarski: Uh, so I th- I think that there is, there might be a revival of deception platforms but clearly they need to be done in a very different way.
Cezary Piekarski: They need to be designed into the ecosystem to be believable, and they need to be flexible enough to adjust to the TTPs and all specific campaigns that you are seeing out there.
Ashish Rajan: Yeah. I think I love this because I think the conclusion that we got to was pretty much the same as you [00:14:00] what you called out here.
Ashish Rajan: It- it's probably the one of the best things that you can have in your ecosystem to, uh, to, to your point, if it's an honest mistake, it's a good thing it's an honest mistake or it gets picked up, but at least these breadcrumbs that have been left around, uh, give you a clear indicator for, uh, "Hey, someone else is in the network," and that we should probably take an action on.
Ashish Rajan: So I, I love that you shared this, and I, uh, I wanna just double click on this because usually the whole idea behind detection has been that, hey, anomaly detection has been in there for a long time now. People are using AI-based anomaly detection, and usually the an- anomaly detection used to be very signature, pattern based.
Ashish Rajan: "Hey I know the signature of what a heartbleed looks like. I'm just gonna, whatever the vulnerability is, I'll go figure it out, and am I vulnerable or not?" With AI, and I think you mentioned this earlier, and probably the s- the pattern across the industry is [00:15:00] that everyone's trying to automate their security level one.
Ashish Rajan: Everyone's trying to figure out, hey, if I get a vulnerability, can I use AI to investigate that quickly and use anomaly detection in my environment? Where do you see there is a... I won't-- I mean, I don't wanna use the word over-reliance on AI because, uh, I think it does definitely has its moments, like hallucination moments is definitely true even today.
Ashish Rajan: Where do you see AI doing a good job and versus where AI gives you a false sense of confidence, which probably is not the right thing? Is there any thoughts you have on the whole anomaly detection with AI space?
Cezary Piekarski: Kind of coming back to my, my earlier comment around preventative versus detective and this move towards the hard preventative controls that, that I think is critical towards, uh, towards the, the future that is approaching very fast.
Ashish Rajan: Yeah.
Cezary Piekarski: You're, you're gonna always have this outlier of, uh, hey, this is sort of twofold, benign, not benign type of activity, and you need to do something about it, right? And, and- Yeah ... this starts with detection. To the extent possible, [00:16:00] obviously eliminate this type of corner cases because this, uh, includes jud- judgment, and judgment tends to be wrong.
Cezary Piekarski: So try to make it as, as preventative, as defined, as binary within the guardrails as possible. Uh, but if you need to build some form of detective or even worse, behavior-based controls, I, I think they, they need to be built very mindfully, mindfully because everyone who tried to do UAPA at scale which is the same problem, just slightly different context-
Ashish Rajan: Yeah
Cezary Piekarski: Noticed that we are probably less or more stochastic machine than we, we tend to think about behaviors. And, and therefore what usually happens is that people fall into the trap of unusual means means malicious, usual means benign, right? Which- Yeah ... which very frequently is not true in like real, uh, real scenarios.
Cezary Piekarski: And, uh, AI is is only is only em- emphasizing and reinforcing th- this problem at the, at the machine scale, right? Just the same, same concept. So I [00:17:00] would I, I would probably be very intentional about, uh, what you try to do in terms of your, um, outliers detection.
Ashish Rajan: Yeah.
Cezary Piekarski: Um, but it doesn't really neglect the point that, or negate the point that, When you think about, um, speed that, that is already necessary and will be even more necessary in the future there is, uh, not really much alternative to having a fully automated, uh, response and containment capabilities.
Cezary Piekarski: And, uh, plenty of, uh, of our thinking within the organization is how we set the boundaries of of doing this and h- you know, where, where we can in the future enable machine to run the, the, the full containment at the scale that is necessary because there are some predefined trade-offs and decisions that you need to make, including, uh, including trade-offs and decisions around your, uh, around your business.
Cezary Piekarski: Uh, 'cause some of those decisions are not, uh, cost-free.
Ashish Rajan: I, I love this, and I love the fact [00:18:00] that unusual versus usual. I, I, I think a friend of mine used an example I thought very well said as well. Uh, it's like if, if you're trying to be ma- if you're trying to map a human behavior to a pattern, yes, we all have patterns, but I may be drinking the same coffee in the same cafe for, I don't know, three months in a row, but one day I just got over the coffee and I decided to go to another shop.
Ashish Rajan: Is that unusual? Maybe as a human, no, but would AI pick it up as unusual? It would definitely pick it up as, "Oh, that is wrong. You should not do that," and there's be alarm bells going off everywhere for Ashish has decided to go to a new coffee place. Why is that? Why? Is he suddenly, uh, an insider threat award?
Ashish Rajan: I love what you said about the UAB piece as well, 'cause it's, it's, uh, it's us trying to, uh... And I think, um, my, my co-host mentioned this one of the episode as well. One thing, he tried doing the UAB, uh, in one of the companies he was a CISO for, and they figured out that there is no pattern to humans. As much as we like to think there's patterns in a c- in an [00:19:00]organization, I may every morning open a calendar, but one day I open Gmail, suddenly it's an anomaly, and it's like, how is that?
Ashish Rajan: It's like... I, I, I'm s- I see you smiling as well. Do you agree on the human being a pattern versus, uh, harder to... the reason why UAB systems don't, uh, do an effective enough job sometimes?
Cezary Piekarski: Yeah, I think it's a part of the problem, definitely, right? In a sense that uh, when you, um, when you have the obser- ob- observation window that is wide enough, everything becomes the same color, right?
Cezary Piekarski: And, and that's, that that's essentially what happens with UABA, and I think that there is also a certain set of assumptions that, people that like the actual outliers are malicious, right? To my earlier, earlier point, which means that then you end up with thousands of false positives in the process because not, as you said not all, not, not all change of taste when it comes to coffee is something- Yeah, yeah
Cezary Piekarski: malicious, right? So- Yeah. Yeah, I agree, agree with you, but I think it's also [00:20:00] aside of those almost like the intellectual discussions around n- nature of the human behavior, I think that there are more practical problems in the way those technologies are implemented because very frequently systems that are covered with this type of technologies do not have the right telemetry, or this telemetry is too generic to draw meaningful conclusions, and you end up monitoring "Hey, someone is logging in the afternoon, so...
Cezary Piekarski: And that's unusual, so probably this is someone malicious," right? So, so I, I think it's just the breadth of data set-
Ashish Rajan: Mm-hmm ...
Cezary Piekarski: um, is not enough and and potentially when you really think about your control posture on those applications, probably it's, it's better to do the right segregation of duties within the application implement a proper authentication authorization model, uh, and ensure the application is just well designed to be secure instead of trying to make it deliberately unsecure and then overlay some sort of behavioral detection engine on top of it to try to detect outliers.
Cezary Piekarski: I, I think it's just- Oh ... just, again, in the sort of in the microcosm, but this move towards preventative controls and [00:21:00] proper designs, uh, applies, uh, equally.
Ashish Rajan: I, I think you're right because you... Due to what you said as well, even in that example of me changing my coffee place, the, the context is that as a human I enjoy coffee, and if there's the...
Ashish Rajan: Da- cha- ... It's perfectly normal for humans to get over a particular coffee at, after a certain point in time. It could be happen any time. If I don't have the right data set, to go- to what your example was, uh, if I don't have the right data set across all the systems that I've been monitoring across the board- Yeah
Ashish Rajan: I may not have enough context to make the right call about- Yeah ... is this an anomaly or not.
Cezary Piekarski: There, there might be a great, you know, great discount at the other coffee shop, right? Or there might be, you know, you, you might be meeting friend there, or you just changed your taste, right?
Ashish Rajan: Yeah, yeah, yeah. 100%.
Ashish Rajan: It
Cezary Piekarski: happens to us all the time. So, so, and, and this problem when applies to technology just compounds the, the challenges related to behavioral detection. So, yeah, I think that's, that settles pretty much the case. '
Ashish Rajan: Cause I guess do you find, uh, you know, obviously in, in security we talk about a lot of recognizable [00:22:00] threats as well.
Ashish Rajan: So obviously we spoke about the, the UABs, which are like the un- human b- going for a new coffee shop, but there's also some recognizable threats like your buffer overflow is pretty standard, SQL injection, XSS and all of that as well. Yeah. Do- does AI seem to do a better job there then? Or is that also kind of like a mixed bag? You know how we were talking about anomaly detection in terms of the UAB, the behaviors that people have and detecting ano- anomalies with it, where AI to your point, if it doesn't have the right context can't give you a high confidence results for- something that is at fault.
Ashish Rajan: But when it comes to things that are known, uh, recognizable classes like your buffer overflow- Yeah ... or XSS and stuff as well. Yeah,
Ashish Rajan: does AI, does, uh, uh, i- what's your opinion on how AI behaves over there?
Cezary Piekarski: Yeah, I th- I think it's not, it's not really an opinion. It's, uh, empirically confirmed that, that frontier models or, and not frontier models are, uh, are robust in identifying known classes of, uh, of vulnerabilities.
Cezary Piekarski: And, uh, and this applies [00:23:00] to a sort of new vulnerability discovery as particularly it applies to for example, reverse engineering vulnerabilities from binaries, right? So, so situations in which you have a sort of be- before patch and post-patch binary, and you diff those two and, and you derive vulnerability that was addressed by patch.
Cezary Piekarski: Uh, and yeah, so I, I don't think really it's a matter of my opinion. That's something that is happening already there. But your analogy to buffer overflow it, um- It reminds me of a slightly broader, broader observation that I wanted to share- Yeah ... which is, uh, you know, I'm old enough to remember, uh, smashing the stack for fun, fun and profit and- Yeah
Cezary Piekarski: How the buffer overflow craze started. And when I think about AI security, there is lots of parallels to the way we think about securing AI and what happens, uh, in the early stages of of buffer overflows because, uh, when, when the whole thing about just, you know, the memory management started people spent a lot of time trying [00:24:00] to protect the stack- Yeah
Cezary Piekarski: uh, and, and filter the input to, uh, to your program not to overwrite the segments of the memory that were steering the execution. And this attempt was actually futile in majority of the programming languages. And we kept improving those mechanisms and we keep- kept failing.
Cezary Piekarski: And, uh, the problem faded away when we moved towards a slightly different approach to the way we design CPUs and we, we introduced the memory management in the CPU and how the kernels are built on top of this architecture of CPUs and this, this reduced the exposure to a certain attack passes in the specific architectures.
Cezary Piekarski: And I think the way we think now about the security of LLMs to some extent it follows a very similar challenges. So we spend a lot of time on prompt security.
Ashish Rajan: Yeah.
Cezary Piekarski: And, uh, there is lots of efforts to think about how you artificially try to distinguish the instruction piece from the data piece in prompt and [00:25:00] how classifiers works and how they...
Cezary Piekarski: and, uh, but I, I also see all of those attempts as largely futile at this stage. Uh, so it, it might be that there is something much more deeper into the way LLMs operate that we're required to change for them to be secure. And, uh, and in this sense, this analogy to buffer overflows, I think I think rings the bell, I guess.
Cezary Piekarski: Ah,
Ashish Rajan: yeah, I mean, and, um, thank you for sharing that 'cause, uh, funny enough, my story with buffer overflow was I just felt overwhelmed when I was trying to learn buffer overflow. The whole XSS and every- or not XSS, the, whatever the language, low-level language used to be. That was-- I didn't realize how scary it could be, but I, that, that day I knew, the m- the first day I tried to develop a malware, and I spent like eight hours on it, I dozed off after a while, and I'm like, "There is no way I can build a career on this."
Ashish Rajan: So I switched gears and went to another side of cybersecurity. So I'm like I respect people who went through the, the toil of a buffer overflow. And to your point, maybe it's a good thing that it became [00:26:00] in-integrated into how systems were built. And, uh, just on the thing that you mentioned about the, does there needs to be a change in the way the models or we work with models that could pr-potentially make this better?
Ashish Rajan: 'Cause I almost feel at this point in time, there is no set benchmark for frontier models or what security standard, because they are evolving, we are evolving with them. There is no set of, hey, th- now we know what buff... We don't, we have a category called prompt injection, but we don't know if we have seen all versions of it.
Ashish Rajan: Would you agree? Is that where the analogy comes in from as well?
Cezary Piekarski: We, we haven't, right? This is still a very evolving, uh, set of attack classes and if you, if you, if, if you, if you use X or X Twitter, uh- Yeah ... extensively, right, it's, it's probably you have, you have 50, 60 different evolutions of, uh, pr- prompt filter bypass attacks, and prompt injections, and this and that every day.
Ashish Rajan: Yeah.
Cezary Piekarski: Uh, so I th- I think it's just... But that's, you know, any other, any new technology, right? Um, uh, it, it [00:27:00] ha- inherits a similar wave of initial happy hacking, um- Yeah ... that, that is happening. And, uh, and the security controls do emerge as, as you progress through through, through technology maturity.
Cezary Piekarski: I think the real challenge now is that the appetite for industrialization of some of, uh, some of those technologies is huge for a good reason. Mm-hmm ... and therefore when you navigate this journey of of building use cases in a responsible way, you need to be very clear about the limitations of your controls, but also about the limitations that you might not be cognizant of.
Cezary Piekarski: So, so those are unknown unknowns in the process. And, and I think responsible organizations needs to make a buffer for- Mm ... for those in, in, in the way they think about about controls around around
Ashish Rajan: AI. Do you find there... And I think, uh, I'm glad you mentioned this, 'cause one of the things that I've been curious about is Manas, what are some of the under-discussed AI attacks?
Ashish Rajan: Like, obviously prompt injection seems to be right up there, like [00:28:00] the top of the tree, everyone just starts off with prompt injection because that's the key that people go for. What is something that you feel as an AI attack that p- the industry should talk more about that probably is not being discussed enough?
Cezary Piekarski: Yeah. I actually think that those, this, there is still a, a lots of underappreciation for prompt, prompting, prompt injection, and i- in, in general everything that is related to input filtering. And the reason for this underappreciation, despite the spotlight, is that, There is this, I think a certain naiveté in a f- in, in, in the way people think about it is that, that by creating a better and better filters you can, you can protect, uh, the model from, uh, from this category of attacks.
Cezary Piekarski: I, I don't think that this is actually what happens. And and we just recently seen an examples of people using different formats, right? Yeah. Not only, you know, translating from ASCII base 64 and whatever, but using, for example, pictures to do- Yeah, yeah. Images are actually a thing. Yeah, yeah
Cezary Piekarski: Pro- prompt injection.
Ashish Rajan: Yeah.
Cezary Piekarski: And, [00:29:00] uh, and I think it, it will only evolve because of the, uh, richness of the communication channels that are available to interact with, uh, with, uh, large language models and with the harnesses.
Ashish Rajan: Yeah.
Cezary Piekarski: Because of this, it's gonna be extremely difficult to build a robust, robust filters that will help you to prevent this type of, uh, this type of attacks.
Cezary Piekarski: And the second category that I think simply have a, have a longer lead time but-- and therefore it's not so popular yet, but I think that there will be lots of data poisoning attacks especially when, when more established LLMs will be out there, and you're gonna see see categories of attacks in this space related to brand infringement to social engineering and to other broader categories of attacks that will leverage training data poisoning to influence the, the output of LLMs.
Ashish Rajan: Yeah. And I guess, do you find, um... 'Cause [00:30:00] I-- Has this changed the way in people should report about risks to the board as well? 'Cause there, there is a certain sense of, we got this, th- that, you know, that's like, uh, it's like-- 'cause it almost feels like because of the under-representation or under rep- uh, or not enough discussion about AI risk, uh, also means that there's not much education about this in the broader ecosystem.
Ashish Rajan: Do you find, uh, and this is more for people who are listening or watching this episode, what have you fi- found is a better way to explain AI security risk to the, the broader ecosystem, whether it's other executives or boards and stuff where, where you feel that... 'Cause obviously security to where we started the conversation, security as a business enabler, one of the pillars for that is to be able to explain the role of security to the broader ecosystem as well.
Ashish Rajan: Do you, do you find that-- what have you found as the best way to explain AI security? 'Cause to your point, we've been talking about this, like prompt injection and like we spoke about UA, how difficult and complex this thing is. [00:31:00] So what have you learned that you can probably share with other people that is a good way to explain that to the broader, wider executives in an organization?
Cezary Piekarski: A great, great question. And, uh, I, I had, I have a privilege of interacting with boards and, and senior executive teams for many year, first-- many years, first in my consulting role and, and then in my, uh, in, in my industry appointments. And w-what I think is a, is a common theme across, not only AI, but more broadly across technology change, is that to communicate effectively you need to use a mix of, uh, at least three components.
Cezary Piekarski: Uh, you need to use a mix of generic education that is not really risk-focused. It's more about simply how technology works. And just imagine this for a moment, right? Like you and me, we are getting paid to stay on top of technology. Yeah,
Ashish Rajan: yeah.
Cezary Piekarski: And people who sit on board, uh, they need to have a very broad and both broad and deep understanding of so many areas: [00:32:00]accounting, risk, governance, technology.
Cezary Piekarski: So it's, for them, it's extremely difficult to stay on top of some of the technology changes. So creating a space to have a general discussion about technology evolution with diverse points of view being brought to the table with people who disagree with you also speaking there is, is the first important ingredient.
Cezary Piekarski: The second one Is a meaningful direct connection with those senior executives or board members. In a sense, after you educate, you need to give space, preferably just, just a small one-to-one space to have a meaningful discussion about any follow-up questions they may have, any areas that they think requires more spotlight any, any doubts they have or any areas of confusion that emerged as, as they acquire this new knowledge.
Cezary Piekarski: And only when you have those two in place you can talk about risk. And this is the moment when you have almost like risk [00:33:00]committees, where you have your metrics where you can have an educated discussion about what it really means and what kind of trade-offs we are taking as an organization. And from my experience, people tend to neglect those first two.
Cezary Piekarski: So they focus only on, on risk, and there is a CISO coming to the board and saying, "Oh, you know, the number of incidents this, and the number of incidents that, and buffer overflow here and other buffer overflow there," right? It never works because- Yeah ... people don't have the taxonomy and context but also they simply don't have the wealth of diverse perspectives that help them to judge whether, your SLA for vulnerability remediation makes sense or not.
Cezary Piekarski: Uh, so make sure that you form those long-term relationship and that you create this education program that help people to stay on top of technology. Yeah. I'm actually very lucky I, I get to work with the board and executive team that is very technology-savvy and very risk-focused.
Cezary Piekarski: So, uh, so those are always great discussions. [00:34:00]
Ashish Rajan: Uh, that's great to hear as well. I, I think definitely great insights there for building the connection before you even start. For, for lack of a better word, coming across as someone who's just too technically smart, but maybe not that business savvy to explain that and translate that as well.
Ashish Rajan: So that's a great skill for all of us to have, for sure. Obviously, uh, one of the questions that 'cause I, I end up working with a lot of people in the financial industry, primarily the US and the UK, and one thing that I keep coming across quite often, especially with this AI wave, has been the question of, uh, more data for security versus less data for privacy is, is a que-question that comes across quite often in terms of AI being this data hungry beast that you're trying to feed every day, while as a security leader trying to balance the trust that people have put on, uh, the institution.
Ashish Rajan: W-what's been something that has worked for you and you can share with other people, uh, in that space on how to kind of re- either resolve it or find the balance for it, uh, where it's a win-win for both sides?
Cezary Piekarski: I think [00:35:00] to some extent this is fake dilemma. Uh, I, I don't think that's really you know, the, the or type of situation because for, for your security mechanisms to be effective and deliver on, on, on trust, right?
Cezary Piekarski: Remember, we, we are, we are in a trust business, right? Yeah, yeah. Financial institutions. People come to financial institutions because their, their assets are safer- That's right ... with, with us than they are if, you know, you put them under a pillow, right? So-
Ashish Rajan: Yeah ...
Cezary Piekarski: so that's non-negotiable part of the business we do.
Cezary Piekarski: And that's the part of the business that we treat with, uh, absolute seriousness. So when you think about what is needed to protect organization like this, there can be trade-off. But the good news is that to deliver on, on our obligation, to deliver on our mission, we actually do not need so much PIIs and data that are impacting people's privacy because what is really important from the security point [00:36:00] of view is, is rather the, the metadata the surroundings, the observability that you can bring to understand what is happening rather than the specifics of the individuals, uh, or groups that, that you protect.
Cezary Piekarski: So, so I experienced in my life, in my previous professional roles decisions related to scope of oversight that we want to have and there are certain guidelines on how do you tackle this type of processes. But I think this is a very rare situation and very rare problem. Uh, in majority, significant majority of cases, you can address your security requirements without, um, uh, compromising on the privacy regulations, uh, and privacy obligations and privacy mission that that you have.
Ashish Rajan: That's well said, man. I mean, those are most of the questions that I had, but I, I feel like I can talk to you for hours, so may have to book like a part two someday as well. Uh, where can people- Let's do so ... uh, connect with you and get to know more about some of the things that you're I guess sharing publicly, or where can people connect with you?
Ashish Rajan: LinkedIn or what's p- usually the, the [00:37:00] hangout place for you on the internet?
Cezary Piekarski: I, I don't really hang out on internet, but I do have a LinkedIn profile.
Ashish Rajan: Unfortunately- And I do- ... all of us have a LinkedIn profile, even if you don't hang out there.
Cezary Piekarski: Yeah. And I do what Shannon tells me I need to do, so yeah.
Cezary Piekarski: That's-
Ashish Rajan: Fair. Uh, I'll, I'll put, I'll put the put your LinkedIn URL in there as well. But dude- Thanks ... thank you so much for coming on AI Security Podcast as well. Thank you, and I enjoyed the discussion. I look forward to having you again, man. It'll be pretty awesome. Thank you so much for this.
Cezary Piekarski: Thank you.
Cezary Piekarski: And, uh, it was great to be here. Thanks for all of the, all of the questions. Thank you. And have a great afternoon ahead of you. Thank you.
Ashish Rajan: Thank you for watching or listening to that episode of AI Security Podcast. This was brought to you by Techriot.io. If you wanna hear or watch more episodes of AI Security, check that out on aisecuritypodcast.com.
Ashish Rajan: And in case you are interested in learning more about cloud security, you should check out our sister podcast called Cloud Security Podcast, which is available on cloudsecuritypodcast.tv. Thank you for tuning in, and I'll see you in the next episode. Peace.














.jpg)

.jpg)


.jpg)
.jpg)