Whether they get explicit approval or not, security teams will leverage generative AI to combat cyber threats. As organizations explore generative AI applications, they must balance innovation with privacy protection to avoid potential misuse of sensitive information.
To gain a deeper understanding into this topic, VMblog spoke with industry expert, Mike Nichols, VP of Product Management at Elastic Security.
VMblog: When generative AI first entered the spotlight last year, what excited you the most and concerned you the most?
Mike Nichols: I’ve seen a lot of potential for Generative AI and we’ve built an infrastructure and the tools for using it within our organization and enabling our customers to take advantage of it. But today, I’m especially excited about the use of AI assistants in IT security and observability. Our AI Assistants leverage proprietary data, a range of LLMs and the power of the Elasticsearch Relevance Engine (ESRE) to help businesses create domain-specific applications that enable users to perform skilled tasks, no matter what their individual skill level might be.
In the area of security, for example, the Elastic AI Assistant allows users without deep security expertise to use natural language to easily interact with the Elastic Security solution for tasks such as alert investigation, incident response and query generation or conversion. It’s a tremendous leap forward in the ability of AI assistants to simplify and accelerate security processes, and it’s just the beginning.
Similarly for observability, generative AI will help improve troubleshooting processes by connecting different telemetry and provide the interactive ability to get automated explanations for information that is not easily understood, leading to better root cause analysis and faster problem resolution. Our observability-focused AI Assistant lets users quickly look up the meaning of log message details and find related messages. It can also explain in plain English an error or stack trace in an APM solution and suggest remediation.
While the potential is unlimited, we – and I think most enterprises – are concerned about how data will be protected and how we can ensure that the answers we get are accurate and beneficial.
VMblog: In your opinion, has the tech industry done its due diligence in prioritizing security in generative AI innovation? What else can be done?
Nichols: Not yet. We’ve seen this before, whether it’s access to the internet, to SaaS tools, to the cloud. The promise of the technology encourages the more daring to move forward quickly, while the risks prompt others to ban the usage. Most companies take a slower approach but don’t always know what the best practices are.
In the end, it’s up to each company to do its own due diligence regarding what the current state of AI technology could mean for its business practices and customers. Developing centers of excellence to build the required understanding and expertise, and then set proper guardrails will be key for many companies.
In the future I expect to see organizations take on the responsibility of establishing trusted standards and best practices that will help any company implement generative AI the right way.
VMblog: What are the most promising implications of generative AI for enterprises deploying it internally for security purposes or infusing it into their offerings?
Nichols: Generative AI will enable cybersecurity operations teams, even those who lack advanced security expertise, to interact with their security platform using natural language for tasks such as alert investigation, incident response, and query generation or conversion – with responses tailored to the role and level of expertise of the team member. For many companies, this will mean significantly better overall security at less cost, and help to fill the growing cybersecurity skills gap that has impacted the industry.
Just a handful of examples of the type of practical and easily consumable information that generative AI can provide for security teams include alert summarizations that give detailed descriptions of why an alert was triggered and recommended steps to triage and remediate the attack; workflow suggestions, including step-by-step guides for accomplishing tasks such as adding an alert exception or creating a custom dashboard; and agent integration advice for users who are unfamiliar with how to collect the information they need. More generally, generative AI solutions can help enterprises fight Shadow AI – when AI applications are implemented or used without knowledge or control of IT or security teams – which has become a growing security concern.
Best of all, companies and individual users will be able to add their own prompts to support workflows that work best for them – and with every conversation with the model, the system gets smarter.
VMblog: How are you and other key team leaders at Elastic collaborating to securely and efficiently implement generative AI across the business? Can you give us an example of what that collaboration looks like?
Nichols: We have multiple examples of collaboration across Elastic on generative AI. We recently held an internal ‘hack-a-thon’ to develop new use cases for generative AI within our own business. One of the winning entries was a collaboration between our engineering and sales teams that will help sales connect faster and better with prospects and customers. Another example is the Security and Observability teams collaborating on the Elastic AI Assistant and then fine-tuning it for our respective audiences.
VMblog: What is your advice for security leaders who are looking to embrace generative AI but fear the security risks it presents?
Nichols: As security leaders, we know the business needs us to be enablers versus the police, and not embracing generative AI will simply lead to shadow AI. We’ve seen over and over again that prohibited technologies will be used if they are seen as mostly beneficial. Generative AI is no different. We must embrace generative AI while still protecting the organization.
A key concern around embracing generative AI is how to maintain control of data. It’s just too easy to accidentally send private information to a public LLM. Protecting data means enabling generative AI with strong controls through trusted solutions, and to do this, security teams need to become familiar with the CIA triad established through the US National Institute of Standards and Technology. When applied to generative AI, this means three things.
Confidentiality – Ensuring the LLMs are hosted either locally within the organization or by a trusted vendor that explicitly ensures the privacy of interactions with the LLM. At Elastic, for example, we chose to first partner with Microsoft Azure OpenAI because of its rigid focus on customer data and privacy. Data sent to the LLM – whether as questions, prompts, or context – will not be used in future pre-training or fine-tuning of new models. Further, it’s critical to have complete transparency. Everything sent to an LLM must be shown to the user. But even this isn’t enough, which is why Elastic also enables admin-controlled context window anonymization.
Integrity – Generative AI is flawed and can provide answers that are incorrect or misleading. So, in addition to ensuring the integrity and security of data, companies must ensure that generative AI answers are not blindly followed. This is critical. Generative AI should never be thought of as a way to reduce the need for human intelligence. No one understands the impact on the business better than the analysts, so while Generative AI can speed up human processes, users must still be responsible for all decisions.
Availability – The technology must be truly usable and benefit the organization. This includes the ability to ensure auditing and compliance with data and cybersecurity policies. Over the longer term, the ideal way to do this is to keep all data local. I expect that as LLMs get smaller over time via distillation and quantization techniques – especially open-source models – this will become a practical approach.
VMblog: What is your vision for the future of generative AI within the enterprise for the next year? Next five years?
Nichols: In the short term, organizations will have some resistance or reluctance to use AI. Some folks are debating how much of a dependency we might be creating for our employees on AI. This is the same resistance folks had around calculators or even spell check features. Eventually, society embraced these technological advances and adapted to ensure we were still teaching students and testing them to ensure their math and spelling skills were adequate.
In the next 1 to 2 years, we expect more customers to be leveraging generative AI for additional use cases to increase their productivity. We also think there will be a big increase in the knowledge base of LLMs as more information is out there for the LLMs to learn from. We expect the models to drastically improve over time. In five years, AI will be so entrenched in our lives that it won’t be obvious which components are AI.
##






