International Business Machines Corporation (IBM) Earnings Call Transcript & Summary
October 3, 2024
Earnings Call Speaker Segments
John Velisaris
executiveHello, everybody. Welcome to the IBM Cybersecurity Services webinar today. We're going to be talking about using AI and automation in security to help mitigate the impact of data breaches as well as talking about -- well, let me get to the agenda slide, and I'll cover what we're going to cover today. But first, let me introduce myself. I'm John Velisaris. I'm in product management within the cybersecurity services threat management portfolio. And Chris is with me today. Chris, I'll let you give a shout out and introduce yourself.
Chris Thompson
executiveHey, Chris Thompson. I lead the X-Force Red team and part of that is to see if [Audio Gap] models and all that stuff. So excited to speak with you all today.
John Velisaris
executiveVery cool. So let me break down what we're going to cover. They always say, tell them what you're going to tell them before you tell them, right? So we're going to talk about AI, the intersection of AI and cybersecurity. There's 2 sides to every coin, right? So there's good things that can come of it. And of course, it's an opportunity for the bad guys as well, too. We're going to talk specifically about what we at IBM are doing to leverage AI in the security discipline as well as some other automation that we're coupling with AI. So we'll show you and talk about some of those assets that we're building, not only through IBM security research, but also with our clients that we're co-creating together as we explore what generative AI can do for security practitioners. Then Chris, with all his deep knowledge and expertise, is going to cover the security concerns around AI and what you should be doing to make sure that AI that's in your business covers the full scope of security concerns there from the model, the data, the infrastructure, end-to-end. And so Chris will cover that with much more depth. And then, obviously, there's -- as part of the platform here, there's a Q&A capability. [Operator Instructions] We will try and catch those as we go along. At the end, we'll circle back. If there were some top questions or common questions, maybe Chris and I will try and verbally expand on those [Audio Gap] IBM Institute for Business Value. And so yes, companies are using them for business process automation. Some are using virtual assistants, generative AI, conversational virtual assistants for things like customer service. There's fraud detection. But 29% of those that we polled and responded said that they're using AI at that intersection of security. And more specifically, we got a lot of responses back talking about threat detection, which you guys know, if you're a security practitioner, we've been using things like machine learning to do threat detection for years now. So anyway, the AI is being used across, and that's another reason why Chris needs to talk about how to secure that AI because it's more than just at the intersection of security. So business leaders are anticipating financial returns. And so I think from a business perspective, we've seen a lot of different approaches in our client base to AI. Some are saying, "Look, I don't want to build a data science team. I don't want to own an AI pipeline. I'm going to consume AI as a SaaS." [Audio Gap] Look, we need to take those foundational AI capabilities and build discrete capabilities ourselves, deliver those. And obviously, and Chris is going to cover some of this, as you move across those architectures, as the business says, yes, we expect a very large ROI coming from our AI capability that we're investing in, the risk increases as well, too, right, as with many things. So when you own everything end to end as opposed to consuming it SaaS, your risk profile changes. But those returns can stack up, and that's why the business is progressing on expanding AI capabilities throughout the enterprise. And we're seeing that. We're seeing with our clients that multiple functions -- that first slide that I covered, multiple functions are co-sharing AI capabilities, generative AI capabilities to build integrated business processes inside companies and serve their customers. So you know, and this is -- since AI -- a lot of AI is about data, we figured we'd grab the cost of the data breach report. You guys know, hopefully, that every year, IBM produces the cost of the data breach report, and it's out. If you missed it, it's out. You can go to ibm.com and download the cost of the data breach report from this year. But in lieu of the entire report, presenting the entire report to you today, let me cover some of the highlights [Audio Gap]
Chris Thompson
executiveJohn, we're having quite a few audio issues on your side. You might want to go off video just to save bandwidth when you bring up the slides, just because it's pausing every couple of minutes here.
John Velisaris
executiveOh, is it, Chris? Okay. Great. Let me see if I can -- how can I turn off my video? Gosh. I'm sorry, guys.
Chris Thompson
executiveIt's bottom right if you hover over the screen. While John gets his audio sorted out, we'll just...
John Velisaris
executiveChris, do you want to hop to Section 3 and do your part, and then we'll double back to me while I work on the audio and video issue?
Chris Thompson
executiveYes. Sounds good. You might need to reboot or whatnot, so let me just share here. Thanks for the patience, folks. All right. There you go. Let me get the slide show going here and swap those. All right. So John is going to work on his audio. I'm going to focus on the later part of the presentation around offensive testing of AI and where automation comes in or manual testing comes in. First, some background. The X-Force Red team has a lot of experience around offensive security. We spoke at Black Hat 6 times in the last year alone. And we're constantly researching emerging technology and the impact to the attack surface of the organization and whatnot. That's no different when we talk about AI. And we've been leveraging AI internally as well as developing extensive tooling and methodology for testing of AI over the years. And typically, what we see in customer environments, as customers start to leverage AI and they start to slap AI on every traditional and new application, this is typically what it looks like. So you have, on the far left, an MLSecOps pipeline. And that could be something as basic as just an existing model that hasn't been tuned that you're just leveraging a little retrievable augmented generation to call internal documents like an internal knowledge base, for example, or it could be something a little more complex, where you've tuned an existing model to focus it on your enterprise knowledge and the area that the app is focused on. So if it's a banking application, limiting its responses and its focus to calling your back-end APIs to make certain transactions happen, or could be something as complex as a model training and tuning environment where you're building your own small 1B, 3B models and leveraging your infrastructure for training. But typically, these MLSecOps environments, they've been readily connected into enterprise data lakes and more sensitive data sets, so financial data, customer data, internal intellectual property. They can reference more complex or sensitive procedures in terms of if it's a banking application, how the procedures for setting up a new account or typically lots of different enterprise data sets that get called. And it doesn't necessarily have to be a customer-facing application. By any means, it could be an internal application, which is intended to automate some HR functionality or a help desk functionality. And the second piece of the pie is we have the model itself. So the model, whether it's a Llama model or a custom model or an OpenAI model, how do we ensure that the model itself is -- doesn't have vulnerabilities within it and how do we test it for safety and security. One key thing I missed on the MLSecOps pipeline is typically, data scientists are downloading a couple hundred models throughout the course of the year to evaluate their effectiveness and their efficiency and their fit for the solution. So normally, they'd be downloading these models from sources such as Hugging Face, and there's always the potential that somebody backdoors a model, and a malicious model could be detonated in this environment. So I want to make sure that we're scanning those models for malware automatically, but we're not fully reliant on model scanning to be that silver bullet because just like any antivirus or EDR, there's going to be a lot of false negatives and misses. And we want to make sure that, that environment is prepared and ready for the event that the malware detonates within it. So how do we ensure that the incident responders know where the logs are? How do we ensure that we've locked down that environment properly? And I'll talk about -- a lot more about that in a minute. Beyond model safety and security testing for prompt injection and the ability to produce content based on copyrighted works or worrying specifically about bias, which is extremely important when it comes to any application, especially those that make decisions based potentially on somebody's marital status, based on their ethnicity, based on any number of sensitive data sets that should not play into a factor if somebody gets approved for a loan, for example. So very important that, that safety and that model ethics testing is performed. Third piece is these platforms that these models are being run on top of with generative applications built on top of them. So think of your big ML, your Azure ML, your SageMakers, your watsonx. How do we ensure that the platform has been configured securely by your team or by a third party? And how do we make sure that the connections between that AI-as-a-service platform and your internal data lakes and any internal APIs that are being called has been provisioned securely, the identity and access management for that cloud environment is properly configured? All those different expanded attack surfaces that come up rolling out a new cloud solution essentially. And then the -- how do we ensure that the gen AI apps or ML apps that are built on top of these platforms leveraging those models are secured? And how do we know that these models or these applications are securely calling APIs? How do we ensure that they're not subject to prompt injection, which could result in code execution in your back-end platforms? All that sort of thing. So these are the areas that we're most concerned about with AI. Typically, when you hear about AI red teaming, it's focused purely on number two here, the safety and security testing of the model. But in reality, there's a much wider ecosystem that we need to consider, especially those models being run in a production application. So securing the MLSecOps pipeline. How do we ensure that, that environment is secure? So in addition to the model training and tuning tools, how do we ensure the deployment orchestrators are secure? How do we see that logging is in place? All that sort of thing. So we can take into consideration a number of frameworks that have been started like the OAuth and MITRE ATLAS and whatnot. OAuth has got 2 projects specific to LLMs and ML, for example. And they've started to categorize some of these attacks. But obviously, as we know with MITRE, MITRE attack and any great industry effort, there's going to be gaps in how the attack actually happens practically at the procedural level. There's going to be a lot of solutions that aren't just limited to, say, supply chain attacks. So when we're testing an MLSecOps pipeline as a red team, we're focused on it much like any DevOps pipeline because those pipelines have the ability to spin up new boxes. They have a lot of secrets built into them. They can be potentially abused for lateral movement or privilege escalation. And different with MLSecOps versus just DevOps is a lot of these environments are, A, built on top of very new code that's built by smaller data scientists that wasn't intended to be used in an enterprise environment. And B, a lot of these MLSecOps pipelines are adjacent or readily connected into sensitive enterprise data lakes, which you just don't see on the DevOps side. So it makes for a very attractive target as a threat actor, as a red teamer for targeting ways into this MLSecOps pipeline. So if I manage to phish my way into your org, the first place I'm probably going to go now is after your data scientists and after your MLSecOps pipeline because I know that red -- blue teams don't have a lot of experience monitoring these environments. I know that the tools within them don't have good security logging enabled or at all. I know that a lot of these tools allow for Python de-serialization and code execution. And I know that the blue teams don't have experience performing incident response or threat hunting in these environments yet. So definitely a juicy target. On the flip side, within this environment, we hinted earlier at the potential for malicious models being downloaded. Most of the models, I think, if not all, to date in Hugging Face, that are malicious are probably set up by one or 2 big researchers. And they're just demonstrating the potential impact. At least a few months ago, that was the case. Where really smart folks, I won't name them because I don't know if they want it [ mentioned ] publicly, they backdoor-ed quite a few models for different companies to demonstrate the impact of supply chain attacks but in a safe way. So they're not actually fully establishing C2 and being leveraged to attack the companies. They're just demonstrating that a lot of these companies are just downloading and executing models and not checking them for malware or not verifying the author of the model, for example. So in the future, we obviously see a lot of these attacks expanding to where actual malicious threat actors are starting to backdoor some of these pickle models. So we want to make sure that the environment is set up in a way that you have an opportunity to spot those malicious models. So your frontline controls around leveraging something like HiddenLayer or another solution to scan these models statically and as they're being run dynamically. And as that serialization happens, can we spot a C2 being established, for example? But because antivirus isn't a silver bullet, as I mentioned, you want to make sure that you have compensating controls as well. So we want to evaluate the logging that's in place. We want to evaluate can C2 be established. A lot of these environments allow outbound Internet access because they have to call a lot of packages from different pipeline packages or they're being used to connect directly to Hugging Face. So just blocking them from the Internet isn't always feasible. So we want to evaluate what are different compensating controls that we can have in place from a logging and hardening perspective to prevent an attack like this happening in the future. So we want to assess the ability to detect malicious model code execution in notebooks. We want to assess the impact of a data scientist's or a developer's workstation being compromised. We want to evaluate the potential to access that crown jewel data within enterprise data lakes that are connected to these environments. And we want to proactively harden the virtualization infrastructure and any shared services or identity infrastructure that's being leveraged in this environment. One of my...
John Velisaris
executiveHey, Chris. Before you roll on there, do you want to advance the slides that you're sharing? Or do you want to toggle back to the platform slides?
Chris Thompson
executiveSorry, could you clarify?
John Velisaris
executiveYour screen has been static for what you're sharing. It's not advancing on the platform.
Chris Thompson
executiveShould you -- do you see pipeline security testing at the moment?
John Velisaris
executiveWe see recent talks, unfortunately. There. Now it's...
Chris Thompson
executiveI must have done pause. Let's see. Are you seeing the pipeline SecOps security testing now?
John Velisaris
executiveNow we're seeing it. Yes.
Chris Thompson
executiveStrange. Okay. Well, I'll keep it out of full screen. That's probably what happened there. So previously, I was referring to this slide for generative AI solutions. So the pipeline on the left, model in the middle, the platform that the model is running on, and then the gen AI application. And right now, talking about the pipeline security testing, so those different frameworks that are in use and the focus on testing the overall pipeline and how we harden it. And we've built a lot of -- oh, somebody said they were seeing the slides advance the whole time, so it might have been on your side, John. Sorry to interrupt. You might want to do a reboot. All right. So back to this slide. So we've built out a lot of tooling that can help to speed up or automate some of the testing for these types of issues in these environments, ability to perform model extraction from these environments or malicious code execution, different tooling that we created to extract different types of model weights and whatnot from the environment. And we're really focused on a lot of this research that can help us speed up how we conduct and assess these environments. We'll be releasing a lot of this tooling as open source, some in the next couple of months here, as long as -- as well as with an accompanying white paper. That brings us into model safety and security testing. I'm going to go back to the slide show here. And somebody please interrupt me if my slides pause, but going to model safety and security testing. So again, traditionally, our red teaming is focused on the safety of the model, can it produce biased or harmful content? And the security model, so can we perform prompt injection, which could result in malicious code execution in the environment? Could we produce some sort of response to other users of the application that could be considered harmful, maybe steal their authentication tokens? Or could we do attacks that are inherent to live models being used in these applications? So looking at the different frameworks that are out there, lots of different ways that the procedures and categories of attacks are being tracked from MITRE ATLAS to the OAuth LLM top 10 around prompt injection and inferring training data, all those sorts of things. And really, we're looking at how can we ensure that the models that we're using in these applications have robust system prompts, that they're not going to produce those biased responses, and that the guardrails and kind of AI firewalls that are being used for the model input and output are effective in protecting areas where these system prompts are not effective in preventing, say, code execution or common ML attacks. We take an approach where we leverage automation from certain partners. We're partnered with like NVIDIA [ Garrix ] open source security tool. We leverage robust intelligence. We leverage in-house tooling. And the reason for that is there is gaps in any one solution. And so some of it can be almost fully automated where for more sensitive application use such as finance or health care or whatnot, we want to do more due diligence because sensitive back-end data sets are being called or maybe sensitive APIs are being called that can pull data from other applications or wire money or perform HR actions such as viewing salary data or terminating an employee, for example. So we really want to make sure that, that can't be abused and the potential for somebody to view that data to perform actions that they shouldn't be authorized to can't happen. So a lot of the focus needs to be on how do we protect those back-end calls from not happening. Going back to the AI-as-a-service platform, my coworker, Brett Hawkins, authored a fantastic white paper around attacking these MLOps and AI-as-a-service platforms with me, a lot of attacks that can be conducted against those platforms you see on the left. And a lot of them surprisingly don't even have logging enabled by default. And most blue teams haven't ingested those logs and brought them into the SIEM and started to train for specific rules that are unique to these types of attacks. And so we've created a lot of tooling around how do we -- if an attacker were to gain access to the authentication tokens, the service principles, the DLI sessions, the managed identity tokens, the access tokens for access in these environments, could the blue team spot malicious behavior within them? And could they see sensitive actions being done? So if I, as a red teamer or as a threat actor, managed to gain access to the environment and I wanted to extract data from those enterprise data sets or I wanted to perform malicious actions that could result in data theft or model theft or privilege escalation, is the blue team prepared to spot these types of attacks and threat hunt for them? And so as I mentioned, the [ MLO ] kit will be relaunching -- we'll be launching open source in the next month or 2 here. And we'll enable internal teams to perform some of these tests themselves. But obviously, we're available to help as well and bring some of that expertise. And then lastly, around the apps, the gen AI apps and whatnot that are built on top of these platforms that leverage these models, that leverage the models that are tuned or leverage RAG within the MLSecOps pipeline. We want to be assessing these apps for traditional application security vulnerabilities but also now in expanded attack surface that comes with using a live model that you can basically store data within or call or try to get the model to open up ports on the back-end web server or open up interfaces that we can interact with or perhaps generate a malicious payload and execute it on the back-end production web server or model production environment. So a lot of an expanded attack surface comes with using a live model in these applications. We want to see that, again, that these applications that are integrated with sensitive API calls, that are integrated with back-end sensitive data sets, that they've been hardened properly and they're not subject to a lot of these new attacks that come with leveraging the live model production. So as I mentioned, lots of different areas that we can help. We're very interested in advancing the overall community's awareness of these types of issues. And that's why we're releasing the white paper for free and the open source security tooling and contributing back to the community. But if you ever need to talk to an expert or you want to look at how you can incorporate these into your testing program, we're more than happy to be available for that. And so with that, those are my slides. I'll turn it back to John. John, if you're ready for sharing?
John Velisaris
executiveYes, maybe. Perfect. I don't know how I can get the uploaded slides back showing again.
Chris Thompson
executiveDo you want me to share them on my side?
John Velisaris
executiveNo. I guess I could fire up the PowerPoint and share through the video bridge unless, Ellie. They are still showing. Okay. Very good. Thank you, Ellie. I will go back up. Hopefully, the audio clarity is better now, given that I've stopped trying to stream video from my computer. So we were covering the cost of the data breach, some highlights there. The total cost of a data breach has gone up. The average cost, the highest industry was health care, $9.77 million. Obviously, there's a lot of valuable data in health care. The -- one of the interesting components here was an increase in the number of organizations paying more than $50,000 in regulatory fines. Now I know that, that number, $50,000 is a low number, but we set the bar kind of low just to gauge if there was increasing regulatory action being taken when it comes to a data breach. And so sure enough, there was a 22%, 23% increase in the number of organizations who ended up with some type of regulatory financial penalty in excess of $50,000. So that seems to be moving. That trend seems to be increasing. In terms of [Audio Gap] conversations saying that they're deploying some type of AI and security automation in their SOC, that was a jump of 10% year-over-year, right? So more security operation centers are adopting an AI type of capability. When you use AI and automation to do things like accelerate investigation, coordinate command center activities, the time that you can take off that breach response is 98 days, right? So organizations that have those capabilities move faster when that breach has been detected. And then the savings for organizations by using AI to fill in part of that skill gap, right, so applying AI to do routine skills that are hard to find, they save $1.76 million. And then finally, the big savings, the big payout, if you have automated responses, if you have AI-driven workflows, right, the cost savings in the data breach scenario goes up to $2.2 million, which is the biggest jump we've seen in the entire report. So investing AI -- the takeaway is investing AI into your security operations capability has returns specifically through the lens of the data breach report. Again, it's available online where you can download the [Audio Gap] the accuracy out of generative AI results. He talked about bias, so on and so forth. So we're not going to do more on that because Chris covered them. We'll move on to the flip side of -- not talking about blue teaming but talking about adversaries. You've got new types of higher-sophistication attacks like better deep fakes, where you have financial controllers who are being deep faked on video calls and releasing transactions that should never happen. You've got generative AI code writing tools out there that can generate malware. So is [Audio Gap] a lot of those risks, so we won't double click on that as well, too. So when -- we've covered businesses adopting AI, the use of AI in that data breach type of model to accelerate detection and response, and the payouts that come from [Audio Gap] Chris covered a lot of those risks and how you go about testing for those. Let's talk about -- a little bit about AI specifically in the discipline of security. So a lot of those risks that we were talking about or whether it's being used as a customer service bot, whether the AI is being applied by, Chris said, for some back-end processing. But let's talk about the AI specific to security. And so we have been using AI in our cybersecurity services platform for years to do things like look at alerts. And we've automated 85% of alerts, right, to accelerate investigation, to look at an inhuman number of indicators and apply threat intelligence. And here's an example of -- and unfortunately, I don't think the roll-in happens or maybe I can get it to roll in here. I can get the slides to roll in. Some timelines and some volume metrics around when we use AI in our threat triage and threat handling function, some of the returns that we're seeing. But given that we're running short on time, let me fast forward and talk about how we're thinking about multiple types of AI, right? There's not just -- it's interesting, in my opinion, the kind of transformation that security teams are going through. They have AI capabilities for discrete functions, and this is a lot of what you see here on this slide, our kind of strategy as it comes to those discrete functions. But we also see organizations looking to create a single interface or at least a single API to put in front of all those functions. And so more to come from us, maybe we'll cover that in a future webinar, but a strategy to stitch all these things together. And the way I'm showing our kind of asset North Star here to you is using an old before the breach and after the breach, how can AI play a role. In many of these -- some of these capabilities like our advanced threat disposition scoring system, that's been around for 8, 9, 10 years. And we've used machine learning in that, and now we're stitching in generative AI capabilities. Other capabilities, other assets that we're building here to help visualize adversary behavior or apply threat intelligence in a predictive way or threat detection insights that does content engineering using generative AI. So using generative AI to create detection rules automatically and publish those into a blue team environment. And then finally, at the end of the -- on the backside of the boom here, we've got our cybersecurity assistant that supports investigation and response capability. So a lot of up-skilling of a SOC analyst around on the blue team side here. But definitely, a lot of work before the boom where Chris lives and the red team and ensuring that security is implemented in a way that will protect the organization. So last 2 slides here, just to double click some of the value statements. I know we're running out of time. We've got about a minute left. So if you want to grab a screenshot of these, I'll pause on each of these slides. What you're going to see is those assets, those AI assets that we're developing, that we're continuing to evolve and investing in, with a client success story, an anonymized client success story. And you've got some quantitative value in terms of the impact that, that technology is making. So we're showing you, we're trying to be as transparent, being sensitive to our client identities, the impact of that AI, those assets that I showed you across that kind of threat management pipeline, right, that they can make. So there's this one. And then there's this slide as well too that also talks about outside of security operations using AI, you'll see in the upper-right corner here, to help automate compliance or, for example, to create a new generative AI-based identity and access management experience, right? So gone are the days of the web forms and the access review websites. Managing identity and access is now as simple as talking to a generative AI bot, right? So those are other areas of the security program that we're working to transform those operations using generative AI. All right. So I don't -- I think we're out of time. I will toggle back and see if there's any other questions that have rolled in. I don't see any new questions. So Chris, unless there's anything that you want to add, guys, I apologize for the audio issues. Truly, that would -- that is a onetime event for me. Usually, it's rock solid. But again, I apologize for that. Chris, anything you want to add before we shut down the webinar?
Chris Thompson
executiveJust if you have any questions about what we chatted today, don't hesitate to reach out to myself or John, cthompson@ibm.com or you can reach us on LinkedIn. Appreciate your time, and we'll hopefully be in touch. Thanks, and take care.
John Velisaris
executiveThank you. Well done, Ellie.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete International Business Machines Corporation transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to International Business Machines Corporation earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.