
Generative AI Security: What CISOs Must Know in 2025
Keywords
Summary
196 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides valuable insights into the practical challenges CISOs face with generative AI, offering actionable advice on threat modeling and security controls. Ross Young’s argumentation is solid, grounded in his extensive experience and the TASM framework, which is a structured approach to addressing AI-specific threats. He effectively argues for a balanced perspective that considers both risks and business benefits, which is a nuanced and valuable viewpoint. The discussion is practical, with concrete examples like prompt injection and CI/CD integration, making it useful for security professionals.
Scientific Rigor, Source Quality, Title Accuracy
The video demonstrates scientific rigor by referencing established frameworks such as OWASP TASM, NIST AI RMF, and EU AI Act. However, it relies heavily on expert opinion rather than empirical evidence, and some claims lack specific citations. The title accurately reflects the content, focusing on generative AI security from a CISO perspective. The sources cited are credible, including the OWASP project page and Ross Young’s LinkedIn profile, but the video does not provide a comprehensive literature review or data-driven analysis.
181 words
Title / Content Match
The title accurately reflects the content, which focuses on generative AI security from a CISO perspective, covering risks, frameworks, and practical measures.
Quality & Reliability
8/10
The discussion is led by a recognized CISO with extensive experience, and references established frameworks (OWASP TASM, NIST AI RMF, EU AI Act). However, it is largely opinion-based and lacks empirical data or case studies, and some claims are not substantiated with specific sources.
Chapters
- 01:05 - Introduction and Welcome Ross Young and his career journey
- 04:12 - Securing Generative AI
- 08:36 - How generative AI important from a CISO perspective
- 11:50 – MCP (Model Context Protocol)
- 17:43 - Threat and safeguard matrix (TSM/TASM)
- 20:00 - LLM threats step by step
- 21:42 - Integrate security controls
- 23:52 - Security Vs functionality
- 25:56 - AI-specific checks into CI/CD pipelines
- 26:42 - Recommend any generic controls for CI/CD pipeline
- 27:04 - Open-source tool for detecting the AI issues
- 30:20 - TASM aligned with the NIST AI RMF and EU AI act?
- 37:03 - Challenges faced with this framework (TSM)
- 40:00 - Single KPI
- 43:35 - One walkthrough for CISO’s to build KPI
- 45:40 - Career Advise - Upscale for CISOs
- 47:37 - Last important point
- End of the conversation by thanking Ross Young and looking forward to doing more Podcast.
Cited Sources
- OWASP Threat and Safeguard Matrix (TASM) — Discussed as the main framework for threat modeling AI threats.
- Ross Young's LinkedIn — Referenced as the guest's professional profile.
- AI Governance video — Mentioned as related content on AI governance.
- Practical AI governance video — Mentioned as related content on practical AI governance.
- AI Security video — Mentioned as related content on AI security.
Concurring Sources
- OWASP Top 10 for LLM Applications — Aligns with the discussion on LLM threats and safeguards.
- NIST AI Risk Management Framework — Referenced in the video as a framework aligned with TASM.
Contribution & Novelties
The video offers a fresh perspective on securing generative AI by introducing the OWASP Threat and Safeguard Matrix (TASM) as a practical framework for CISOs. It emphasizes the shift from traditional coding to prompt engineering and the need for new security controls. The discussion on integrating AI-specific checks into CI/CD pipelines and balancing security with functionality provides actionable insights. The emphasis on considering the upside of AI adoption, not just risks, is a valuable addition to the discourse.
Pour aller plus loin :
- OWASP Top 10 for LLM Applications — Relevant for understanding common LLM vulnerabilities.
- NIST AI Risk Management Framework — Provides a structured approach to managing AI risks.
- EU AI Act — Overview of the EU’s regulatory framework for AI.
- Model Context Protocol (MCP) — Concept discussed; no specific URL provided, but can be researched further.
138 words
Radar Profile
The radar profile shows high scores in information quantity and quality, indicating a content-rich discussion. Technical level is moderate, suitable for a professional audience. Overall reliability is good, but the reliance on expert opinion rather than empirical data slightly lowers the score.
💬 No comments were provided for analysis.