Generative AI Security: What CISOs Must Know in 2025

Generative AI Security: What CISOs Must Know in 2025

🎙 Prabh Nair 👥 184K 📅 September 12, 2025 ⏱ 49 min 👁 2K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

generative AICISOthreat modelingOWASP TASMCI/CD

Summary

In this podcast episode, Prabh Nair interviews Ross Young, a CISO in residence and creator of the OWASP Threat and Safeguard Matrix (TASM). They discuss the security implications of generative AI in software development, emphasizing that developers are becoming prompt engineers, which introduces new vulnerabilities and compliance challenges. Ross explains the importance of securing AI-generated code and the need for CISOs to address shadow AI, data security posture management, and data loss prevention. They delve into the Model Context Protocol (MCP) as a new integration standard that brings both opportunities and risks. The conversation centers on the TASM framework, which maps material threats to the NIST cybersecurity functions (identify, protect, detect, respond, recover), enabling a defense-in-depth approach. They illustrate how to apply TASM to threats like prompt injection and hallucinations, and discuss integrating AI-specific checks into CI/CD pipelines. Ross highlights the need to balance security with functionality and to consider the upside of AI adoption, not just risks. They also touch on alignment with NIST AI RMF and EU AI Act, and the challenges of implementing such frameworks. The episode concludes with career advice for CISOs, emphasizing the importance of upskilling and focusing on business impact.

196 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the practical challenges CISOs face with generative AI, offering actionable advice on threat modeling and security controls. Ross Young’s argumentation is solid, grounded in his extensive experience and the TASM framework, which is a structured approach to addressing AI-specific threats. He effectively argues for a balanced perspective that considers both risks and business benefits, which is a nuanced and valuable viewpoint. The discussion is practical, with concrete examples like prompt injection and CI/CD integration, making it useful for security professionals.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates scientific rigor by referencing established frameworks such as OWASP TASM, NIST AI RMF, and EU AI Act. However, it relies heavily on expert opinion rather than empirical evidence, and some claims lack specific citations. The title accurately reflects the content, focusing on generative AI security from a CISO perspective. The sources cited are credible, including the OWASP project page and Ross Young’s LinkedIn profile, but the video does not provide a comprehensive literature review or data-driven analysis.

181 words

Title / Content Match

The title accurately reflects the content, which focuses on generative AI security from a CISO perspective, covering risks, frameworks, and practical measures.

Quality & Reliability

8/10

The discussion is led by a recognized CISO with extensive experience, and references established frameworks (OWASP TASM, NIST AI RMF, EU AI Act). However, it is largely opinion-based and lacks empirical data or case studies, and some claims are not substantiated with specific sources.

Chapters

Cited Sources

Concurring Sources

Contribution & Novelties

The video offers a fresh perspective on securing generative AI by introducing the OWASP Threat and Safeguard Matrix (TASM) as a practical framework for CISOs. It emphasizes the shift from traditional coding to prompt engineering and the need for new security controls. The discussion on integrating AI-specific checks into CI/CD pipelines and balancing security with functionality provides actionable insights. The emphasis on considering the upside of AI adoption, not just risks, is a valuable addition to the discourse.

Pour aller plus loin :

138 words

Radar Profile

The radar profile shows high scores in information quantity and quality, indicating a content-rich discussion. Technical level is moderate, suitable for a professional audience. Overall reliability is good, but the reliance on expert opinion rather than empirical data slightly lowers the score.

Reliability 7/10

💬 No comments were provided for analysis.